CybersecurityJobs.io
← Back to all jobs

Job Description

Remote Information Security Engineer – Security Automation and Response at UChicago Medicine, based in Illinois with remote work options.

Responsibilities

  • Design, implement, and maintain SOAR playbooks to automate routine security tasks such as alert triage, threat investigation, and incident response, leveraging SOAR platforms, Python, and API integrations.
  • Apply expertise in threat detection development, automate SOAR development processes, and contribute to incident response workflows.
  • Collaborate with the Information Security Operations Manager to advance Security Operations capabilities through AI-driven initiatives.
  • Investigate malware activity, intrusions, unauthorized access, and data infiltration and exfiltration events.
  • Examine logs, memory captures, disk images, and network captures to define attack scope and impact.
  • Stay informed on evolving cyber threats and standard SOC practices to continuously enhance Security Operations Center capabilities.
  • Demonstrate strong knowledge of security information and event management (SIEM) platforms and query languages such as Yara-L, CQL, SPL, and related tooling.
  • Participate in Purple Team activities to strengthen defensive and offensive testing cycles.
  • Join the on-call rotation and respond to critical security events as needed.

Requirements

  • BS or BA degree in Computer Science, Engineering, or equivalent education, training, or work experience.
  • Five years of security experience or equivalent combination of training and education.
  • Knowledge of computing systems, data network communications, and network architecture.
  • Effective written and verbal communication skills.
  • Experience in SOAR playbook development.
  • Scripting or programming skills required (Python, PowerShell, Go, etc.).
  • Experience in Incident Response and Threat investigation.
  • Experience in Threat detection.
  • Understanding of logging systems.
  • Security related certifications are preferred (GIAC, CISSP).

Technologies

  • SOAR
  • Python
  • API integrations
  • Yara-L
  • CQL
  • SPL
  • PowerShell
  • Go
  • SIEM

Essential Job Functions

  • Develop, implement, and maintain SOAR playbooks to automate repetitive security tasks, such as alert triage, threat investigation, and incident response, using tools like SOAR, Python, and API integrations.
  • Leverage knowledge of threat detection development, automation of SOAR development, and Incident Response to drive security outcomes.
  • Support initiatives with the Information Security Operations Manager to enhance Security Operations capabilities using AI.
  • Investigate malware, intrusions, unauthorized access, and data infiltration and exfiltration events.
  • Analyze logs, memory, disk images, and network captures to determine attack scope and impact.
  • Stay informed on cyber threats and standard SOC processes to continuously improve Security Operations Center capabilities.
  • Maintain strong proficiency with SIEM platforms and query languages (Yara-L, CQL, SPL, etc.).
  • Participate in Purple Team activities.
  • Participate in on-call rotation and respond to critical security events.

Required Qualifications

  • BS or BA degree, Computer Science, Engineering, or equivalent education, training, or work experience.
  • Five years of security experience, or equivalent training and education.
  • Knowledge of computing systems, data network communications, and network architecture.
  • Effective written and verbal communication skills.
  • Experience in SOAR playbook development.
  • Scripting or programming skills (Python, PowerShell, Go, etc.) required.
  • Experience in Incident Response and Threat investigation.
  • Experience in Threat detection.
  • Understanding of logging systems.
  • Security related certifications are preferred (GIAC, CISSP).

Position Details

  • Job Type/FTE: Full Time (1.0 FTE)
  • Shift: Day
  • Location: Remote
  • Unit/Department: Information Security
  • CBA Code: Non-Union

Similar Jobs