Cyber Defense Engineer - SIEM

NorthMark Strategies LLC

New York (NY)

On-site

USD 120,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical coverage
Dental & Vision
401(k) match
PTO 25 days + 12 holidays
16 weeks parental leave
Lunch stipend (GrubHub)
Employee assistance program
Life insurance
Disability insurance

Job summary

NorthMark Strategies LLC is seeking a Cyber Defense Engineer – SIEM to architect and implement AI‑driven detections and automation within the SIEM/SOAR stack. You will enhance cyber defense investigations and incident response capabilities across our security program.

The role emphasizes AI/ML for anomaly detection, UEBA, threat correlation, and automated playbooks, collaborating with IT and engineering to ensure telemetry quality and scalable data pipelines.

Qualifications

  • Bachelor’s degree in CS, information security, or a related field.
  • 4–6+ years in cybersecurity engineering, SOC engineering, or insider threat.
  • Demonstrated SIEM engineering and security monitoring at scale.
  • Experience integrating or developing AI/ML capabilities within security operations.

Responsibilities

  • Design, develop, and deploy AI-enhanced detections and automations within the SIEM/SOAR platform.
  • Engineer and optimize SIEM pipelines using AI/ML techniques for anomaly detection and threat correlation.
  • Integrate SIEM with security tools and data sources for a richer monitoring ecosystem.
  • Develop AI-assisted threat detection models, including UEBA and predictive analytics.
  • Collaborate with cyber defense operations to identify threats and capability gaps.
  • Build and maintain automated response orchestration and intelligent playbooks.

Skills

SIEM engineering
AI/ML security
Automation scripting
KQL
Python
PowerShell
API development
Log ingestion
Multi-tenant environments
Self-starter

Education

Bachelor's degree in CS or related field

Tools

Azure Sentinel
Microsoft Defender Suite
SIEM/SOAR tooling

Job description

Cyber Defense Engineer – SIEM

Reports to the Director of Cyber Defense and operates within the Office of the CISO. This role is responsible for architecting, developing, and implementing advanced security solutions that enhance cyber defense investigations and incident response capabilities. The position places a strong emphasis on AI‑driven security engineering, including the development of intelligent detection systems, automation pipelines, and data‑driven defense mechanisms.

Responsibilities
  • Design, develop, and deploy AI‑enhanced detections and automations within the SIEM/SOAR platform to improve signal‑to‑noise ratio and reduce alert fatigue.
  • Engineer and optimize SIEM pipelines using AI/ML techniques for anomaly detection, behavioral analytics, and threat correlation.
  • Integrate SIEM with security tools and data sources to build a context‑rich, intelligence‑driven monitoring ecosystem.
  • Develop and implement AI‑assisted threat detection models, including user/entity behavior analytics (UEBA) and predictive analytics.
  • Collaborate with cyber defense operations to identify emerging threats and capability gaps, leveraging AI to proactively strengthen defenses.
  • Build and maintain automated response orchestration and intelligent playbooks that adapt based on threat context.
  • Design automation for alert enrichment, triage, and response using both rule‑based and AI‑assisted decisioning frameworks.
  • Partner with IT and engineering teams to ensure comprehensive telemetry collection and high‑quality data pipelines.
  • Continuously improve SIEM engineering practices, including data normalization, enrichment strategies, and AI model tuning.
  • Support SOC operations by enhancing detection engineering, incident response workflows, and operational metrics through AI augmentation.
Requirements
  • Bachelor’s degree in computer science, information security, or a related field.
  • 4–6+ years of experience in cybersecurity engineering, SOC engineering, or insider threat.
  • Demonstrated expertise in SIEM engineering and security monitoring at scale.
  • Experience integrating or developing AI/ML capabilities within security operations or detection engineering.
  • Strong understanding of the Microsoft security stack (e.g., Sentinel, Defender suite).
  • Proficiency with automation tooling and scripting languages (KQL, Python, PowerShell).
  • Proficiency in API development with the goal of integrating security tooling.
  • Familiarity with various log ingestion methodologies into a SIEM environment.
  • Experience in multi‑tenant or MSP‑like environments is a plus.
  • Highly motivated self‑starter who thrives on positively influencing the environment.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Benefits & Perks
  • Company‑Paid Lunch Stipend: Lunch is provided via GrubHub.
  • Company‑Paid Benefits: 100% Employer‑Paid Medical in our High Deductible Health Plan, Dental and Vision benefits for employees and their families.
  • 16 weeks of Paid Parental Leave.
  • Employee Assistance Program.
  • Life insurance.
  • Short‑Term and Long‑Term Disability.
  • 401(k): Company will match 100% of contributions up to 6%.
  • Optional Employee‑Paid Benefits: Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub, and more.
  • Time Off: 25 days of Paid Time Off plus 12 company holidays.

EQUAL OPPORTUNITY EMPLOYER
NorthMark Strategies LLC is an equal employment opportunity employer. The company's policy is not to discriminate against any applicant or employee based on race, color, religion, national origin, gender, age, sexual orientation, gender identity or expression, marital status, mental or physical disability, or genetic information, or any other basis protected by applicable law. The firm also prohibits harassment of applicants or employees based on any of these protected categories.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defense - Incident Responder
Cyber Defense - Incident Responder

NorthMark Strategies • Dallas (TX)

On-site
USD 150,000 - 190,000
Lunch stipend
Employer-paid medical (HDHP)
Dental and Vision benefits
+4
Principal Software Engineer, AI SIEM
Principal Software Engineer, AI SIEM

SentinelOne • United States

On-site
USD 216,000 - 297,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Flexible time off
+15
AI-Enhanced SIEM Cyber Defense Engineer
AI-Enhanced SIEM Cyber Defense Engineer

NorthMark Strategies LLC • New York (NY)

On-site
USD 120,000 - 170,000
Medical coverage
Dental & Vision
401(k) match
+6
Cyber Security Engineer
Cyber Security Engineer

empirical Foods • North Sioux City (SD)

On-site
USD 100,000 - 140,000
Health benefits
Dental insurance
Vision insurance
+5
SIEM Engineer
SIEM Engineer

IDBNY • New York

Hybrid
USD 140,000 - 160,000
SIEM Engineer
SIEM Engineer

Cymertek Corporation • Tysons (VA)

On-site
USD 110,000 - 150,000
SIEM Engineer
SIEM Engineer

Cymertek Corporation • Reston (VA)

On-site
USD 110,000 - 170,000
Excellent Salaries
Flexible Work Schedule
Cafeteria Style Benefits
+3
SIEM Engineer
SIEM Engineer

IDBNY • New York (NY)

Hybrid
USD 140,000 - 160,000
Annual bonus
Medical, dental, and vision plans
Life and disability insurance
+5
SIEM Engineer
SIEM Engineer

Cymertek Corporation • Maryland

On-site
USD 120,000 - 180,000
Excellent salaries
Flexible schedule
401k matching
+4
SIEM Engineer
SIEM Engineer

Cymertek Corporation • Chantilly (VA)

On-site
USD 120,000 - 155,000
Excellent Salaries
Flexible schedule
401k Matching
+3