Senior CSIRT Engineer — Remote, SIEM/EDR & SOAR Lead

Webhosting

United States

On-site

USD 110,000 - 130,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical benefits with 100% premiums
401(k) plan with 100% match up to 4%
Professional development stipend

Job summary

Vultr is seeking a Senior CSIRT Engineer to own the SIEM and EDR platforms, build detections, and design automation workflows. You will work with CSIRT Analysts to investigate events, conduct threat hunts, and support incident response, reporting to the Senior Manager of Incident Response.

Cloud experience and advanced certifications are preferred. The role emphasizes building integrations across security tooling, implementing MITRE ATT&CK mappings, and strengthening security visibility across a

Qualifications

  • Experience with cloud infrastructure environments.

Responsibilities

  • Engineer, tune, and maintain detection rules and analytics in the SIEM and EDR platforms.
  • Administer SIEM platform health, parser configuration, log source onboarding, and data pipeline optimization.
  • Design and build SOAR playbooks and automated response workflows to streamline triage, enrichment, and containment.
  • Develop and maintain integrations between security tools (SIEM, EDR, SOAR, SEG, TIP, DLP, ticketing)
  • Map detection coverage to MITRE ATT&CK to identify and close gaps
  • Identify and drive improvements to security visibility across the environment, including new log sources, enrichment opportunities, and telemetry gaps
  • Assist with investigation of security events, from alert through remediation
  • Assist with conducting threat hunts across organizational telemetry
  • Assist incident response with log analysis, artifact collection, and containment
  • Manage EDR platform coverage, sensor health, and policy configuration
  • Coordinate with Threat Intelligence to translate intel into deployed, actionable detection logic
  • Coordinate with Security Engineering on infrastructure integrations and log pipeline architecture
  • Document detection logic, automation workflows, and operational procedures
  • Experience with cloud infrastructure environments
  • Familiarity with data loss prevention concepts and insider threat detection patterns
  • Certifications such as BTL1, BTL2, CCD, CCSP, CKA, CKS, CJDE, CISSP, GCDA, GCED, GCFA, GCIH, GCIA, GCTD, GNFA, etc.
  • Experience in SOC2, ISO 27001, FedRAMP, or GDPR environments.

Skills

SIEM/EDR
SOAR
Threat hunting
Automation workflows
MITRE ATT&CK mapping
Incident response
Cloud infrastructure

Education

Certifications: BTL1
Certifications: BTL2
Certifications: CCD
Certifications: CCSP
Certifications: CISSP
Certifications: GCFA
Certifications: GCIH

Tools

SIEM
EDR
SOAR
SEG
TIP
DLP
Ticketing systems

Job description

Vultr is seeking a Senior CSIRT Engineer to own the SIEM and EDR platforms, build detections, and design automation workflows. You will work with CSIRT Analysts to investigate events, conduct threat hunts, and support incident response, reporting to the Senior Manager of Incident Response.

Cloud experience and advanced certifications are preferred. The role emphasizes building integrations across security tooling, implementing MITRE ATT&CK mappings, and strengthening security visibility across a

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Senior SIEM Engineer — Cloud & On-Prem
Remote Senior SIEM Engineer — Cloud & On-Prem

ECS • Richmond (VA)

On-site
USD 120,000 - 170,000
Senior Cybersecurity Engineer: EDR, SIEM & AI Security
Senior Cybersecurity Engineer: EDR, SIEM & AI Security

redesigncareers • United States

On-site
USD 120,000 - 150,000
Remote Senior Security Analyst - Elastic SIEM
Remote Senior Security Analyst - Elastic SIEM

ecsfederal • Virginia (MN)

Hybrid
USD 90,000 - 120,000
US Passport required
Secret clearance preferred
Domestic travel
Remote Threat Detection & Response Engineer — IR & SOC
Remote Threat Detection & Response Engineer — IR & SOC

Whatnot • United States

Remote
USD 120,000 - 170,000
Health Insurance
401(k) with employer match
Work From Home Support
+2
Senior SIEM Engineer — Remote
Senior SIEM Engineer — Remote

ecsfederal • Virginia (MN)

Hybrid
USD 120,000 - 170,000
Senior Detection & Response Engineer — SIEM & Threat Hunt
Senior Detection & Response Engineer — SIEM & Threat Hunt

Cedarparktexasedc • Austin (TX)

On-site
USD 140,000 - 190,000
Remote SIEM Engineer: Detection & Analytics Lead
Remote SIEM Engineer: Detection & Analytics Lead

PowerToFly • Washington

On-site
USD 89,000 - 163,000
Senior SIEM & Incident Response Engineer (Remote)
Senior SIEM & Incident Response Engineer (Remote)

Empower AI • United States

Hybrid
USD 87,000 - 135,000
Senior Cloud Security Engineer: SIEM & IR (Remote)
Senior Cloud Security Engineer: SIEM & IR (Remote)

SmarterDx, Inc. • United States

Remote
USD 190,000 - 220,000
Medical, Dental & Vision
Remote-First Team
Unlimited PTO & 10 Holidays
+3
Senior SIEM & SOAR Platform Engineer
Senior SIEM & SOAR Platform Engineer

Center for Internet Security, Inc. • United States

Remote
USD 129,000 - 225,000
Health insurance
401(k) with company match
Paid time off