Information Security Engineer β Security Automation and Response
Job Description
Remote Information Security Engineer β Security Automation and Response at UChicago Medicine, based in Illinois with remote work options.
Responsibilities
- Design, implement, and maintain SOAR playbooks to automate routine security tasks such as alert triage, threat investigation, and incident response, leveraging SOAR platforms, Python, and API integrations.
- Apply expertise in threat detection development, automate SOAR development processes, and contribute to incident response workflows.
- Collaborate with the Information Security Operations Manager to advance Security Operations capabilities through AI-driven initiatives.
- Investigate malware activity, intrusions, unauthorized access, and data infiltration and exfiltration events.
- Examine logs, memory captures, disk images, and network captures to define attack scope and impact.
- Stay informed on evolving cyber threats and standard SOC practices to continuously enhance Security Operations Center capabilities.
- Demonstrate strong knowledge of security information and event management (SIEM) platforms and query languages such as Yara-L, CQL, SPL, and related tooling.
- Participate in Purple Team activities to strengthen defensive and offensive testing cycles.
- Join the on-call rotation and respond to critical security events as needed.
Requirements
- BS or BA degree in Computer Science, Engineering, or equivalent education, training, or work experience.
- Five years of security experience or equivalent combination of training and education.
- Knowledge of computing systems, data network communications, and network architecture.
- Effective written and verbal communication skills.
- Experience in SOAR playbook development.
- Scripting or programming skills required (Python, PowerShell, Go, etc.).
- Experience in Incident Response and Threat investigation.
- Experience in Threat detection.
- Understanding of logging systems.
- Security related certifications are preferred (GIAC, CISSP).
Technologies
- SOAR
- Python
- API integrations
- Yara-L
- CQL
- SPL
- PowerShell
- Go
- SIEM
Essential Job Functions
- Develop, implement, and maintain SOAR playbooks to automate repetitive security tasks, such as alert triage, threat investigation, and incident response, using tools like SOAR, Python, and API integrations.
- Leverage knowledge of threat detection development, automation of SOAR development, and Incident Response to drive security outcomes.
- Support initiatives with the Information Security Operations Manager to enhance Security Operations capabilities using AI.
- Investigate malware, intrusions, unauthorized access, and data infiltration and exfiltration events.
- Analyze logs, memory, disk images, and network captures to determine attack scope and impact.
- Stay informed on cyber threats and standard SOC processes to continuously improve Security Operations Center capabilities.
- Maintain strong proficiency with SIEM platforms and query languages (Yara-L, CQL, SPL, etc.).
- Participate in Purple Team activities.
- Participate in on-call rotation and respond to critical security events.
Required Qualifications
- BS or BA degree, Computer Science, Engineering, or equivalent education, training, or work experience.
- Five years of security experience, or equivalent training and education.
- Knowledge of computing systems, data network communications, and network architecture.
- Effective written and verbal communication skills.
- Experience in SOAR playbook development.
- Scripting or programming skills (Python, PowerShell, Go, etc.) required.
- Experience in Incident Response and Threat investigation.
- Experience in Threat detection.
- Understanding of logging systems.
- Security related certifications are preferred (GIAC, CISSP).
Position Details
- Job Type/FTE: Full Time (1.0 FTE)
- Shift: Day
- Location: Remote
- Unit/Department: Information Security
- CBA Code: Non-Union