JSOC - Principal SIEM Engineer
Tasks
- Administer security solutions and policies
- Architect and maintain NXLog deployment
- Automate platform operations with scripting and infrastructure as code
- Build and maintain ingest pipelines and parsers
- Coordinate log source onboarding
- Deploy detection as code using CI CD pipelines
- Design deploy and maintain Elastic cluster architecture
- Design deploy and maintain Kafka streaming infrastructure
- Design deploy and maintain security tools
- Maintain Elastic Security dashboards and saved searches
- Maintain platform documentation runbooks and operational procedures
- Manage Elastic upgrades and cluster health monitoring
- Manage index lifecycle policies and data retention
- Measure SIEM platform performance metrics
- Mentor team members in Elastic administration and data pipeline engineering
- Monitor and maintain end to end data pipeline reliability
- Own SIEM platform health performance and evolution
- Participate in on-call rotations
- Plan capacity and scale Elastic and Kafka infrastructure
- Recommend SIEM and log management technology improvements
- Translate detection requirements into platform capabilities
- Tune platform performance query optimization and sharding
Perks/Benefits
- Career growth and development
- Community causes opportunities
- Health and wellbeing resources
- Hybrid work with at least 3 days in office
- Inclusive and collaborative work environment
- Paid vacation and sick days
- Work-life balance
Skills/Tech-stack
AWS | Apache Kafka | Bash | Beats | CI/CD | Docker | EDR | Elastic Agent | Elastic Security | Elastic Stack | Elasticsearch | Elasticsearch Index Lifecycle Management | Email Gateway | GCP | GitLab | Index Lifecycle Management | Infrastructure as Code | KRaft | Kafka | Kafka Connect | Kibana | Kubernetes | Lifecycle Management | Linux | Logstash | NxLog | OpenSearch | Python | SOAR | WAF | Zookeeper | “as-code”
Education
N/A
Roles
Engineer | Principal | Principal SIEM Engineer | SIEM Engineer
Related jobs
-
Senior Cloud Security Engineer CAD 130K-160KCI/CD | Cloud platform | Datadog | GitHub Actions | Google CloudCoaching and feedback | Flexible vacation policy | Health and dental benefits | Home office setup | Hybrid work optionsSenior-level Full TimeSaskatoon, SK1d ago
-
Senior Cloud Security Engineer CAD 130K-160KAI Tooling | CI/CD | Cloud platform | Data masking | DatadogDental insurance | Flexible vacation policy | Health insurance | Hybrid work options | Parental leaveSenior-level Full TimeToronto, ON1d ago
-
Information Security Engineer / Ingénieur en Sécurité de l'Information | North America (EST) /Amérique du Nord (EST) CAD 105K-145KAWS | Browser Extension | Browser extension security | CASB | Cloud SecuritySenior-level Full TimeCanada R1d ago
-
Senior Software Engineer, IAM USD 160K-260KAWS | Audit Logging | Distributed Systems | GRPC | GoEquity | Flexible work hours | Home office setup | Medical benefits | PTOSenior-level Full TimeCanada R1d ago
-
Application Security | Application Security Testing | Azure DevOps | Bash | CI/CDCustom training program | Employee assistance program | Family support program | Flexible work hours | Hybrid workMid-level Full TimeQuébec, Quebec, Canada1d ago
-
Application Security | Azure DevOps | Bash | CI/CD | DASTCustom training and development | Employee assistance program | Flexible work schedule | Hybrid work model | Paid time offMid-level Full TimeSherbrooke, Quebec, Canada1d ago
-
AWS | Azure | Azure DevOps | Bash | CI/CDEmployee Retirement Savings Plan | Employee assistance program | Flexible work hours | Hybrid work mode | Paid vacationMid-level Full TimeLongueuil, Quebec, Canada1d ago
-
Azure DevOps | Bash | CI/CD | Continuous Delivery | Continuous integrationCustomized training program | Employee assistance program | Flexible work schedule | Health benefits | Hybrid work modelMid-level Full TimeMontreal, Quebec, Canada1d ago
-
Azure DevOps | Bash | CI/CD | DAST | Dependency ScanningAction purchase program | Employee assistance program | Flexible schedule | Generous paid vacation | Hybrid workMid-level Full TimeLaval, Quebec, Canada1d ago
-
Azure DevOps | Bash | CI/CD | DAST | Dependency ScanningEmployee assistance program | Flexible work schedule | Hybrid work mode | Retirement savings plan | Tailored trainingMid-level Full TimeLongueuil, Quebec, Canada1d ago
-
Automation | Azure DevOps | Bash | CI/CD | Code ScanningEmployee and family assistance program | Flexible work schedule | Hybrid work mode | Retirement savings plan | Tailored trainingMid-level Full TimeQuébec, Quebec, Canada1d ago
-
Azure DevOps | Bash | CI/CD | DAST | Dependency ScanningEmployee and family assistance program | Flexible work schedule | Hybrid work mode | Paid vacation | Retirement savings planMid-level Full TimeMontreal, Quebec, Canada1d ago
-
Azure DevOps | Bash | CI/CD | Code Scanning | DASTEmployee assistance program | Flexible work schedule | Hybrid work mode | Retirement savings plan | Tailored trainingMid-level Full TimeSherbrooke, Quebec, Canada1d ago
-
Automation | Azure DevOps | Bash | CI/CD | Code ScanningEmployee and family assistance program | Employee share purchase opportunity | Flexible work schedule | Hybrid work mode | Paid vacationMid-level Full TimeLaval, Quebec, Canada1d ago
-
System Engineering Analyst, Networking (Junior) CAD 73K-80KAnsible | Automation | Bash | Cisco | Configuration Management24 7 Virtual Care Services | Educational assistance | Emergency travel insurance | Employee & Family Assistance Program | Employee discountsEntry-level Full TimeOttawa, ON, Canada1d ago
-
Principal Software Engineer CAD 75K-90KABAC | API Design | API Versioning | Access Management | Active DirectorySenior-level Full TimeToronto, Ontario1d ago
-
Lead, Network Security Engineer CAD 91K-141KAccess Control | Cloud Native | Cloud Secure | Cloud Secure Web Gateways | Cloud SecurityCompetitive rewards | Employee resource groups | Tuition assistance | Upskilling programs | Workplace accommodationsSenior-level Full TimeToronto, ON, CA, M1K5L12d ago
-
Application Security Developer CAD 80K-116KAPI Gateway | API Security | API Top 10 | Access Control | AcunetixMid-level Full TimeAMER - Canada - Ontario - …2d ago
-
Incident Response Principal Consultant (Remote CAN) CAD 135K-200KAWS | Cloud platform | Computer forensics | Digital forensics | Google CloudAdoption leave | Employee networks | Paid parental leave | Professional development | Remote workSenior-level Full TimeCAN AB Remote, Canada R2d ago
-
Senior Cybersecurity Developer CAD 101K-136KAWS | Auth0 | Bash | CI/CD | Cloud SecurityDental coverage | Fitness reimbursement | Health spending account | Hybrid work | Insurance coverageSenior-level Full TimeToronto, Canada; Montréal, Canada2d ago
-
Senior Security Engineer CAD 150K-190KApplication Security | Automation | Bug Bounty | CI/CD | Cloud SecurityCo-working stipend | Health and dental benefits | Inclusive culture | Parental leave top-up | Remote-flexibleSenior-level Full TimeToronto2d ago
-
Technical Lead, DevOps CAD 120K-155KAWS | AWS CloudFormation | AWS ECS | AWS EKS | AWS LambdaContract-to-hireSenior-level Contract Full TimeCanada4d ago
-
Mid-level Full TimeVancouver, British Columbia, Canada4d ago
-
Senior-level Full TimeCalgary, Alberta4d ago
-
SAP ASE (Sybase) & HANA Database Administrator CAD 110K-140KAutomation | Backup and Restore | Database Administration | Database Upgrade | Database securityMid-level Full TimeToronto, ON, CA, M5K 1B75d ago