Sr Advanced Cyber Security Architect Engineer
Honeywell Duluth, Georgia, United States
Automation Machinery Manufacturing · 10,001+ employees
About the role
The role involves monitoring industrial security infrastructure, managing SIEM and SOAR platforms, and performing threat hunting and incident response activities. You will also mentor junior analysts, develop automation playbooks, and provide remediation recommendations to business owners.
What they look for
Requirements
Candidates must have at least 7 years of experience in IT or cybersecurity, with 5+ years specifically in SOC, incident response, and SIEM/SOAR technologies. Proficiency in security automation using Python and a strong understanding of industrial control systems are required.
Benefits
Full description
This position will be a part of the Industrial Cyber-Security team and will participate in delivering and developing cyber security services for a wide range of industrial global customers. The position will have a direct reporting relationship to the Global Security Operation Center Manager and Incident Response Lead and work as part of a global managed services team.
You will report directly to our Sr. Cyber Security Manager and you’ll work out of our Duluth, GA. location on a Hybrid work schedule.
The position requires very good cyber security knowledge, excellent analytical skills and proficient handling of specific tools such as SIEMs and Security Orchestration, Automation and Response platforms. A successful candidate would be able to evaluate security incidents and determine true positives situations within an environment and provide context enrichment service before escalation to Level 3 Cyber Security Incident Response team as needed.
Responsibilities
KEY RESPONSIBILITIES
- Monitors SIEM, trouble tickets / email notifications and in-person escalations, logs from ICS infrastructure components (SCADA, HMI, PLC, RTU, Control Servers), applications or network devices such as switches, firewalls, IDS/IPS;
- Design, implement, test Security Orchestration, Automation and Response processes and procedures;
- SOAR playbook development and troubleshoot automation capabilities;
- Examine the escalated tickets to determine if they are true positive or false positives.
- Performs malware analysis, threat hunting and threat modeling activities;
- Assist forensic investigation by providing reports and other information;
- Reviews and suggests improvements to control deployment process and installation procedures
- Develops and documents remediation recommendations for business owners to improve the control environment in which a security incident occurs. Recommendations must be easily understood by non-technical staff;
- Provide recommendations and direction on the tuning of signatures, rules, alerts, parsers, and custom scripts within the monitoring solutions;
- Participates in root cause analysis and helps with the orchestration of remediation;
- Understand defense in depth strategies and apply those to Client’s environment;
- Creates and disseminates security related notifications for internal staff (for example: trends, developments, changes in capabilities);
- Acts as L2 Escalation layer in the SOC.
- Mentors Level 1 SOC Analysts;
- Creates manuals, guides and knowledge base entries;
- Keep abreast of latest security and privacy legislation, emerging threats, regulations, advisories, alerts, and vulnerabilities pertaining to HCE OT IR SOC and its customers;
- Remains knowledgeable of our current solution portfolio and the technical specificities of our offerings.
Qualifications
YOU MUST HAVE
- 7+ years of experience in Information Technology, cybersecurity, or a related technical field.
- 5+ years of experience working in a Security Operations Center (SOC), cybersecurity operations, incident response, or a related security function.
- 5+ years of experience working with Security Information and Event Management (SIEM) or Security Orchestration, Automation and Response (SOAR) technologies.
- 5+ years of experience developing or implementing security automation using Python, SOAR platforms, or similar technologies.
WE VALUE
- Bachelor’s degree in Computer Science, Computer Information Systems, Electronics, or a related field.
- ITIL Foundation certification or a cybersecurity certification such as CompTIA Security+, GCIH, CCNA, GCFA, or CEH.
- Experience with SIEM platforms and security logging solutions such as Swimlane, Sentinel, or GOOGLE SECOPS.
BENEFITS OF WORKING FOR HONEYWELL
In addition to a competitive salary, leading-edge work, and developing solutions side-by-side with dedicated experts in their fields, Honeywell employees are eligible for a comprehensive benefits package. This package includes employer subsidized Medical, Dental, Vision, and Life Insurance; Short-Term and Long-Term Disability; 401(k) match, Flexible Spending Accounts, Health Savings Accounts, EAP, and Educational Assistance; Parental Leave, Paid Time Off (for vacation, personal business, sick time, and parental leave), and 12 Paid Holidays. Learn more (https://benefits.honeywell.com/) The application period for the job is estimated to be 40 days from the job posting date; however, this may be shortened or extended depending on business needs and the availability of qualified candidates.
ABOUT HONEYWELL
Honeywell International Inc. (Nasdaq: HON) invents and commercializes technologies that address some of the world's most critical challenges around energy, safety, security, productivity, and global urbanization. We are a leading software-industrial company committed to introducing state of the art technology solutions to improve efficiency, productivity, sustainability, and safety in high growth businesses in broad-based, attractive industrial end markets. Our products and solutions enable a safer, more comfortable, and more productive world, enhancing the quality of life of people around the globe. Learn more (https://www.honeywell.com/us/en)
U.S. PERSON REQUIREMENTS
Due to compliance with U.S. export control laws and regulations, candidate must be a U.S. Person, which is defined as, a U.S. citizen, a U.S. permanent resident, or have protected status in the U.S. under asylum or refugee status or have the ability to obtain an export authorization.
Honeywell Technologies is a global, pure-play automation company with a legacy of innovating to help solve the world’s most mission-critical challenges, enhancing the quality of life for people and communities around the world. We serve the building, industrial and process sectors with a broad portfolio of services, solutions and products, underpinned by our Honeywell Technologies Accelerator operating system and Honeywell Technologies Forge intelligence layer. By combining the deep domain expertise of our more than 50,000 employees with decades of data from our global installed base, we are uniquely positioned to lead the industrial sector’s transition from automation to autonomy.