Samsung SDS America (SDSA) serves as the U.S. technology and innovation hub for Samsungs global enterprise solutions, delivering secure, scalable, and high-performance IT services that support some of the worlds most complex business environments. As SDSA continues to expand its cloud, mobility, analytics, and cybersecurity capabilities, maintaining a resilient security operations foundation is essential to protecting the companys digital assets and ensuring uninterrupted service delivery.
Position Summary:
As Security Engineer, youll join the Cybersecurity Operations team, where youll serve as the frontline detective monitoring and correlating real-time threat data from firewalls, cloud assets, EDR, and AI-driven platforms like Darktrace. Youll design, tune, and optimize Splunk Enterprise Security dashboards, detection rules, and correlation searches to cut false positives while delivering rapid, high-fidelity alerts. Leveraging your experience SOC environments, youll lead deep incident investigations, spearhead proactive threat-hunting missions, and drive remediation priorities based on risk and business impact. Collaboration is key: youll partner with global engineers, cloud specialists, and incident-response teams to continuously improve our security posture and document best-practice playbooks.
Responsibilities:
- Monitor and analyze security event logs from multiple sources, including firewalls, intrusion detection/prevention systems, endpoint protection platforms, servers, cloud environments, and tools like Darktrace, to identify potential threats.
- Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise Security (ES) platform.
- Assist in improving SIEM processes, detection coverage, alert fidelity, and operational workflows including creating dashboards
- Support the onboarding and integration of logs from enterprise systems into the Splunk environment.
- Validate log source completeness, data normalization, rule logic, and alert relevance across critical systems and infrastructure
- Perform initial analysis of security events, escalate incidents when appropriate, and assist with root cause identification.
- Conduct in-depth investigations of security incidents and recommend remediation and containment actions.
- Conduct proactive threat hunting using SIEM, EDR, CASB, and network detection tools, such as Darktrace, to identify suspicious activity that may have bypassed traditional controls.
- Tune and optimize correlation searches, detection rules, dashboards, and use cases to improve operational efficiency and reduce false positives.
- Prioritize remediation efforts based on risk, severity, and business impact.
- Participate in incident response activities and support threat hunting initiatives as needed.
- Collaborate with cross-functional teams to respond effectively to cybersecurity incidents and strengthen overall security posture.
- Create and maintain documentation for log flows, detection use cases, triage procedures, playbooks, cybersecurity processes, and operational standards.