Senior Information Security Engineer – SIEM and Detection

Faegre-Drinker-Biddle-

Philadelphia (Philadelphia County)

Hybrid

USD 160,000 - 183,000

Full time

9 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work environment
Wellness programming
Health plan options
Dental and vision
401(k) plan
Paid time off

Job summary

Faegre Drinker Biddle & Reath LLP seeks a Senior Information Security Engineer – SIEM and Detection to support its Technology & Innovation team across Philadelphia, NYC, or DC. You will own the firm’s SIEM platform, onboard log sources, and design detection rules aligned with MITRE ATT&CK.

You will lead IR activities, maintain IR playbooks, and coordinate with CrowdStrike and other security tools to strengthen monitoring and response capabilities for client confidentiality and regulatory needs.

Qualifications

  • Bachelor's degree in cybersecurity or related field or equivalent experience.
  • 8+ years in information security with security operations and IR.
  • Hands-on SIEM engineering: log onboarding, parsing, normalization.
  • Experience tuning detections with MITRE ATT&CK awareness.
  • Proven leadership in incident response and playbooks.

Responsibilities

  • Own SIEM architecture, config, health and cost management with partners.
  • Onboard log sources across Defender, Entra ID, 365, Purview, CrowdStrike.
  • Design and tune detection rules mapped to MITRE ATT&CK.
  • Lead Security Incident Response Team investigations and recovery.
  • Maintain Incident Response Plans and run tabletop exercises.
  • Configure CrowdStrike Falcon across endpoints and identities.

Skills

SIEM engineering
Detections tuning
EDR configuration
Incident response
Managed services liaison
Microsoft security tooling
MITRE ATT&CK knowledge
KQL queries

Education

Bachelor's degree in cybersecurity or related field

Tools

CrowdStrike Falcon
Microsoft Defender
Microsoft Entra ID
Microsoft 365
Microsoft Purview

Job description

Faegre Drinker is a firm designed for clients and designed for you. We understand that our people are critical to our success and we are committed to investing in our paraprofessional, administrative and operations professionals. We are always looking for talented, service-focused individuals to join our flexible and high-performing culture. With technology tools and resources that support our hybrid work environment, our colleagues enjoy a culture of learning, support for work and personal goals, opportunities to give back to our communities, and competitive benefits and rewards programs. At Faegre Drinker, you will have the opportunity to share your expertise within and across teams and contribute to our success.Job Description Summary:Faegre Drinker has an opportunity for a Senior Information Security Engineer – SIEM and Detection to work with our Technology & Innovation team in our Philadelphia, New York City, or Washington, D.C. offices. You will be part of a dynamic team responsible for owning the firm’s security monitoring platform and the detection capability built on it. This position will work with other talented individuals who share a passion for doing great work in the best interest of our clients.Job Description:What you would do:Owns the architecture, configuration, health, and performance of the firm’s SIEM platform, including data ingestion, parsing, normalization, retention, and cost management, in partnership with CrowdStrike as the managed security service providerOnboards and maintains log sources across Microsoft Defender, Microsoft Entra ID, Microsoft 365, Microsoft Purview, Azure, CrowdStrike, network and firewall infrastructure, and key business applications, using Event Hub, Graph API, and native connectors as appropriateDesigns, builds, tests, and tunes detection rules and analytics mapped to the MITRE ATT&CK framework, prioritizing coverage based on the firm’s threat profile and riskServes as senior technical lead for the Security Incident Response Team, guiding investigations from analysis and containment through recovery and reporting, and advising the Director and leadership on response decisionsOwns the firm’s Incident Response Plan and playbooks, maintaining them as the firm’s environment, threats, and regulatory obligations evolveOwns the configuration of the CrowdStrike Falcon platform and its related modules across all firm endpoints and identities, including EDR, Identity Protection, Data Protection, prevention and update policies, integrations, and day-to-day tuning, along with adjacent security technologies that feed or act on Falcon dataBuilds security automation and orchestration workflows for common response actions, enrichment, and case management, integrating the SIEM, CrowdStrike, and ServiceNowSpecial projects and other duties as assignedWhat is expected:Ability to problem-solveExcellent interpersonal, verbal and written communication skills, including the ability to communicate effectively in a virtual environment (e.g., via phone, web/videoconference)Ability to concentrate on tasks, make decisions and work calmly and effectively in a high-pressure, deadline-orientated environmentDemonstrated ability to use good judgment in taking initiative while asking for direction or clarification and consulting others, as appropriateWillingness to be flexible with time and adjust to a changing work environmentAbility to build and maintain positive relationships, both internally and externally, while maintaining a client service orientationAbility to use sound judgment and discretion in dealing with highly confidential informationAbility to take direction and accept supervisionDemonstrated ability to work independently, organize and accurately prioritize work, be detail-oriented, understand when urgency is required and use good judgment in varied situationsAbility to work effectively with co-workers in a team oriented collaborative environmentWhat we offer:Flexible working environment for work-life successOpportunity to participate in firm-sponsored volunteer eventsWellness programming with personalized content and activitiesProfessional environment and the opportunity to work with experts at the top of their fieldsVariety of health plan options, as well as dental, vision and 401(k) plansGenerous paid time offThe anticipated initial salary for someone who is hired into this position is $160,200 - $183,100.Actual initial salary may be above or below the above-identified range and will be based on the relevant skills, training, experience, and other job-related factors, including the location where the position is filled, in all cases consistent with applicable law. This is an exempt role and the initial salary range listed above is just one component of Faegre Drinker's total compensation and benefits package for professional staff, which includes, but is not limited to, a discretionary bonus; life, health, accident, and disability insurance; and a 401(k) plan.What is required:Bachelor’s degree in cybersecurity, information systems, or a related field, or equivalent years of experienceEight years or more of relevant information security experience, including security operations and incident response in an enterprise environmentHands-on experience engineering a SIEM platform, including log source onboarding, forwarding infrastructure, parsing and normalization, and at least one major deployment or migrationExperience developing and tuning detections, with working knowledge of the MITRE ATT&CK framework and query languages such as KQL or equivalentExperience owning the configuration of an enterprise EDR platform, including policy management, tuning, integrations, and containment actions. CrowdStrike Falcon experience strongly preferredDemonstrated experience leading incident response, including building or maintaining incident response plans and playbooks and running tabletop exercisesExperience managing a managed detection and response or managed security service provider relationship as the primary technical counterpart, including tuning, escalation, and service reviewsWorking knowledge of Microsoft security tooling, including Microsoft Defender, Microsoft Entra ID, Microsoft 365, and Microsoft PurviewWorking knowledge of network security, firewalls, and email security controls.Thorough understanding of current security principles, techniques, and protocols.Ability to effectively communicate information security issues, risks, and recommendations to both technical and non-technical peers and management, including through well-written reportsApply now if you are ready to join the Faegre Drinker team!Faegre Drinker Biddle & Reath LLP participates in the federal government's E-Verify program. With all new hires, we provide the Social Security Administration and, when applicable, the US Department of Homeland Security with information from each new employee's Form I-9 to confirm work authorization.Faegre Drinker Biddle & Reath LLP is an Equal Opportunity Employer and is committed to providing equal employment opportunities to all employees and applicants for employment. We do not discriminate on the basis of race, color, religion, age, national origin, disability, sex, sexual orientation, gender, gender identity, gender expression, marital status, veteran or military status, or any other characteristic made unlawful by applicable federal, state or local laws. Equal employment opportunity will be extended to all persons in all aspects of employment, including retirement, hiring, training, promotion, transfer, compensation, benefits, discipline and termination.Notice to Recruiters and Staffing Agencies: Faegre Drinker Biddle & Reath (and any subsidiary) has an internal recruiting department and does not accept unsolicited resumes.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Engineer - SIEM and Detection
Senior Information Security Engineer - SIEM and Detection

esswd • Philadelphia

Hybrid
USD 160,000 - 183,000
Flexible working environment for work–
Volunteer events
Wellness programming
+4
Information Security Engineer - Threat and Vulnerability Management
Information Security Engineer - Threat and Vulnerability Management

esswd • Philadelphia

Hybrid
USD 122,000 - 138,000
Flexible working environment
Volunteer events
Wellness programs
+3
Human Resources Business Partner
Human Resources Business Partner

Faegre Drinker Biddle & Reath LLP • Philadelphia

Hybrid
USD 95,000 - 140,000
Flexible working environment
Volunteer opportunities
Wellness programs
+3
Senior Information Security Engineer - AI & Application Security
Senior Information Security Engineer - AI & Application Security

esswd • New York (NY)

Hybrid
USD 160,000 - 183,000
Flexible working environment
Volunteer events
Wellness programming
+1
Director of Financial & Strategic Analysis
Director of Financial & Strategic Analysis

Faegre Drinker Biddle & Reath LLP • Chicago (IL)

Hybrid
USD 189,000 - 293,000
Flexible working environment
Volunteer events
Wellness programming
Human Resources Business Partner
Human Resources Business Partner

Faegre Drinker • Pennsylvania

On-site
USD 90,000 - 120,000
Flexible work environment
Volunteer events
Wellness programs
+3
Director of Financial & Strategic Analysis
Director of Financial & Strategic Analysis

Faegre Drinker • Indianapolis (IN)

On-site
USD 189,000 - 293,000
Flexible working environment
Volunteer programs
Wellness programs
+3
Director of Financial & Strategic Analysis
Director of Financial & Strategic Analysis

Faegre Drinker • Chicago (IL)

Hybrid
USD 189,000 - 293,000
Flexible working environment
Volunteer events
Wellness programming
+4
Data Engineer III - Security Engineer (Hybrid)
Data Engineer III - Security Engineer (Hybrid)

CrowdStrike Holdings, Inc. • New York (NY)

On-site
USD 120,000 - 180,000
Great Place to Work Certified
Professional development opportunities
Competitive vacation and holidays
+1
Senior SIEM & Detection Engineer - Flexible Hybrid Role
Senior SIEM & Detection Engineer - Flexible Hybrid Role

esswd • Philadelphia

Hybrid
USD 160,000 - 183,000
Flexible working environment for work–
Volunteer events
Wellness programming
+4