Back to search
The University of Chicago Medicine Himalayas · Posted 3d ago

Information Security Engineer – Security Automation and Response

Full time Remote

Infosec Security Engineering Security Operations Center Incident Response
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Join one of the nation’s most comprehensive academic medical centers, UChicago Medicine as an Information Security Engineer – Security Automation and Response for the Information Security department. This is a remote, work from home opportunity, and you may be based outside of the greater Chicagoland area.

Under general direction of the Information Security Operations Manager, implementing, deploying, and optimizing Automation using SOAR playbook development, Logging, AI driven workflows, streamline incident response, and improve SOC operational efficiency. Participate in threat investigation and Incident response.

Essential Job Functions

  • Develop, implement, and maintain SOAR playbooks to automate repetitive security tasks, such as alert triage, threat investigation, and incident response, using tools like SOAR, Python, and API integrations.
  • Knowledge of threat detection development, automation of SOAR development, and Incident Response.
  • Support initiatives working with Information Security Operations Manager to advance Security Operations capabilities using AI.
  • Investigate malware, intrusions, unauthorized access, and data infiltration and exfiltration events
  • Analyze logs, memory, disk images, and network captures to determine attack scope and impact
  • Dedicate efforts to staying informed on cyber threats and standard processes to consistently enhance Security Operations Center capabilities
  • Excellent knowledge of security information and event management (SIEM) platforms including query language (Yara-L, CQL, SPL, etc.)
  • Participate in Purple Team activity.
  • Participate in on-call rotation and respond to critical security events

Required Qualifications

  • BS or BA degree, Computer Science, Engineering, or equivalent education, training or work experience
  • 5 years of Security experience, or equivalent training and education
  • Knowledge of computing systems, data network communications, and network architecture
  • Effective written and verbal communication skills
  • Experience in SOAR playbook development
  • Scripting or programming skills (Python, PowerShell, Go, etc.) required.
  • Experience in Incident Response and Threat investigation.
  • Experience in Threat detection
  • Understanding of logging systems
  • Security related certifications are preferred. (GIAC, CISSP)

Position Details

  • Job Type/FTE: Full Time (1.0 FTE)
  • Shift: Day
  • Location: Remote
  • Unit/Department: Information Security
  • CBA Code: Non-Union

Originally posted on Himalayas

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search