Job description
Join one of the nation’s most comprehensive academic medical centers, UChicago Medicine as an Information Security Engineer – Security Automation and Response for the Information Security department. This is a remote, work from home opportunity, and you may be based outside of the greater Chicagoland area.
Under general direction of the Information Security Operations Manager, implementing, deploying, and optimizing Automation using SOAR playbook development, Logging, AI driven workflows, streamline incident response, and improve SOC operational efficiency. Participate in threat investigation and Incident response.
Essential Job Functions
Develop, implement, and maintain SOAR playbooks to automate repetitive security tasks, such as alert triage, threat investigation, and incident response, using tools like SOAR, Python, and API integrations.
Knowledge of threat detection development, automation of SOAR development, and Incident Response.
Support initiatives working with Information Security Operations Manager to advance Security Operations capabilities using AI.
Investigate malware, intrusions, unauthorized access, and data infiltration and exfiltration events
Analyze logs, memory, disk images, and network captures to determine attack scope and impact
Dedicate efforts to staying informed on cyber threats and standard processes to consistently enhance Security Operations Center capabilities
Excellent knowledge of security information and event management (SIEM) platforms including query language (Yara-L, CQL, SPL, etc.)
Participate in Purple Team activity.
Participate in on-call rotation and respond to critical security events
Required Qualifications
BS or BA degree, Computer Science, Engineering, or equivalent education, training or work experience
5 years of Security experience, or equivalent training and education
Knowledge of computing systems, data network communications, and network architecture
Effective written and verbal communication skills
Experience in SOAR playbook development
Scripting or programming skills (Python, PowerShell, Go, etc.) required.
Experience in Incident Response and Threat investigation.
Experience in Threat detection
Understanding of logging systems
Security related certifications are preferred. (GIAC, CISSP)
Position Details
Job Type/FTE: Full Time (1.0 FTE)
Shift: Day
Location: Remote
Unit/Department: Information Security
CBA Code: Non-Union
Originally posted on Himalayas
Who can apply
Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.