This position will be a part of the Industrial Cyber-Security team and will participate in delivering and developing cyber security services for a wide range of industrial global customers. The position will have a direct reporting relationship to the Global Security Operation Center Manager and Incident Response Lead and work as part of a global managed services team. You will report directly to our Sr. Cyber Security Manager and you’ll work out of our Duluth, GA. location on a Hybrid work schedule. The position requires very good cyber security knowledge, excellent analytical skills and proficient handling of specific tools such as SIEMs and Security Orchestration, Automation and Response platforms. A successful candidate would be able to evaluate security incidents and determine true positives situations within an environment and provide context enrichment service before escalation to Level 3 Cyber Security Incident Response team as needed. KEY RESPONSIBILITIES Monitors SIEM, trouble tickets / email notifications and in-person escalations, logs from ICS infrastructure components (SCADA, HMI, PLC, RTU, Control Servers), applications or network devices such as switches, firewalls, IDS/IPS; Design, implement, test Security Orchestration, Automation and Response processes and procedures; SOAR playbook development and troubleshoot automation capabilities; Examine the escalated tickets to determine if they are true positive or false positives. Performs malware analysis, threat hunting and threat modeling activities; Assist forensic investigation by providing reports and other information; Reviews and suggests improvements to control deployment process and installation procedures Develops and documents remediation recommendations for business owners to improve the control environment in which a security incident occurs. Recommendations must be easily understood by non-technical staff; Provide recommendations and direction on the tuning of signatures, rules, alerts, parsers, and custom scripts within the monitoring solutions; Participates in root cause analysis and helps with the orchestration of remediation; Understand defense in depth strategies and apply those to Client’s environment; Creates and disseminates security related notifications for internal staff (for example: trends, developments, changes in capabilities); Acts as L2 Escalation layer in the SOC. Mentors Level 1 SOC Analysts; Creates manuals, guides and knowledge base entries; Keep abreast of latest security and privacy legislation, emerging threats, regulations, advisories, alerts, and vulnerabilities pertaining to HCE OT IR SOC and its customers; Remains knowledgeable of our current solution portfolio and the technical specificities of our offerings. YOU MUST HAVE 7+ years of experience in Information Technology, cybersecurity, or a related technical field. 5+ years of experience working in a Security Operations Center (SOC), cybersecurity operations, incident response, or a related security function. 5+ years of experience working with Security Information and Event Management (SIEM) or Security Orchestration, Automation and Response (SOAR) technologies. 5+ years of experience developing or implementing security automation using Python, SOAR platforms, or similar technologies. WE VALUE Bachelor’s degree in Computer Science, Computer Information Systems, Electronics, or a related field. ITIL Foundation certification or a cybersecurity certification such as CompTIA Security+, GCIH, CCNA, GCFA, or CEH. Experience with SIEM platforms and security logging solutions such as Swimlane, Sentinel, or GOOGLE SECOPS. BENEFITS OF WORKING FOR HONEYWELL In addition to a competitive salary, leading-edge work, and developing solutions side-by-side with dedicated experts in their fields, Honeywell employees are eligible for a comprehensive benefits package. This package includes employer subsidized Medical, Dental, Vision, and Life Insurance; Short-Term and Long-Term Disability; 401(k) match, Flexible Spending Accounts, Health Savings Accounts, EAP, and Educational Assistance; Parental Leave, Paid Time Off (for vacation, personal business, sick time, and parental leave), and 12 Paid Holidays. Learn more (https://benefits.honeywell.com/) The application period for the job is estimated to be 40 days from the job posting date; however, this may be shortened or extended depending on business needs and the availability of qualified candidates. ABOUT HONEYWELL Honeywell International Inc. (Nasdaq: HON) invents and commercializes technologies that address some of the world's most critical challenges around energy, safety, security, productivity, and global urbanization. We are a leading software-industrial company committed to introducing state of the art technology solutions to improve efficiency, productivity, sustainability, and safety in high growth businesses in broad-based, attractive industrial end markets. Our products and solutions enable a safer, more comfortable, and more productive world, enhancing the quality of life of people around the globe. Learn more (https://www.honeywell.com/us/en) U.S. PERSON REQUIREMENTS Due to compliance with U.S. export control laws and regulations, candidate must be a U.S. Person, which is defined as, a U.S. citizen, a U.S. permanent resident, or have protected status in the U.S. under asylum or refugee status or have the ability to obtain an export authorization.
Cyber Security Architect/Engineer I
Honeywell
Sr. Engineer, Information Security Architect
Lovesac Company
Technical Lead Chief Security Architect / Engineer
9th Way Insignia
Associate Principal Engineer - Snowflake AI Architect
Nagarro
AWS Cloud Solutions Architect / Cloud Engineer 6015-1
Triforce Inc
AI Architect/AI Engineer – Generative & Agentic AI
Cencora