Sr Advanced Cyber Security Architect Engineer
Listed on 2026-09-25
-
IT/Tech
Cybersecurity, Security Management & Operations, Network Security
Job Description
This position will be a part of the Industrial Cyber‑Security team and will participate in delivering and developing cyber security services for a wide range of industrial global customers. The position will have a direct reporting relationship to the Global Security Operation Center Manager and Incident Response Lead and work as part of a global managed services team.
You will report directly to our Sr. Cyber Security Manager and you'll work out of our Duluth, GA. location on a Hybrid work schedule.
The position requires very good cyber security knowledge, excellent analytical skills and proficient handling of specific tools such as SIEMs and Security Orchestration, Automation and Response platforms. A successful candidate would be able to evaluate security incidents and determine true positives situations within an environment and provide context enrichment service before escalation to Level 3 Cyber Security Incident Response team as needed.
ResponsibilitiesKEY RESPONSIBILITIES
- Monitors SIEM, trouble tickets / email notifications and in-person escalations, logs from ICs infrastructure components (SCADA, HMI, PLC, RTU, Control Servers), applications or network devices such as switches, firewalls, IDS/IPS;
- Design, implement, test Security Orchestration, Automation and Response processes and procedures;
- SOAR playbook development and troubleshoot automation capabilities;
- Examine the escalated tickets to determine if they are true positive or false positives.
- Performs malware analysis, threat hunting and threat modeling activities;
- Assist forensic investigation by providing reports and other information;
- Reviews and suggests improvements to control deployment process and installation procedures
- Develops and documents remediation recommendations for business owners to improve the control environment in which a security incident occurs. Recommendations must be easily understood by non-technical staff;
- Provide recommendations and direction on the tuning of signatures, rules, alerts, parsers, and custom scripts within the monitoring solutions;
- Participates in root cause analysis and helps with the orchestration of remediation;
- Understand defense in depth strategies and apply those to Client's environment;
- Creates and disseminates security related notifications for internal staff (for example: trends, developments, changes in capabilities);
- Acts as L2 Escalation layer in the SOC.
- Mentors Level 1 SOC Analysts;
- Creates manuals, guides and knowledge base entries;
- Keep abreast of latest security and privacy legislation, emerging threats, regulations, advisories, alerts, and vulnerabilities pertaining to HCE OT IR SOC and its customers;
- Remains knowledgeable of our current solution portfolio and the technical specificities of our offerings.
- 7+ years of experience in Information Technology, cybersecurity, or a related technical field.
- 5+ years of experience working in a Security Operations Center (SOC), cybersecurity operations, incident response, or a related security function.
- 5+ years of experience working with Security Information and Event Management (SIEM) or Security Orchestration, Automation and Response (SOAR) technologies.
- 5+ years of experience developing or implementing security automation using Python, SOAR platforms, or similar technologies.
- Bachelor's degree in Computer Science, Computer Information Systems, Electronics, or a related field.
- ITIL Foundation certification or a cybersecurity certification such as CompTIA Security+, GCIH, CCNA, GCFA, or CEH.
- Experience with SIEM platforms and security logging solutions such as Swimlane, Sentinel, or GOOGLE SECOPS.
In addition to a competitive salary, leading-edge work, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).