CLOUD SECURITY & SIEM ENGINEER

Technet, LLC
United States
20 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Amazon Web Services Amazon S3 Audit Trail Bash Shell Cloud Computing Security Cyber Security Databases Data Transmissions Data Infrastructure Data Integration
+29 more
Data Sharing Linux Middleware File Transfer Identity and Access Management Internet Information Services (IIS) Virtual Private Networks (VPN) JSON Python (Programming Language) Microsoft SQL Server Windows Servers Salesforce.Com Security Information and Event Management Data Streaming Software Vulnerability Management Extensible Markup Language (XML) YAML Scripting Indexer Amazon Virtual Private Cloud (VPC) Amazon Relational Database Service Information Technology Enterprise Integration Route53 Opsworks Amazon Simple Queue Service (SQS) Network Server Api Management Security Orchestration, Automation & Response

Job description

Technet is seeking a hands-on Cloud Security & SIEM Engineer to deploy, configure, and maintain the cybersecurity architecture for a critical energy-sector utility billing and data platform hosted in AWS (us-west-2). In this role, you will lead the implementation and engineering of an enterprise high-availability (HA) Wazuh SIEM cluster deployed in a dedicated, tenant-isolated AWS management VPC. You will be responsible for telemetry pipelines across AWS-native security services, CrowdStrike Falcon EDR integration, containerized Prowler Cloud Security Posture Management (CSPM), and security monitoring for third-party middleware and data transfer tiers.

  1. Technical Stack & Systems Managed * SIEM & Endpoint: Wazuh (HA Manager Cluster, Indexer, Dashboard, Agents, File Integrity Monitoring [FIM], Security Configuration Assessment [SCA]), CrowdStrike Falcon (Streaming API, Falcon Data Replicator / FDR). * AWS Native Security & Infrastructure: Amazon GuardDuty, AWS Security Hub, AWS WAF, AWS Config, AWS Systems Manager (SSM), CloudTrail, VPC Flow Logs, Route 53 Resolver logs, S3 Access Logs, EventBridge, SQS, Transit Gateway, AWS Directory Service. * CSPM & Compliance Automation: Containerized Prowler, CIS AWS Foundations Benchmark, SOC 2 Type II, NIST 800-53. * Middleware & Data Integration Tiers: GoAnywhere Managed File Transfer (MFT), Dell Boomi Middleware, Salesforce CRM API feeds, PG&E data exchanges. * Operating Systems & Databases: Windows Server (IIS Web Tier), Linux workloads, Amazon RDS (Microsoft SQL Server Audit Logs)., * Wazuh SIEM Implementation & Cluster Administration: Deploy, configure, and maintain a high-availability Wazuh SIEM manager cluster in a dedicated AWS management VPC. Deploy and tune Wazuh agents across Windows/IIS web nodes, Linux instances, middleware servers, and MFT nodes. * AWS Telemetry Pipeline Engineering: Architect and validate centralized log ingestion using AWS EventBridge, SQS, CloudTrail, VPC Flow Logs, Route 53 Resolver logs, and S3 server access logs into the SIEM correlation pipeline. * EDR Integration: Ingest CrowdStrike Falcon telemetry via Streaming API / FDR into Wazuh to correlate endpoint activity with cloud control plane logs without endpoint resource contention. * Integration Edge & MFT Security: Develop custom log parsers, decoders, and alerting rules for high-risk integration boundary systems, specifically GoAnywhere MFT, Dell Boomi, Salesforce integrations, and external PG&E utility feeds. * CSPM & Continuous Compliance: Deploy and automate containerized Prowler scans and AWS Config rules to deliver daily posture assessments mapped to SOC 2 Type II, CIS AWS Foundations Benchmark, and NIST 800-53 standards. * Vulnerability Management & Configuration Hardening: Operationalize automated recurring vulnerability scans and Security Configuration Assessments (SCA) using Wazuh and AWS Systems Manager (SSM); track and support infrastructure remediation. * Identity & Access Security: Assist with MFA deployment and continuous auditing across AWS Directory Service, VPN endpoints, and GoAnywhere MFT exchanges. * Encryption Validation: Continuously validate encryption-in-transit and encryption-at-rest across S3, EBS, and RDS SQL Server databases.

Requirements

  • Experience: 4+ years of hands-on experience in Cloud Security Engineering, SIEM Administration, or SecOps within AWS enterprise environments.
  • SIEM & Log Engineering: Deep practical expertise deploying and managing Wazuh (or ELK/OpenSearch-based security stacks), including writing custom XML decoders, rules, and managing agent fleets.
  • AWS Security Core: Strong hands-on experience with GuardDuty, Security Hub, AWS WAF, AWS Config, Systems Manager (SSM), IAM policy design, and multi-VPC networking (Transit Gateway).
  • Workload & Database Auditing: Experience configuring log feeds and auditing for Windows Server/IIS, Linux, and Amazon RDS SQL Server audit logs.
  • Integration Knowledge: Experience securing and ingesting logs from middleware and file-transfer systems (e.g., GoAnywhere MFT, Dell Boomi, API connectors).
  • Scripting: Proficiency in Python, Bash, and JSON/YAML for security automation and API integrations.
  • U.S. Data Residency Requirement: Must reside and work exclusively within the United States.
  1. Preferred Qualifications & Certifications * AWS Certified Security - Specialty * AWS Certified Solutions Architect (Associate or Professional) * GIAC Cloud Security Automation (GCSA), GCED, or CISSP * Experience with utility, energy-sector, or NERC/CIP-adjacent regulated cloud environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

1:35 min

Centralizing configuration logic with native YAML block references

Matthieu Vincent Matthieu Vincent · Europe 2026 Virtual

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

6:51 min

Audience questions on cloud security and operational capacity

Steffen Heilmann · World Congress 2021

2:00 min

Introduction to YAML syntax and basic formatting

Chris Ayers · LIVE

Videos

See all

Related articles

See all