Proficio is an award-winning managed detection and response (MDR) services provider. We provide 24/7 security monitoring, investigation, alerting and response services to organizations in healthcare, financial services, manufacturing, retail and other industries. Proficio has been highlighted in Gartner’s Market Guide for Managed Detection and Response Services for the last three consecutive years. We have a track record of innovation. Proficio invented the concept of SOC-as-a-Service. We were the first MSSP to provide automated response services and the first in our space to provide a risk scoring dashboard.
Our typical client is a medium to large-sized organization that lacks the in-house resources to address the challenges of a rapidly changing threat landscape. The difficulty of hiring and retaining cybersecurity professionals are widely understood but our prospective clients also struggle to effectively harness technology and build hardened processes.
While Proficio has developed a unified service delivery platform designed to meet the needs of the most demanding clients, what sets us apart is the quality and passion of our people. We believe the SOC of the Future will meld the creativity of human intelligence with the power of advanced technologies like AI.
SUMMARY
The SIEM Infrastructure Engineer reports to our SIEM Infrastructure Engineering Manager and handles production support and onboarding for our Elastic SIEM global customer instances. We are hiring customer-facing entry and mid-level individuals for this team who will be able to organize and drive multiple customer implementations and maintenance scenarios at once. This is a position for a tech-savvy individual so we expect the majority of the work to be done remotely with customer interaction mainly being telephonic, email or video and occasional customer site visits.
- Our SIEM Infrastructure Engineers are security problem solvers! They look at the SIEM Infrastructure and think “problem,” first, “tool set” second. We are tasked today with utilizing the Elastic SIEM to enhance our customers’ security, but we see other products on the horizon. We seek a security minded professional who is creative with their problem-solving skills, adaptable with their tool sets, but also proficient today in the Elastic SIEM product.
- Ability to work in a team: Our US SIEM Infrastructure Engineers do not work in a silo! They are in front of our customers before and after the sales helping to determine needs, find solutions, and outline work to be done. They are supported by a global team of Elastic Stack Architects, Admins and Developers who also execute and support the Elastic implementations we envision. We seek individuals who are able to work in a global team and pass work from shift to shift as needs require. Lone wolves are not allowed!
- Ability to work independently: This is a hybrid position that services customers across the globe. Our staff works both remotely and in office for client meetings and presentations.
- We are doing great things! We want enthusiastic Elastic SIEM professionals who can share our passion with customers. Strong communication skills prior to contract execution will ensure our customers know exactly what to expect during the onboarding process. Continuous relationship building throughout the implementation and maintenance phase will ensure our customers are receiving our best in class service for their cybersecurity needs!
- The nitty gritty: 1-2+ years hands on experience in engineering and supporting a large scale Elastic Stack environment; strong event logging solutions for large corporations is preferred; experienced with multiple security platform administration or engineering within large-scale or global enterprises combined; understanding of Network Firewalls, Load-balancers, and complex network designs; good understanding of Unix/Linux and Windows operating systems, good command on Python, Perl, SQL, Regex and Shell scripting is preferred.
- Specific work history should include knowledge in Terraform, Kubernetes, AWS, and Elasticsearch
- Clear understanding of Elastic's data onboarding process and CIM mapping.
- Ability to define and clearly express work required to customers.
- Ensure security, availability, and confidentiality of all sensitive data collected, processed, or stored by this position
- Opportunity to work in a progressive organization with structured training and roadmap for success
- Health benefits, lunches, gym reimbursement, and fun events for our Singapore staff!
- Experience in one of the hottest IT industries today
Proficio is an EOE employer.
Proficio collects certain personal information upon your submission of an application for an open position. More information is available about your consumer rights and our privacy policy at
Top Skills
What We Do
Proficio is a world-class Managed Security Service Provider (MSSP) providing managed detection and response solutions, 24×7 security monitoring and advanced data breach prevention services to organizations globally.
Our rapid growth is being fueled by the rise in cloud-based services, the acceptance of the Software-as-a-Service (SaaS) model, and the increasing number of cyber security attacks on businesses, hospitals and government. We have developed proprietary security content and threat intelligence tools to identify and proactively defend against advanced attacks and insider threats. Proficio’s founders are veterans of the security and networking industry who have helped guide multiple companies to successful exits.
Proficio’s customers benefit from the most advanced security monitoring and 24×7 managed security services that until recently were outside the budget of all but the very largest enterprises. Proficio’s ProSOC service offerings include the following:
• 24×7 security event monitoring, alerting, and remediation
• Advanced SIEM correlation analysis
• Protection against complex attacks and insider threats
• Actionable intelligence that enables internal IT teams to effectively and quickly resolve issues
• Threat Intelligence
• Active Defense that blocks targeted attacks in real time 24×7
• Worry-free compliance audits for: PCI, HIPAA, SOX, GLBA, FFIEC, NERC CIP, and FISMA regulations
• Visibility to event logs with easy-to-use web portal, powerful reporting, dashboards, and drill-down analytics
• Full management of security devices including patching, health and performance monitoring, and tuning
• Free 12 month log retention
• Out-of-the-box support for 400+ log sources
• Scalable cloud-based deployment – fast implementation and no software or hardware purchases
• Advanced scanning eliminating vulnerabilities before they can be exploited