FortiSIEM Security Engineer
United States - Remote
Thrive
Thrive is a leading provider of outsourced IT infrastructure. Our managed services provide customers with a strategic advantage as they secure, scale, and succeed.About UsÂ
Thrive is a rapidly growing technology solutions provider focusing upon Cloud, Cyber Security, Networking, Disaster Recovery and Managed Services. Our corporate culture, engineering talent, customer-centric approach, and focus upon ânext generationâ services help us stand out amongst our peers. Thrive is on the look-out for individuals who donât view their weekdays spent at âa jobâ, but rather look to develop valuable skills that ignite their passion and lead to a CAREER. If youâre attracted to a âwork hard, play hardâ environment, seeking the guidance, training and experience necessary to build a lucrative career, then welcome to THRIVE!!Â
Position OverviewÂ
We are seeking a Security Engineer to lead the management and optimization of our security tools, with a primary focus on FortiSIEM, Microsoft Sentinel, and Defender XDR. This role is critical in bolstering our cybersecurity framework by effectively utilizing these key tools to elevate our existing Security Operations. The ideal candidate will have hands-on experience designing and optimizing SIEM rules for enhanced threat detection and incident management, deploying EDR solutions to safeguard endpoints, and implementing automated security responses. This role also requires expertise in customizing and automating client reports, ensuring robust API security, and analyzing SOC and SIEM data for actionable insights. The Security Engineer will play a crucial part in client interactions, providing regular updates on security posture and findings. A meticulous approach to documentation and a proactive stance on staying abreast of the latest security trends are essential. This is an excellent opportunity for a detail-oriented and proactive individual who is passionate about cybersecurity and dedicated to enhancing client relationships.Â
Primary ResponsibilitiesÂ
Lead the management of FortiSIEM, Microsoft Sentinel and Defender XDR products, including their integration with existing tools, utilizing them to elevate existing Security OperationsÂ
Design and optimize SIEM (Security Information and Event Management) rules using FortiSIEM to enhance threat detection and streamline incident response activitiesÂ
Deploy and manage Endpoint Detection and Response (EDR) solutions, specifically FortiEDR, SentinelOne, and Defender for Endpoint to identify and mitigate endpoint threats effectivelyÂ
Design and implement automated security use cases and playbooks to accelerate incident response and remediationÂ
Assist in overseeing the implementation and management of API security measures, ensuring secure data transmission and compliance with industry-standard API security protocolsÂ
Collaborate with clients to understand their reporting needs and requirements and customize reports accordinglyÂ
Develop, maintain, and automate client-facing reports using our existing security tools. These reports should effectively articulate incident metrics and trends to both technical and non-technical audiences. This role also includes automating the upload of these reports to the ServiceNow client portalÂ
Create and maintain materials documenting our security processes, procedures, and technologies, along with the generation of automated reports for relevant stakeholders.Â
Provide expert guidance on alarm tuning and configuration tasks necessary for Security Service deployment to new and existing customersÂ
Take a proactive role in updating client Security presentations and discuss findings with our clientsÂ
Perform comprehensive analysis of data from our SOC and SIEM to identify patterns, anomalies, and potential threatsÂ
Design and implement client reports, dashboards, and metrics, and manage response runbooks and walkthrough documentsÂ
Stay informed about the latest security events and techniques to enhance our operations and defense strategies,Â
Qualifications and Required SkillsÂ
Proven experience with Microsoft Sentinel and Defender XDR productsÂ
Strong background in SIEM rule design and optimizationÂ
Extensive experience in implementing and overseeing Endpoint Detection and Response (EDR) solutionsÂ
Experience with SOAR tools and automated security response implementationsÂ
Familiarity with API security protocols and measuresÂ
Ability to analyze large amounts of data from various sources to solve complex problems and make informed decisionsÂ
Proficiency in developing and automating client-facing reportsÂ
Excellent communication skills for both technical and non-technical audiencesÂ
Demonstrated understanding of cybersecurity threats and incident response proceduresÂ
Knowledge of risk assessment tools, technologies, and methodsÂ
Expertise in computer networking and securityÂ
Passion for cybersecurity and continuous learningÂ
Must be able to work effectively in a team environment and collaborate within the team and with other stakeholdersÂ
Tags: APIs Cloud Compliance EDR Incident response Risk assessment Sentinel SIEM SOAR SOC Threat detection XDR
Perks/benefits: Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.