Cybersecurity Engineer II – SIEM, EDR

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of The Home Depot

The Home Depot

10,000+ employees

Founded 1978

🏗️ Construction

📦 Logistics

🛒 Retail

💰 Debt Financing on 2007-07

Construction • Logistics • Retail

The Home Depot is a leading home improvement retailer, offering a wide range of building materials, home improvement products, lawn and garden products, and related services. The company operates both physical stores and an online platform, providing comprehensive solutions for DIY enthusiasts, professional contractors, and homeowners. The Home Depot is committed to diversity, equity, and inclusion, providing employment opportunities and benefits to a diverse workforce. Additionally, the company places a high emphasis on customer service and associate engagement to maintain its position as a trusted leader in the home improvement industry.

📋 Description

• Maintain day-to-day operational health of EDR and SIEM infrastructure • Research normal activity baselines and tune alerting noise • Tune security use cases to provide high-fidelity alerts • Develop custom security use cases, log correlations, and detection rules • Apply event data to existing security use cases and models • Develop and configure dashboards for event trends and alerts • Configure reporting for key metrics and trends • Collaborate with external teams to onboard new SIEM data sources • Validate extraction, parsing, and formatting in event data • Write custom field extractions using RegEx • Troubleshoot and perform break/fix efforts during service disruptions • Configure antivirus exceptions and blocks • Maintain updated service documentation • Configure and integrate cybersecurity systems that mitigate risk • Resolve escalated incidents • Design, build, configure, maintain, and monitor cybersecurity threat defense capabilities and user access management • Coordinate integration with managed security providers • Investigate incidents and recommend corrective actions

🎯 Requirements

• 2+ years of cybersecurity work experience • 1+ years of SIEM or EDR-specific work experience with platforms such as Cortex XSIAM, Splunk, or CrowdStrike • Understanding of networking infrastructure concepts, technologies, and protocols • Ability to identify logging, monitoring, and endpoint protection gaps and recommend solutions • Ability to bridge technical and non-technical constituents • Strong people, team, and communication skills • Security+ certification and SIEM vendor certification, plus EDR vendor certification, or equivalent certifications (preferred) • Incident Response / SOC work experience (preferred) • Experience with cloud-based solutions such as Azure or GCP (preferred) • Linux/Unix administration experience (preferred) • Experience writing formal reports (preferred) • Must be at least 18 years of age • Must be legally permitted to work in the United States • Bachelor's degree or equivalent degree in a related field, or equivalent acquired knowledge, skills, and abilities • Ability to troubleshoot and resolve cybersecurity incidents • Ability to design, configure, maintain, monitor, and integrate cybersecurity systems

🏖️ Benefits

• Remote/Virtual work arrangement • No travel required

Apply Now

Similar Jobs

🔥 1 hour ago

CACI International Inc

10,000+ employees

💼 Consulting

🎖️ Defense

Cyber Security Engineer securing CACI’s DoD customer environments through RMF, ATO, NIST controls, and vulnerability assessments. Supporting mission-critical defense systems with compliance documentation, STIG implementation, and continuous monitoring.

🔥 1 hour ago

Northrop Grumman

10,000+ employees

🏭 Manufacturing

📦 Logistics

🎖️ Defense

Data Security Engineer securing Databricks Lakehouse access controls at Northrop Grumman. Managing Unity Catalog permissions, sensitive-data controls, Terraform automation, audits, and governance.

🔥 7 hours ago

Avertium

201 - 500

🔒 Cybersecurity

🏢 Enterprise

Cybersecurity Consultant securing Microsoft Cloud infrastructure and applications for Avertium clients. Leading architecture, integration, security controls, and cybersecurity strategy projects.

🔥 9 hours ago

Akamai Technologies

5001 - 10000

🔒 Cybersecurity

Security Incident Responder monitoring Akamai's distributed cloud and edge platform. Triaging customer-impacting events, coordinating engineering response, and minimizing downtime for major online services.

🕒 Yesterday

Optiv

1001 - 5000

Cybersecurity advisor designing scalable security solutions for Optiv’s strategic clients. Driving security services sales, client advisory, and cybersecurity strategy across assigned territories.