Senior Security Engineer – SIEM and UBEA @ Marriott International

Cyber Crime
Bethesda, Maryland, US
$132.9K-$160.3K a year
Full-time

Senior Security Engineer - SIEM and UBEA

Company : Marriott International

Scroll down to find the complete details of the job offer, including experience required and associated duties and tasks.

We are seeking a highly skilled and experienced Senior SIEM and UEBA Engineer to join our cybersecurity operations team. The ideal candidate will have extensive experience in security architecture and engineering, with a strong focus on SIEM, UEBA platforms, and log management.

Responsibilities include design, implementation, and maintenance of SIEM, UEBA, and log management systems. This role will provide engineering support for Insider Threat and Detection Engineering analytics teams to support development of threat detections.

CANDIDATE PROFILE

Education and Experience

Required :

  • Bachelor’s degree in Computer Sciences or related field or equivalent experience / certification
  • 3+ years of experience in :
  • Security architecture and engineering experience on SIEM, UEBA, and log collection and management platforms.
  • Scripting language experience (*nix shell scripting, Python, PowerShell, etc.) and regular expressions
  • Linux and Microsoft operating systems (advanced knowledge)
  • 5+ years of experience in some or all of the following :
  • Experience working in (or with) security functions such as SOC, CIRT, security engineering, risk management, vulnerability management.
  • Technical infrastructure operations, administration, or systems engineering

Preferred Skills / Experience :

  • Current information security certification such as Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP) or an equivalent.
  • Splunk Certification, including Splunk Enterprise Security Certified Admin
  • Cribl Certified Admin : Stream
  • Working knowledge of the NIST Cyber Security Framework and ISO / IEC 27001 : 2022
  • Working knowledge of the MITRE ATT&CK Framework
  • Exabeam UEBA platform and Advanced Analytics administration
  • Splunk Enterprise platform and Splunk Enterprise Security administration
  • Hands-on experience with logging implementations for services / assets in cloud service provider platforms (AWS, Azure, GCP)
  • Familiarity with Identity and access management systems, firewalls, next-gen anti-malware, intrusion detection and prevention systems, proxies, reverse proxies, credential vaults, and database fundamentals.
  • Knowledge of IP networking
  • Solid written and verbal communication skills

Core Responsibilities

What You’ll be Doing :

  • Designing, implementing, and maintaining the SIEM, UEBA, and log management systems.
  • Implementing and maintaining data pipelines to analytics platforms to support threat detection with SIEM, UEBA, and other log collection and management tools.
  • Working with Insider Threat, Detection Engineering, and other security analytics teams to support the development of threat detection analytics.

This includes integrations, data onboarding, data normalization, and stack tuning for SIEM and UEBA platforms.

  • Collaborating with stakeholders in Global Information Security, Enterprise Architecture, and other IT teams on the development of procedures, standards, integration, and operability patterns for logging and monitoring.
  • Identifying and resolving escalated engineering-level analytics platform performance and functional problems for SIEM, UEBA, and log management systems.
  • Collaborating with other teams such as Security Architecture, Security Engineering, Policy and Compliance, network operations teams, and dev ops teams to ensure the security of our infrastructure through the application of security controls for SIEM, UEBA, and log management systems.
  • Keeping pace with the latest security trends, threats, and technologies and making recommendations for improvements to our security posture.
  • Providing technical guidance and mentoring to junior team members.
  • Creating reports on analytics platform operations, documenting engineering processes, creating SOPs, and presenting findings and issues remediation plans to management and other stakeholders.
  • Providing direction and support for the development of platform metrics, dashboards, and reports for analytics platforms to support operational monitoring.

Additional Responsibility :

  • Contributing to ongoing development and maintenance of documented standards, workflows, and best practices within the Analytics Platform Engineering discipline.
  • Researching emerging threats and adversary tactics, techniques, and procedures to understand the threat landscape and the implications on our analytics platform architecture and configurations to maintain good security posture.
  • Providing governance support for the analytics platforms such as platform management standards and change oversight.
  • Supporting budgeting work with analysis of analytics platform resource and licensing utilization and forecasted needs.
  • Occasional participation in evaluations of new platforms, technologies, and methodologies pertaining to security monitoring.
  • Attending SCRUM and prioritization meetings to review and update deliverables.

The salary range for this position is $132,900 to $160,300 annually. In addition to the annual salary, the position will be eligible to receive an annual bonus.

Washington Applicants Only : Employees will accrue 0.04616 PTO balance for every hour worked and eligible to receive a minimum of 7 holidays annually.

All locations offer coverage for medical, dental, vision, health care flexible spending account, dependent care flexible spending account, life insurance, disability insurance, accident insurance, adoption expense reimbursements, paid parental leave, educational assistance, 401(k) plan, stock purchase plan, discounts at Marriott properties, commuter benefits, employee assistance plan, and childcare discounts.

Benefits are subject to terms and conditions, which may include rules regarding eligibility, enrollment, waiting period, contribution, benefit limits, election changes, benefit exclusions, and others.

Marriott HQ is committed to a hybrid work environment that enables associates to be connected. Headquarters-based positions are considered hybrid for candidates within a commuting distance to Bethesda, MD;

candidates outside of commuting distance to Bethesda, MD will be considered for Remote positions.

The application deadline for this position is 28 days after the date of this posting, October 8, 2024.

Marriott International is an equal opportunity employer. We believe in hiring a diverse workforce and sustaining an inclusive, people-first culture.

We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law.

J-18808-Ljbffr

3 days ago
Related jobs
Promoted
Booz Allen Hamilton
Laurel, Maryland

As a Release Train Engineer and Release Manager, you manage engineering support for all the processes and activities of agile software development. You'll work with the Software and DevSecOps teams and Chief Architect to plan releases, including increment planning, road mapping, user stories, priori...

Promoted
The Johns Hopkins University Applied Physics Laboratory
Laurel, Maryland

If so, we want you to join our group of offensive cyber experts! We seek experienced reverse engineers and developers who will build inventive cyber capabilities leveraging novel reverse engineering and exploitation techniques. Share and enhance knowledge by clearly articulating ideas through papers...

Promoted
INSPYR Solutions
Silver Spring, Maryland

The Security Tools Engineer administers, monitors, and maintains security infrastructure, which includes but is not limited to application and container security tools, security orchestration solutions, security information and event monitoring (SIEM), Network Security Tools, system logging and anal...

Promoted
The Johns Hopkins University Applied Physics Laboratory
Laurel, Maryland

We are seeking a senior engineer to lead the radome design and analysis for subsonic, supersonic, and hypersonic applications. Provide technical contributions and leadership in designing and analyzing new radome structures to the development of strike weapon systems in the relevant areas such as ana...

Marriott International
Bethesda, Maryland

Support efforts to monitor and measure the financial performance of CRL and its applicable programs and services to help ensure results are aligned with business objectives; deliver actionable monthly and quarterly reporting for Senior CRL Leadership. Partner with Accenture Hospitality Services (AHS...

Task Force Talent
Laurel, Maryland

Task Force Talent is a specialized recruiting firm for science, engineering, and security careers. Full Stack Software Engineers (all levels - Junior/Senior/Expert). This application puts you into consideration for dozens of positions, and we'll match you with the best fits according to your interes...

Marriott International
Bethesda, Maryland

Cyber Incident Response that must include experience in: Identification and response to existing and emerging threats Identification of attacker tools, tactics, and procedures (TTPs) Security data analysis from a variety of sources and tools TCP/IP, DNS, SIEM, and EDR technologies (Splunk, CrowdStri...

DirectViz Solutions, LLC
Lanham, Maryland

The ideal candidate will be responsible for program and project integration, supporting various activities through technical analyses and reviews, and ensuring process improvement and adherence across the integrated IMF Modernization system. Senior Development and Integration Engineer. Identify and ...

Blackbaud
Remote, Maryland, US
Remote

You are either a security-minded software engineer who has been building modern services using a microservice architecture in an agile development environment or a development-interested security practitioner who understands security best practices, but wants to get closer to development and enginee...

Vexterra Group
Bethesda, Maryland

Vexterra Group is currently searching for a TS/SCI cleared network engineer to provide the following database system support: Primary Responsibilities Provide network project engineering support to replace and consolidate End of Life (EOL) Controlled Interfaces with new Controlled Interfaces Use an ...