
SR INFORMATION SECURITY ENGINEER
Lumen Technologies2 hours ago
Singapore, SingaporeSenior
Responsibilities
- Design and implement MSSP-grade security platform architectures for multi-customer SOC delivery.
- Engineer unified SecOps capabilities across SIEM, XDR, SOAR, EDR, NDR, cloud security, identity security, threat intelligence, ITSM, vulnerability, and exposure management platforms.
- Build and maintain security telemetry ingestion, parsing, normalization, enrichment, routing, retention, archival, and data-quality controls.
- Design SOAR playbooks and automate SOC workflows including phishing triage, suspicious sign-in response, IOC enrichment, endpoint containment support, case creation, and SLA tracking.
- Deploy, validate, tune, and maintain detection content aligned with MITRE ATT&CK and Detection-as-Code practices.
- Own patching, upgrades, lifecycle management, integrations, agents, collectors, forwarders, certificates, credentials, and supporting infrastructure.
- Lead technical onboarding of MSSP customers through discovery, design, integration, testing, acceptance, and SOC handover.
- Create architecture diagrams, integration standards, onboarding plans, runbooks, validation test cases, and technical documentation.
Requirements
- 5+ years of cybersecurity engineering, security platform engineering, SOC engineering, security data engineering, or security infrastructure experience.
- 3+ years of hands-on experience designing, deploying, maintaining, or upgrading SIEM and/or SOAR platforms in an enterprise, MSSP, MDR, SOC, or security consulting environment.
- Hands-on experience with at least one major SIEM platform, such as Microsoft Sentinel, Splunk, Cortex XSIAM, Google SecOps, FortiSIEM, QRadar, or equivalent.
- Hands-on experience with at least one SOAR or automation platform, such as Cortex XSOAR, FortiSOAR, Splunk SOAR, Microsoft Sentinel automation, Azure Logic Apps, Google SecOps SOAR, or equivalent.
- Experience with agent deployment and patching, collector and forwarder management, connector updates, platform upgrades, change control, rollback planning, and production validation.
- Strong understanding of telemetry across cloud, SaaS, identity, endpoint, network, application, database, and infrastructure environments.
- Working knowledge of APIs, scripting, automation, secrets handling, service principals, certificates, secure integration design, and production support practices.
- Strong troubleshooting, architecture documentation, runbook development, onboarding, and stakeholder communication capabilities.
- Preferred certifications include Microsoft SC-200, SC-100, AZ-500, Splunk Admin or Architect, Palo Alto Cortex XSOAR or XSIAM, Fortinet NSE, Google SecOps, GIAC certifications, CISSP, CCSP, AWS Security Specialty, or equivalent certifications.
- Training or practical experience in MITRE ATT&CK, detection engineering, threat hunting, purple teaming, cloud security, platform engineering, or DevSecOps is preferred.
Benefits
- Lumen describes a collaborative, human-centered, AI-focused work environment with clear expectations, trust, support, and shared accountability.
- Selected candidates undergo a background screening that may include criminal records, motor vehicle reports, and/or drug screening depending on position requirements.