Über diese CyberSecurity Engineer | USM Anywhere Stelle bei Avertium
Avertium is seeking a Senior Cybersecurity Engineer with strong hands-on experience with USM Anywhere and modern SIEM/XDR technologies. This role will focus on designing, implementing, optimizing, and supporting security monitoring and response solutions across customer environments.
The ideal candidate understands how SIEM and XDR technologies work together to provide centralized visibility, threat detection, investigation, incident response, and security automation. You will serve as a senior technical resource for complex security issues, help improve the effectiveness of our security monitoring capabilities, and support the continued evolution and scalability of our security operations.
While USM Anywhere is the primary platform for this role, candidates with strong experience in other major SIEM/XDR platforms such as Microsoft Sentinel, Splunk, FortiSIEM, LogRhythm, or comparable technologies will also be considered.
Responsibilities:
-
Design, implement, configure, and optimize USM Anywhere SIEM/XDR environments.
-
Configure and manage security monitoring, log collection, data sources, integrations, agents, and supporting infrastructure.
-
Develop, tune, and maintain detections, correlation rules, alerts, dashboards, and other security monitoring capabilities.
-
Support threat detection, investigation, and incident response using SIEM and XDR technologies.
-
Leverage endpoint, network, cloud, application, and other security telemetry to improve threat visibility and detection.
-
Troubleshoot complex SIEM, XDR, security, infrastructure, and networking issues and serve as a technical escalation point for other engineers.
-
Support integrations between USM Anywhere and endpoint, cloud, network, identity, and other security technologies.
-
Develop automation and scripting to improve operational efficiency and enhance security response capabilities.
-
Identify opportunities to improve detection quality, system performance, reliability, scalability, and operational processes.
-
Support the architecture and deployment of new SIEM/XDR environments and customer solutions.
-
Create and maintain technical documentation, architecture diagrams, procedures, and operational standards.
-
Collaborate with Security Operations, Engineering, Service Delivery, and other technical teams to resolve complex customer and operational issues.
-
Participate in change management and CAB processes.
-
Stay current with emerging SIEM, XDR, threat detection, automation, and security operations technologies.
Qualifications for success:
-
5+ years of overall IT experience, including at least 2 years in cybersecurity engineering, security operations, or a related security role.
-
2+ years of hands-on experience implementing, administering, troubleshooting, or engineering SIEM and/or XDR solutions.
-
Strong hands-on experience with USM Anywhere or a comparable enterprise SIEM/XDR platform.
-
Strong understanding of SIEM concepts, including log collection, normalization, correlation, alerting, detection, dashboards, and security event analysis.
-
Experience developing, tuning, or troubleshooting security detections and understanding the underlying data supporting those detections.
-
Strong technical troubleshooting and advanced problem-solving skills.
-
Experience with security automation or scripting using PowerShell, Python, Bash, SQL, or similar technologies.
-
Foundational understanding of cloud security and infrastructure in AWS and/or Azure.
-
Working knowledge of networking concepts, including TCP/IP, DNS, VPNs, and IPsec.
-
Strong written and verbal communication skills.
Preferred Qualifications:
-
Advanced experience with USM Anywhere and/or related LevelBlue security technologies.
-
Experience with Open XDR and security orchestration, automation, and response (SOAR) capabilities.
-
Experience with Microsoft Sentinel, SentinelOne, Splunk, FortiSIEM, LogRhythm, or other major SIEM/XDR platforms.
-
Experience working in an MSSP, managed security services, or professional services environment.
-
Experience supporting multiple customer environments or multitenant security platforms.
-
Strong Windows and Linux administration experience.
-
Experience with SQL, Elasticsearch, or other security data platforms.
-
Familiarity with MITRE ATT&CK and the NIST Cybersecurity Framework.
-
Relevant cybersecurity or vendor certifications.
-
Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent professional experience.