SIEM & Incident Respose Manager

Phoenix, Arizona
04/12/2024
Phoenix
Depends on Experience 
Full-Time

COMPANY OVERVIEW

Join our award-winning team at Information Management Resources, Inc. (IMRI), a small business leader in the technology industry known for our commitment to innovation, excellence, and authenticity. Founded in 1992, IMRI has been at the forefront of delivering advanced cybersecurity and IT solutions, safeguarding organizations against evolving threats. We have built a reputation for our expertise in Cybersecurity, Digital Transformation, Strategic Business Consulting, and Staff Augmentation. Guided by our core values of innovation, excellence, and a solution-driven mindset, we have served a diverse portfolio of customers that includes federal agencies, state and local governments, and Fortune 1000 companies.

At IMRI, we recognize the integral part our employees play in our ongoing success. To support this, we offer a comprehensive benefits package, tailored to meet the individual needs of our employees. We are committed to promoting their overall well-being and equipping them with the necessary tools to flourish in their careers. We welcome you to be a part of our ongoing mission as we continue to navigate the digital landscape, committed to empowering organizations with our innovative solutions.

Job Description:
The SIEM and IR Manager must have responsibility for overseeing the work performed by other Professional Services Engineers along with the implementation, management, and optimization of the Security Information and Event Management (SIEM) solution and coordinating with existing SOC operations and existing SOC management and leadership teams. Strong background in cybersecurity, extensive experience with SIEM technologies (Elastic preferred) and SOC operations, and a proven track record of leading and developing high-performing teams.

Responsibilities:
-  Lead and manage the SIEM and IR team to ensure effective detection, analysis, and response to security incidents.
-  Oversee the implementation, configuration, and optimization of the SIEM solution to enhance threat detection capabilities.
-  Align with existing SOC procedures, processes, and playbooks to streamline incident response activities.
-  Monitor SIEM and IR team with respect to SIEM alerts and security events, investigation of incidents, and oversight of root cause analysis.
-  Collaborate with existing SOC personnel and cross-functional teams to coordinate incident response efforts and mitigate security risks.
-  Provide leadership and mentorship to SIEM and IR team members, guiding their professional development and enhancing team capabilities.
-  Conduct regular assessments and audits of SIEM configurations to ensure compliance with industry standards and best practices as defined by the existing customer.
- Stay current on emerging threats, vulnerabilities, and security technologies to continuously improve SIEM and IR operations and threat detection capabilities.

Requirements:
-  Hands-on experience with SIEM platforms such as Splunk, IBM QRadar, ArcSight, or LogRhythm and preferably Elastic.
-  Strong understanding of SOC procedures, incident response methodologies, and best practices and the ability to work with existing customer operational personnel and leadership.
-  Proven leadership skills with experience managing and developing teams and reporting activities and success to a customer’s operational and leadership teams.
-  Excellent communication and interpersonal skills, with the ability to collaborate effectively with the customer’s cross-functional teams.