Lead, Info Security Systems

Job Type:  Full-Time
Location Type:  Hybrid
Primary Location: 

Atlanta, Georgia, US

W3Schools.com

Job ID: 16337 

Alternate Locations:  

 

Newell Brands is a leading consumer products company with a portfolio of iconic brands like Graco®, Coleman®, Oster®, Rubbermaid®, Sharpie® and Yankee Candle® - and 24,000 talented teammates around the world. Our culture is built on values in action: Integrity, Teamwork, Passion for Winning, Ownership, and Leadership. We work together to win, grow, and make a real impact—supported by a high-performing, inclusive, and collaborative environment where you can be your best, every day. 

 

Position Title: Senior CyberSecurity Specialist - Engineer (SIEM/SOAR)

Location: Remote

Reports To: Senior Manager, Security Engineering

 

 

Company Overview

 

 

Newell Brands (NASDAQ: NWL) is a leading global consumer goods company with a strong portfolio of well-known brands, including Rubbermaid®, Paper Mate®, Sharpie®, Dymo®, EXPO®, Parker®, Elmer’s®, Coleman®, Marmot®, Oster®, Sunbeam®, FoodSaver®, Mr. Coffee®, Rubbermaid Commercial Products®, Graco®, Baby Jogger®, NUK®, Calphalon®, Contigo®, Mapa®, Spontex® and Yankee Candle®.  Newell Brands is committed to enhancing the lives of consumers around the world with planet friendly, innovative, and attractive products that create moments of joy and provide peace of mind.

 

 

Job Summary

 

 

The Senior Cybersecurity Specialist - Engineer (SIEM/SOAR) is a hands-on engineering role responsible for the design, build, and continuous optimization of Newell Brands’ SIEM and SOAR capabilities. This role owns the full lifecycle of detection engineering – from ingestion and correlation through automated response – and serves as the technical authority for SOAR playbook development and AI-driven workflow automation across the Security Operations function. This is a conversion of a current contractor engagement into a full-time position, enabling expanded scope, deeper cross-team integration, and long-term program ownership.

 

 

Key Responsibilities

 

 

  • Own SIEM architecture, content development, and ongoing tuning including log source onboarding, parsing, normalization, and field mapping
  • Serve as the primary engagement lead for internal SIEM customer teams, owning recurring touchpoints with data owners and data consumers and ensuring consistent service experience
  • Manage the intake and lifecycle of customer requests from initial capture through structured triage to fulfillment
  • Serve as the primary administrator, technical lead, and subject matter expert for Cribl Stream hybrid deployment, owning all sources, destinations, routes and processing pipelines across cloud and on-premises worker groups
  • Lead Cribl Edge expansion by engaging data owners on agent deployment and validating collection health for newly onboarded sources
  • Support administering multi-tenant CrowdStrike NG-SIEM environment, managing child tenant log source retention and RBAC for content and data repositories
  • Build and maintain alerting, monitoring, and forecasting of data health and license usage for data ingestion and SIEM platforms
  • Develop and maintain high-fidelity detection rules, correlation logic, and threat-based use cases aligned to MITRE ATT&CK in support of data consumers
  • Continuously measure and report detection coverage gaps and use-case performance (false positive rate)
  • Own the full Falcon Fusion SOAR environment: design, build, test, and maintain automated response playbooks across the incident lifecycle
  • Develop AI-assisted triage workflows that classify alerts, enrich cases with threat intel, and route to the correct analyst or automated response path
  • Integrate SOAR with security tooling across the stack: CrowdStrike, Palo Alto, Microsoft Defender, Tenable, Wiz, and external threat intelligence feeds
  • Document all playbooks with runbooks, decision logic, and exception handling so continuity does not depend on a single engineer
  • Define and maintain SOAR SLAs and operational metrics including auto-close rates, escalation thresholds, and analyst workload distribution
  • Lead development of AI-augmented detection and response workflows including LLM-assisted alert summarization, entity enrichment, and automated analyst briefing generation
  • Evaluate and prototype emerging SIEM/SOAR AI capabilities and make adoption recommendations aligned to Newell’s AI governance framework
  • Partner with the AI/Agentic Security governance initiative to ensure SOAR automation meets non-human identity (NHI) controls and agentic risk requirements
  • Own MTTD and MTTR metrics for SIEM-generated alerts; translate operational metrics into presentation-ready content covering active projects, accomplishments, and trends for Security Engineering leadership
  • Support incident response by providing platform-level investigation capability and post-incident forensic log review
  • Participate in threat hunts by developing hunt-specific queries and detection logic from threat intelligence inputs

 

 

Required Qualifications

 

 

  • 5+ years of hands-on SIEM engineering experience including platform administration, log source integration, content building, data enrichment and detection rule development
  • 3+ years of SOAR development experience: playbook design, automation logic, API integrations, and incident case management
  • Demonstrated proficiency with at least one enterprise SIEM platform (CrowdStrike NG-SIEM, Microsoft Sentinel, Splunk, IBM QRadar, or equivalent)
  • Hands-on experience with Cribl Stream hybrid deployment or comparable log pipeline technology
  • Proficiency in at least one scripting or query language such as Python or Powershell
  • Expert-level proficiency in at least one SIEM query language such as CQL or SPL, demonstrating the ability to author complex and performance-tuned queries from scratch
  • Working knowledge of MITRE ATT&CK framework and application to detection use case development
  • Experience integrating SOAR with EDR, firewall, vulnerability management, and identity platforms via APIs
  • Strong written communication: ability to document technical logic, playbooks, and runbooks to an operational standard
  • Bachelor's degree in Computer Science, Information Security, or equivalent practical experience

 

 

Preferred Qualifications

 

 

  • Experience with SOAR configuration management and administration (Falcon Fusion SOAR, Microsoft Sentinel SOAR, Splunk SOAR) in an enterprise environment
  • Exposure to LLM-assisted security tooling, prompt engineering for security use cases, or AI-augmented SOC workflows
  • Familiarity with non-human identity (NHI) monitoring and agentic risk controls
  • Experience in a manufacturing, retail, or consumer goods environment with OT/IT convergence exposure
  • Certifications: CrowdStrike Certified SIEM Engineer, SC-200 (Microsoft Sentinel), Splunk Core Certified Power User, SANS GIAC GCED, or equivalent
  • Familiarity with CrowdStrike Falcon, Palo Alto Cortex XSOAR, or Splunk Cloud enterprise deployments

 

The Remote base pay range for this position is from $108,000 to $138,600. Salary will be based on prior experience related to the skills required for this position.

 

 

Newell Brands (NASDAQ: NWL) is a leading global consumer goods company with a strong portfolio of well-known brands, including Rubbermaid, Sharpie, Graco, Coleman, Rubbermaid Commercial Products, Yankee Candle, Paper Mate, FoodSaver, Dymo, EXPO, Elmer’s, Oster, NUK, Spontex and Campingaz. We are focused on delighting consumers by lighting up everyday moments. Newell Brands and its subsidiaries are Equal Opportunity Employers and comply with applicable employment laws. EOE/M/F/Vet/Disabled are encouraged to apply. 

Date Posted:  Jul 28, 2026