Information Security Engineer, Senior
Listed on 2026-06-03
-
IT/Tech
Cybersecurity, Systems Engineer
Overview
Toyota Financial Services (TFS) Technology team is looking for a highly motivated person to fill a role as a Senior Cyber Security Engineer. The primary responsibility is to architect, deploy, optimize, and maintain the organization's Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms. You will lead engineering efforts to ensure comprehensive log ingestion, detection fidelity, platform health, and automation capabilities that empower the Security Operations Center (SOC) and broader cyber defense teams.
An important part of the Toyota family is Toyota Financial Services (TFS), the finance and insurance brand for Toyota and Lexus in North America. While TFS is a separate business entity, it is an essential part of this world-changing company—delivering on Toyota's vision to move people beyond what's possible.
Location: Plano, TX
What You'll Be Doing- SIEM Engineering & Platform Health:
Lead the design, configuration, and ongoing maintenance of complex SIEM environments, including onboarding and managing diverse data sources, ensuring proper log parsing, normalization, and enrichment. Proactively monitor platform health, troubleshoot ingestion failures, and optimize storage and performance to maintain operational excellence. - SOAR Development & Automation:
Design, build, and maintain SOAR playbooks and automated workflows that streamline alert triage, enrichment, and response actions. Continuously identify opportunities to reduce manual effort and accelerate mean time to detect (MTTD) and mean time to respond (MTTR) through intelligent automation. - Agent Deployment & Endpoint Telemetry:
Lead the deployment, configuration, and lifecycle management of security agents across on-prem, cloud, and hybrid endpoint environments. Ensure consistent agent coverage, policy enforcement, and telemetry collection to maximize detection visibility across the enterprise. - Detection Engineering & Data Source Management:
Develop and tune detection rules, correlation logic, and alerting thresholds within the SIEM to improve signal-to-noise ratio and detection accuracy. Partner with threat intelligence and SOC teams to translate emerging threats into actionable detection content. Manage the full lifecycle of data source integrations, including scoping, onboarding, validation, and ongoing health monitoring. - Scripting & Automation Development:
Leverage scripting languages such as Python and Power Shell to build custom tooling, automate repetitive engineering tasks, develop API integrations, and enhance platform capabilities beyond out-of-the-box functionality. - Process Development & Standardization:
Assist in the development and maintenance of standard operating procedures (SOPs), engineering runbooks, and documentation that streamline data source onboarding, platform maintenance, and incident support workflows. Continuously refine processes to improve efficiency and consistency.
- 3-5 years of experience in cyber security engineering, with hands-on expertise in SIEM administration and engineering, SOAR platform development, log management, data source onboarding, and security agent deployment and lifecycle management.
- Subject matter expertise in one or more SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel, Chronicle, Elastic, Palo Alto XSIAM/XSOAR, Phantom, Swimlane, etc.).
- Strong understanding of log source types, parsing methodologies, data normalization techniques, and common log formats (e.g., Syslog, CEF, JSON, XML, Windows Event Logs).
- Proficiency in scripting languages, particularly Python and Power Shell, with demonstrated ability to build automation, custom integrations, and engineering tooling.
- Excellent communication skills with the ability to collaborate with and influence stakeholders at all levels, including SOC analysts, infrastructure teams, and leadership.
- A bachelor's degree in a relevant field (e.g., Cybersecurity, Computer Science, Engineering, Information Technology) or equivalent work experience.
- Experience in a regulated industry (e.g., finance, healthcare, government).
- Proficiency in additional…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).