Security Platform Engineer (Remote USA ONLY)
ExperianAbout the role
Company Description
Experian is the world’s leading global information services company. During life’s big moments – from buying a home or a car, to sending a child to college, to growing a business by connecting with new customers – we empower consumers and our clients to manage their data with confidence. We help individuals to take financial control and access financial services, businesses to make smarter decisions and thrive, lenders to lend more responsibly, and organizations to prevent identity fraud and crime.
We have 20,000 people operating across 44 countries and every day we’re investing in new technologies, talented people, and innovation to help all our clients maximize every opportunity
We are very proud that FORTUNE named us one of The 100 Best Companies to Work For. In addition, for the last five years we’ve been named in the 100 “World’s Most Innovative Companies” by Forbes Magazine.
Job Description
The Security Platform Engineer is part of the Engineering & Architecture team within the Experian Global Security Office (EGSO). This role will focus on threat detection engineering, development, and maintenance of SIEM & UEBA systems. Specific focus will be directed to understanding various vendor feeds and developing the capability of our analytics tools. An ideal candidate will have extensive information security experience particularly in incident response. The Security Platform Engineer will work closely with the various internal teams, including but not limited to cyber threat intelligence analysts, SOC analysts, threat detection engineers, server and network administrators, security tool administrators, and business unit customers. An ideal candidate will have extensive information security experience particularly in incident response and understanding the various security log feeds mapping the data into the SIEM.
Major Responsibilities include:
- Understand data feeds of various security tools and logs that feed the SIEM & UEBA technologies. Ability to identify capabilities and quality of these feeds and recommend improvements.
- Ability to craft new content use cases based on threat intelligence, analyst feedback, available log data, and previous incidents.
- Perform day to day activities of the content life cycle, including creating new use cases, testing content; tuning, and removing content; and maintain associated documentation.
- Remediate vulnerabilities in the different application environments
- Work with the other security teams and product SMEs to identify gaps within the existing analytical capability.
- Development of parsers/field extractions to facilitate reliable content development
- Development of custom scripts as required to augment default SIEM functionality
- Participate in root cause analysis on security incidents and provide recommendations for containment and remediation
- Act as the liaison to business units to fulfill audit, regulatory compliance and/or corporate security policy requirements.
- Create, implement, and maintain novel analytic methods and techniques for incident detection
- Ensure documentation for content is available on team wiki- specifically including content roadmap and documentation on current content
Qualifications
- Strong Understanding of the MITRE ATT&CK framework, cloud attack vectors and detection engineering for cloud specific threats
- 5+ years of information security experience, preferably engineering or development
- 3+ years of experience supporting a Splunk platform administration, new content dashboards, applications, and use cases
- 2+ years’ experience performing ETL onboarding for various log feed technologies such as CSV, JSON, XML, syslog, etc.
- 2+ years of experience mentoring junior Splunk engineers
- 2+ years of experience with developing Rest API’s to capture data from external sources
- Prior experience in Splunk content development
- Experience with Agile methodologies as a scrum master running scrum meetings.
- Understanding of various log formats and source data for SIEM Analysis
- Solid background with Windows and Linux platforms (security or system administration)
- Ability to effectively communicate with anyone, from end users to senior leadership- facilitating technical and non-technical conversations.
- Strong incident handling/incident response/security analytics skills
- Deep understanding of technical concepts including networking and various cyber attacks
- Solid comprehension of various security controls, capabilities and use in a corporate environment
- Exceptional problem-solving capabilities
- Strong documentation and communication skills
- Demonstrated h
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s