Information Security Engineer - IS Mod
The Information Security Detection Engineer is responsible for the operational health, data quality, and detection effectiveness of Exabeam, a critical security analytics and UEBA platform. This role combines detection engineering, data engineering, and platform support responsibilities to ensure reliable security analytics, high-fidelity detection content, and effective integration with Google SecOps and other enterprise security technologies.
Key Responsibilities
• Develop, tune, and maintain custom detection content within Exabeam.
• Manage the onboarding, validation, and optimization of log sources and enrichment data supporting Exabeam analytics.
• Monitor and maintain the operational health, performance, and stability of Exabeam, including data ingestion pipelines and parser functionality.
• Coordinate with Exabeam to troubleshoot platform, data, integration, and content-related issues.
• Develop and maintain parsers, data transformations, and normalization processes required to support accurate analytics and investigations.
• Perform capacity planning and utilization management to support platform growth and licensing constraints.
• Collaborate with CSOC, Threat Intelligence, Insider Risk, and other stakeholders to operationalize detection use cases and continuously improve Mayo Clinic's threat detection and security monitoring capabilities.
This is a hybrid position and incumbent must live within 100 miles of a Mayo Clinic campus. Mayo Clinic will not sponsor or transfer visas for this position including F1 OPT STEM.
Bachelor's degree and four (4) years experience in the information security field required, OR Associates degree and 6 years' experience in the information security field. Pertinent fields of study include Computer Science, Information Systems, Engineering or related field.
Master's Degree in applicable field and two (2) years experience preferred. Pertinent fields of study include Computer Science, Information Systems, Engineering or related field.
One or more of the following certifications (or equivalent) are required at time of hire or must be obtained within two years of hire: CISSP, CISM, GSEC, OSCP.