Information Security Engineer β Security Automation and Response
Job Description
This remote position supports UChicago Medicine's Information Security team as an Information Security Engineer focused on Security Automation and Response. The role centers on designing and maintaining SOAR playbooks, automating security tasks, and assisting with incident response and threat investigations.
Overview
The role operates within the Information Security department, delivering automation and guidance to enhance security operations from a remote location in Illinois.
Responsibilities
- Create, deploy, and maintain SOAR playbooks to streamline routine security tasks such as alert triage, threat analysis, and incident response, leveraging SOAR platforms, Python scripting, and API integrations.
- Apply knowledge of threat detection development, automate SOAR development, and support incident response processes.
- Collaborate with the Information Security Operations Manager to advance Security Operations capabilities with AI technologies.
- Conduct investigations into malware, intrusions, unauthorized access, and data infiltration and exfiltration events.
- Examine logs, memory dumps, disk images, and network captures to determine attack scope and impact.
- Stay current on cyber threats and standard SOC practices to continually improve security operations.
- Demonstrate strong knowledge of security information and event management platforms and associated query languages such as Yara-L, CQL, and SPL.
- Participate in Purple Team activities.
- Join on-call rotations and respond to critical security events.
Essential Job Functions
- Develop, implement, and maintain SOAR playbooks to automate repetitive security tasks using SOAR tools, Python, and API integrations.
- Apply expertise in threat detection development, SOAR automation, and incident response.
- Support initiatives with the Information Security Operations Manager to enhance Security Operations capabilities through AI.
- Investigate malware, intrusions, unauthorized access, and data infiltration and exfiltration events.
- Analyze logs, memory, disk images, and network captures to assess attack scope and impact.
- Maintain current awareness of cyber threats and standard operating procedures to improve SOC capabilities.
- Utilize SIEM platforms and query languages such as Yara-L, CQL, and SPL with proficiency.
- Engage in Purple Team activities.
- Participate in on-call rotation and respond to critical security events.
Requirements
- Bachelor's degree in Computer Science, Engineering, or an equivalent combination of education, training, and experience.
- Minimum five years of security experience or equivalent background.
- Understanding of computing systems, data network communications, and network architecture.
- Strong written and verbal communication skills.
- Experience in SOAR playbook development.
- Proficiency in scripting or programming languages such as Python, PowerShell, or Go.
- Experience in incident response and threat investigations.
- Experience in threat detection.
- Understanding of logging systems.
- Security certifications are preferred (GIAC, CISSP).
Technologies
- SOAR
- Python
- API integrations
- Yara-L
- CQL
- SPL
- PowerShell
- Go
- SIEM
Position Details
- Job Type/FTE: Full Time (1.0 FTE)
- Shift: Day
- Location: Remote
- Unit/Department: Information Security
- CBA Code: Non-Union