Sr. Security Engineer - SIEM, Automation & Elastic Security - Red Lobster - Orlando, FL
Red Lobster
Overview
SUMMARY
Serve as a senior member of the Cybersecurity Engineering team responsible for designing, implementing, and optimizing enterprise security monitoring and automation capabilities. Led the architecture and operational maturity of the organization's SIEM platform with a focus on Elasticsearch and security automation to improve threat detection, incident response, and visibility across enterprise infrastructure. Partnered with product, platform, DevOps, and security teams to integrate security telemetry, automate workflows, and strengthen the organization's overall cybersecurity posture.
ESSENTIAL/PRIMARY DUTIES, FUNCTIONS, AND RESPONSIBILITIES
Design, implement, and maintain enterprise SIEM infrastructure, including Elasticsearch clusters, log pipelines, indexing strategies, and data ingestion from cloud, network, endpoint, and application sources. Develop and maintain SIEM detection content, including correlation rules, dashboards, threat detection use cases, and alerting frameworks to improve security monitoring and incident detection. Lead the Elasticsearch roadmap and platform strategy, ensuring scalability, high availability, performance optimization, and alignment with enterprise security initiatives. Built security automation workflows and scripts to streamline incident response, threat hunting, log enrichment, and security operations processes. Integrate SIEM/SOAR capabilities with security technologies including EDR, threat intelligence platforms, vulnerability scanners, identity systems, and network security tools to create a unified security monitoring ecosystem. Tune and optimized detection logic and log pipelines to reduce false positives and improve signal-to-noise ratio across security monitoring platforms. Collaborate with SOC analysts and incident response teams to investigate alerts, conduct forensic analysis, and identify root causes of security incidents. Ingest and operationalized threat intelligence feeds to enhance