
Cybersecurity Engineer
- Dearborn, MI
- Permanent
- Full-time
- SIEM Solution Design and Implementation:
- Designing and deploying secure, scalable Google SecOps architectures, including log ingestion pipelines and integration with existing IT infrastructure
- Configuring and managing log ingestion from various sources, ensuring data normalization and efficient analysis within Google SecOps.
- Design, Build, and Maintain SIEM Data Pipelines:
- Design and develop robust, scalable, and automated data pipelines to ingest, process, transform, and store security logs and events from diverse sources (e.g., servers, firewalls, applications, cloud platforms) into the SIEM platform.
- Develop and implement data parsing rules, enrichment processes, and data normalization techniques to ensure data quality and consistency within the SIEM.
- Integrate new data sources into the SIEM, including connecting to APIs, databases, streaming data sources, and cloud platforms.
- Collaborate with various teams (e.g., development, operations, cloud services) to understand logging requirements, define logging standards, and ensure the appropriate data is collected.
- Optimize SIEM Data Pipelines:
- Monitor data pipeline performance, identify bottlenecks, and implement optimizations to improve efficiency, reduce latency, and ensure timely data availability for security analysis.
- Tune log sources and correlation rules to reduce false positives, minimize noise, and enhance the accuracy of threat detection.
- Develop and implement best practices for SIEM and SOAR (Security Orchestration, Automation, and Response) content management and development.
- Explore and implement automation opportunities to improve analyst alert handling, streamline security operations, and reduce manual intervention.
- SIEM Administration and Support:
- Maintain the health, performance, and tuning of the SIEM platform.
- Troubleshoot issues related to log sources, data ingestion, parsing failures, and other SIEM platform issues.
- Security Command Center (SCC) responsibilities:
- Managing access to Security Command Center features through IAM roles, allowing granular control over who can view, edit, or manage findings and assets
- Ensuring that Security Command Center settings are configured and maintained to support the organization's security needs.
- Connecting with other Google Cloud products and third-party tools for a more complete security posture
- Bachelor's degree in Computer Science, Cyber Security, Information Systems or related field.
- 8+ years of overall software engineering experience
- 4+ years of hands-on experience with SIEM platforms such as Google SecOps, IBM QRadar, Microsoft Azure Sentinel, or similar.
- Experience with security logging, data sources, and industry best practices for log ingestion
- Experience in log parsing, custom rule creation, and developing actionable alerts
- 2+ years experience developing cloud native applications preferably on Google Cloud Platform
- Proficiency in scripting languages like Python, Go, Java, or Bash for automation, data manipulation, and integration tasks.
- Hands-on experience setting up CI/CD pipelines. OpenShift Tekton, or GitHub Actions, or alike Knowledge of secure coding practices
- Experience setting up serverless functions using GCP Cloud Run or Cloud functions, and configuring the respective cloud provider for scaling
- Robust knowledge of system design principles including reliability, availability, and scalability
- Experience setting up logging and monitoring services (Dynatrace, GCP Ops Suites)
- Strong understanding of network security, log analysis, threat detection, and incident response.
- Knowledge of RESTful APIs, data integration techniques, and infrastructure-as-code tools (e.g., Terraform, Ansible).
- Analytical and Problem-Solving Skills:
- Ability to analyze complex data systems, identify improvement opportunities, and translate business requirements into detailed technical designs.
- Excellent analytical skills and attention to detail for solving complex problems with many variables.
- Communication and Collaboration:
- Strong verbal and written communication skills to articulate technical issues, collaborate with stakeholders, and create comprehensive documentation.
- Ability to work effectively in a team environment and interact with various internal and external teams.
- Comfortable supporting multiple client environments and balancing delivery with operations.
- Security & Cloud skills:
- Familiarity with security concepts, cybersecurity frameworks such as NIST, MITRE ATT&CK threat hunting, and cyber threat intelligence.
- Strong technical experience working in multi-cloud platforms, particularly Google Cloud.
- Relevant industry certifications (e.g., CISSP, CISA, GCIH, GCIA, CompTIA Security+, CEH) are highly valued.
- GCP Professional certifications like Security Engineer, Cloud Engineer/Architect are a strong plus.
- Immediate medical, dental, vision and prescription drug coverage
- Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more
- Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more
- Vehicle discount program for employees and family members and management leases
- Tuition assistance
- Established and active employee resource groups
- Paid time off for individual and team community service
- A generous schedule of paid holidays, including the week between Christmas and New Year's Day
- Paid time off and the option to purchase additional vacation time.