Position SummaryThe F5 Global Cyber Defense and Intelligence team within the Office of the CISO is seeking hard-working and versatile Security Logging Engineers who will focus on updating, maintaining, and creating data pipelines fundamental to security services at F5. You will play a key role in protecting F5 and translating residual risk from critical application deployment into our logging and event platform to ensure data is flowing smoothly and consistently. Success in this role requires individuals to possess a blend of profound technical expertise, extensive knowledge in security, and substantial experience with logging. You'll be working with teams around the world in this position, so flexibility and excellent communication is key to excel in this role.
ResponsibilitiesBe part of the architectural direction, administration, maintenance, documentation, and oversight of the event logger and Security information and event management (SIEM) solutionAnalyze threat models and work with partner teams to ingest logging into the security event monitoring tool.Create and maintain integrations and solutions for the log collection, aggregation, indexing, search, alertingManage implementation, enhancement and adoption of the solutions built by the team into operationsUtilize log ingestion platform for security analytics and identification of tactics, techniques and patterns of attackersCollect and review security logs from all systems (Cloud Providers, GitLab, OS, G-Suite, OKTA, IDS, etc.) to ensure they can be used by the detection engineering teamEnsure compliance with internal policies, standards, and regulatory requirementsContribute to creation of security operation runbooks, threat hunting run books
Required Skills & Knowledge
Requires at least 6+ years of relevant industry experience preferably in SIEMExperience with large scale log aggregation/SIEM systems like SumoLogic, Splunk, Exabeam, LogRhythm, etc.Good written and verbal communication skillsExperience working in site-reliability engineering, cloud security, system engineering, or similar positionsDemonstrated experience with running systems at scaleProficiency to communicate over a text-based medium (Slack, GitLab Issues, Email) and can succinctly document technical detailsA Computer Science or Engineering degree is preferred, but not requiredAutomationProficiency in scripting language such as Python or Bash.Experience with log identifications and analysis withing GCP, AWS, Azure, or other cloud provider.Bonus Points:Experience analysing and interpreting large volumes of data to identify potential threats and security incidentsNice to haveExperience implementing Data Engineering patterns with Spark, Databricks, pandas, or SQLNice to haveAn understanding of attacker exploit and evasion techniquesNice to have competency in BigQuery, Athena, or any cloud provider query language.Nice to have familiarity with regexSANS (GCFR, GMON, or other related certifications )