SIEM/SOAR Engineer (Cloud Sec Spec 3)
Job Title: SIEM/SOAR Engineer (Cloud Sec Spec 3)Location: Onsite - Washington DCWork AuthorizationRole SummaryThe SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA s enterprise security operations.Roles & ResponsibilitiesConfigure ingestion pipelines and validate endtoend log flow.Implement Google curated detections and build custom detection rules.Develop SOAR playbooks for SBA s top incident categories.Integrate threat intelligence sources (Mandiant, VirusTotal).Tune detections to meet falsepositive thresholds.Support UEBA dashboard configuration and risk scoring.Assist with runbook creation, analyst training, and operational transition.Professional Experience Required5+ years of experience with SIEM/SOAR platforms (Google SecOps preferred).Experience building detection rules, automation workflows, and parser validation.Experience with cloud telemetry ingestion (Azure, AWS, on-prem).Experience with threat intelligence integration.Educational QualificationBachelor s degree in Cybersecurity, IT, or related field.CertificationsGoogle SecOps, GIAC, CISSP, or equivalent preferred.