Principal SIEM Architect: Scale, Automation & Detection

Ally

Detroit (MI)

Hybrid

USD 140,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Ally is seeking a Principal Cyber Security Engineer to own the end-to-end SIEM lifecycle, from data onboarding to content engineering and automation. You will collaborate with SOC analysts, incident responders, threat hunters, and IT teams to ensure high‑fidelity detections and compliant log management.

The ideal candidate has 5+ years of SIEM experience and a strong track record with enterprise platforms such as Splunk and Cribl.

Qualifications

  • 5+ years of experience in SIEM engineering or closely related security engineering roles.
  • Bachelor’s degree in Computer Science, Information Security, or related field; or equivalent experience.
  • Proven expertise with at least one enterprise SIEM platform end‑to‑end, preferably Splunk and Cribl (e.g., Splunk, Microsoft Sentinel, QRadar, Elastic Security, Exabeam, Sumo Logic, LogRh

Responsibilities

  • Design and maintain the SIEM architecture, including data ingestion pipelines, parsers, normalization schemas, storage tiers, and retention strategies.
  • Evaluate and implement SIEM platform features and integrations; drive upgrades and migrations as needed.
  • Onboard logs from diverse sources (EDR, firewalls, IDS/IPS, IAM, AD, DNS, proxies, email security, cloud platforms like AWS/Azure/GCP, SaaS apps, containers/Kubernetes, DBs, identity providers).
  • Implement data quality monitoring and SLA-driven dashboards for ingestion health, parser accuracy, and data latency.
  • Optimize SIEM performance: indexing, search speed, hot/warm/cold storage, retention, and cost control.
  • Implement role‑based access control, multitenancy (if applicable), and data governance.
  • Ensure high availability and disaster recovery; document and test failover procedures.
  • Define KPIs/KRIs (e.g., MTTD, alert quality, data freshness, coverage, false positive rate).
  • Handle purple‑team exercises and detection gap assessments; drive remediation.
  • Provide runbooks, knowledge base articles, and training to SOC and IT teams.
  • Align SIEM data handling with regulatory and contractual requirement (e.g., SOC 2, ISO 27001, PCI‑DSS, HIPAA, GDPR).
  • Implement data minimization, masking, and retention policies, support audits and eDiscovery.
  • Partner with IT/Cloud/Data teams to implement logging at source and ensure secure, reliable transport.
  • Contribute to security architecture reviews for new systems and applications.

Skills

SIEM engineering
Security engineering

Education

Bachelor’s degree in Computer Science / Information Security or related field

Tools

Splunk
Cribl
Microsoft Sentinel
QRadar
Elastic Security

Job description

Ally is seeking a Principal Cyber Security Engineer to own the end-to-end SIEM lifecycle, from data onboarding to content engineering and automation. You will collaborate with SOC analysts, incident responders, threat hunters, and IT teams to ensure high‑fidelity detections and compliant log management.

The ideal candidate has 5+ years of SIEM experience and a strong track record with enterprise platforms such as Splunk and Cribl.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SIEM Architect & Threat Detection Leader
Senior SIEM Architect & Threat Detection Leader

Ally Bank • Detroit (MI)

Hybrid
USD 110,000 - 180,000
Total Rewards program
Time Away: 20 PTO days plus holidays
Relocation assistance
+1
Senior SIEM Architect & Threat Detection Lead (Hybrid/Remote)
Senior SIEM Architect & Threat Detection Lead (Hybrid/Remote)

Ally Bank • New York (NY)

Hybrid
USD 110,000 - 180,000
Time off & holidays
401K with match
Healthcare benefits
Senior SIEM Architect - Hybrid/Remote
Senior SIEM Architect - Hybrid/Remote

Ally-Financial • Detroit (MI)

Hybrid
USD 110,000 - 180,000
Time off and holidays
401K matching and financial wellness
Health insurance
+1
Principal Cyber Security Engineer
Principal Cyber Security Engineer

Ally • Detroit (MI)

Hybrid
USD 140,000 - 190,000
Principal SIEM Architect & Threat Detection Lead
Principal SIEM Architect & Threat Detection Lead

Cybersecurity Jobs • Detroit (MI)

On-site
USD 110,000 - 180,000
20 paid time off days
11 paid holidays
401(k) retirement plan
+2
Senior SIEM & SOAR Platform Engineer
Senior SIEM & SOAR Platform Engineer

Center for Internet Security, Inc. • United States

Remote
USD 129,000 - 225,000
Health insurance
401(k) with company match
Paid time off
Remote SIEM Engineer: Detection & Analytics Lead
Remote SIEM Engineer: Detection & Analytics Lead

PowerToFly • Washington

On-site
USD 89,000 - 163,000
IT Security Engineer
IT Security Engineer

Pike Corporation • Fort Mill (SC)

On-site
USD 120,000 - 180,000
Senior SOC Engineer – SIEM & Detection Lead
Senior SOC Engineer – SIEM & Detection Lead

Pike Corporation • Fort Mill (SC)

On-site
USD 120,000 - 180,000
Sr SIEM Data Engineer
Sr SIEM Data Engineer

Shain Associates • Quincy (MA)

Hybrid
USD 140,000 - 190,000