This position will be a part of the Industrial Cyber-Security team and will participate in delivering and developing cyber security services for a wide range of industrial global customers. The position will have a direct reporting relationship to the Global Security Operation Center Manager and Incident Response Lead and work as part of a global managed services team.
You will report directly to our Sr. Cyber Security Manager and you’ll work out of our Duluth, GA. location on a Hybrid work schedule.
The position requires very good cyber security knowledge, excellent analytical skills and proficient handling of specific tools such as SIEMs and Security Orchestration, Automation and Response platforms. A successful candidate would be able to evaluate security incidents and determine true positives situations within an environment and provide context enrichment service before escalation to Level 3 Cyber Security Incident Response team as needed.
Responsibilities
KEY RESPONSIBILITIES
- Monitors SIEM, trouble tickets / email notifications and in-person escalations, logs from ICS infrastructure components (SCADA, HMI, PLC, RTU, Control Servers), applications or network devices such as switches, firewalls, IDS/IPS;
- Design, implement, test Security Orchestration, Automation and Response processes and procedures;
- SOAR playbook development and troubleshoot automation capabilities;
- Examine the escalated tickets to determine if they are true positive or false positives.
- Performs malware analysis, threat hunting and threat modeling activities;
- Assist forensic investigation by providing reports and other information;
- Reviews and suggests improvements to control deployment process and installation procedures
- Develops and documents remediation recommendations for business owners to improve the control environment in which a security incident occurs. Recommendations must be easily understood by non-technical staff;
- Provide recommendations and direction on the tuning of signatures, rules, alerts, parsers, and custom scripts within the monitoring solutions;
Participates in root cause analysis and helps with the orchestration of remediation; - Understand defense in depth strategies and apply those to Client’s environment;
Creates and disseminates security related notifications for internal staff (for example: trends, developments, changes in capabilities); - Acts as L2 Escalation layer in the SOC.
- Mentors Level 1 SOC Analysts;
- Creates manuals, guides and knowledge base entries;
- Keep abreast of latest security and privacy legislation, emerging threats, regulations, advisories, alerts, and vulnerabilities pertaining to HCE OT IR SOC and its customers;
- Remains knowledgeable of our current solution portfolio and the technical specificities of our offerings.
YOU MUST HAVE
- 7+ years of experience in Information Technology, cybersecurity, or a related technical field.
- 5+ years of experience working in a Security Operations Center (SOC), cybersecurity operations, incident response, or a related security function.
- 5+ years of experience working with Security Information and Event Management (SIEM) or Security Orchestration, Automation and Response (SOAR) technologies.
- 5+ years of experience developing or implementing security automation using Python, SOAR platforms, or similar technologies.
WE VALUE
- Bachelor’s degree in Computer Science, Computer Information Systems, Electronics, or a related field.
- ITIL Foundation certification or a cybersecurity certification such as CompTIA Security+, GCIH, CCNA, GCFA, or CEH.
- Experience with SIEM platforms and security logging solutions such as Swimlane, Sentinel, or GOOGLE SECOPS.
BENEFITS OF WORKING FOR HONEYWELL
In addition to a competitive salary, leading-edge work, and developing solutions side-by-side with dedicated experts in their fields, Honeywell employees are eligible for a comprehensive benefits package. This package includes employer subsidized Medical, Dental, Vision, and Life Insurance; Short-Term and Long-Term Disability; 401(k) match, Flexible Spending Accounts, Health Savings Accounts, EAP, and Educational Assistance; Parental Leave, Paid Time Off (for vacation, personal business, sick time, and parental leave), and 12 Paid Holidays. Learn more (https://benefits.honeywell.com/)
The application period for the job is estimated to be 40 days from the job posting date; however, this may be shortened or extended depending on business needs and the availability of qualified candidates.
ABOUT HONEYWELL
Honeywell International Inc. (Nasdaq: HON) invents and commercializes technologies that address some of the world's most critical challenges around energy, safety, security, productivity, and global urbanization. We are a leading software-industrial company committed to introducing state of the art technology solutions to improve efficiency, productivity, sustainability, and safety in high growth businesses in broad-based, attractive industrial end markets. Our products and solutions enable a safer, more comfortable, and more productive world, enhancing the quality of life of people around the globe. Learn more (https://www.honeywell.com/us/en)
U.S. PERSON REQUIREMENTS
Due to compliance with U.S. export control laws and regulations, candidate must be a U.S. Person, which is defined as, a U.S. citizen, a U.S. permanent resident, or have protected status in the U.S. under asylum or refugee status or have the ability to obtain an export authorization.
.
Skills Required
- 7+ years of experience in information technology, cybersecurity, or a related technical field
- 5+ years of experience in a Security Operations Center, cybersecurity operations, incident response, or related security function
- 5+ years of experience working with SIEM or SOAR technologies
- 5+ years of experience developing or implementing security automation using Python, SOAR platforms, or similar technologies
- Bachelor's degree in Computer Science, Computer Information Systems, Electronics, or a related field
- ITIL Foundation or cybersecurity certification such as CompTIA Security+, GCIH, CCNA, GCFA, or CEH
- Experience with SIEM platforms and security logging solutions such as Swimlane, Sentinel, or Google SecOps
- Must be a U.S. Person or have the ability to obtain export authorization under U.S. export control laws
Honeywell Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Honeywell and has not been reviewed or approved by Honeywell.
-
Retirement Support — Retirement benefits are anchored by a strong 401(k) match with clear vesting and annual funding mechanics. Plan administration and education resources further reinforce long‑term savings support.
-
Leave & Time Off Breadth — Time away provisions include company holidays, flexible vacation for many exempt roles, and paid sick time. These policies contribute meaningful breadth beyond base pay.
-
Parental & Family Support — Paid parental leave is available to all parents with flexible usage options, and certain family‑building supports are included. Birth mothers can coordinate leave with short‑term disability for extended coverage.
Honeywell Insights
What We Do
Honeywell is a Fortune 500 company that invents and manufactures technologies to address tough challenges linked to global macrotrends such as safety, security, and energy. With approximately 110,000 employees worldwide, including more than 19,000 engineers and scientists, we have an unrelenting focus on quality, delivery, value, and technology in everything we make and do.






