Senior Information Security Engineer - SIEM and Detection

esswd

Philadelphia (Philadelphia County)

Hybrid

USD 160,000 - 183,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Flexible working environment for work–
Volunteer events
Wellness programming
Work with security experts
Health plan options
Dental, vision and 401(k)
Generous paid time off

Job summary

Faegre Drinker invites applications for a Senior Information Security Engineer - SIEM and Detection to join our Technology & Innovation team in Philadelphia, NYC, or Washington, D.C. You will own the firm’s SIEM platform, guide detection development, and lead incident response initiatives across major platforms.

You will oversee log onboarding from Defender suites and CrowdStrike, shape rules per MITRE ATT&CK, and drive automation across SIEM, CrowdStrike, and ServiceNow.

Qualifications

  • Owns architecture, configuration, health, and performance of the firm's SIEM platform.
  • Onboards and maintains log sources across Defender, Entra ID, Microsoft 365, Purview, Azure, CrowdStrike and key business apps.
  • Designs, builds, tests, and tunes detection rules mapped to the MITRE ATT&CK framework.
  • Leads the Security Incident Response Team through investigations and containment.
  • Owns Incident Response Plan and playbooks.
  • Manages CrowdStrike Falcon configurations across endpoints.
  • Builds security automation and orchestration workflows integrating SIEM, CrowdStrike, and ServiceNow.

Responsibilities

  • Owns the architecture, configuration, health, and performance of the firm's SIEM platform.
  • Onboards and maintains log sources across Defender, Entra ID, Microsoft 365, Purview, Azure, CrowdStrike, and critical apps.
  • Designs, tests, and tunes detection rules aligned to MITRE ATT&CK.
  • Provides senior technical leadership for the Security Incident Response Team.
  • Oversees Incident Response Plan and playbooks.
  • Configures CrowdStrike Falcon across endpoints and identities.
  • Builds automation workflows for response actions and case management.

Skills

SIEM platform ownership
Incident Response Leadership
Threat detection
Communication skills
Problem-solving

Tools

CrowdStrike Falcon
Microsoft Defender
Microsoft Entra ID
Microsoft 365
Azure

Job description

Faegre Drinker is a firm designed for clients and designed for you. We understand that our people are critical to our success and we are committed to investing in our paraprofessional, administrative and operations professionals. We are always looking for talented, service-focused individuals to join our flexible and high-performing culture. With technology tools and resources that support our hybrid work environment, our colleagues enjoy a culture of learning, support for work and personal goals, opportunities to give back to our communities, and competitive benefits and rewards programs. At Faegre Drinker, you will have the opportunity to share your expertise within and across teams and contribute to our success.

Job Description Summary:

Faegre Drinker has an opportunity for a Senior Information Security Engineer - SIEM and Detection to work with our Technology & Innovation team in our Philadelphia, New York City, or Washington, D.C. offices. You will be part of a dynamic team responsible for owning the firm's security monitoring platform and the detection capability built on it. This position will work with other talented individuals who share a passion for doing great work in the best interest of our clients.

What you would do:
  • Owns the architecture, configuration, health, and performance of the firm's SIEM platform, including data ingestion, parsing, normalization, retention, and cost management, in partnership with CrowdStrike as the managed security service provider
  • Onboards and maintains log sources across Microsoft Defender, Microsoft Entra ID, Microsoft 365, Microsoft Purview, Azure, CrowdStrike, network and firewall infrastructure, and key business applications, using Event Hub, Graph API, and native connectors as appropriate
  • Designs, builds, tests, and tunes detection rules and analytics mapped to the MITRE ATT&CK framework, prioritizing coverage based on the firm's threat profile and risk
  • Serves as senior technical lead for the Security Incident Response Team, guiding investigations from analysis and containment through recovery and reporting, and advising the Director and leadership on response decisions
  • Owns the firm's Incident Response Plan and playbooks, maintaining them as the firm's environment, threats, and regulatory obligations evolve
  • Owns the configuration of the CrowdStrike Falcon platform and its related modules across all firm endpoints and identities, including EDR, Identity Protection, Data Protection, prevention and update policies, integrations, and day-to-day tuning, along with adjacent security technologies that feed or act on Falcon data
  • Builds security automation and orchestration workflows for common response actions, enrichment, and case management, integrating the SIEM, CrowdStrike, and ServiceNow
  • Special projects and other duties as assigned
What is expected:
  • Ability to problem-solve
  • Excellent interpersonal, verbal and written communication skills, including the ability to communicate effectively in a virtual environment (e.g., via phone, web/videoconference)
  • Ability to concentrate on tasks, make decisions and work calmly and effectively in a high-pressure, deadline-orientated environment
  • Demonstrated ability to use good judgment in taking initiative while asking for direction or clarification and consulting others, as appropriate
  • Willingness to be flexible with time and adjust to a changing work environment
  • Ability to build and maintain positive relationships, both internally and externally, while maintaining a client service orientation
  • Ability to use sound judgment and discretion in dealing with highly confidential information
  • Ability to take direction and accept supervision
  • Demonstrated ability to work independently, organize and accurately prioritize work, be detail-oriented, understand when urgency is required and use good judgment in varied situations
  • Ability to work effectively with co-workers in a team oriented collaborative environment
What we offer:
  • Flexible working environment for work-life success
  • Opportunity to participate in firm-sponsored volunteer events
  • Wellness programming with personalized content and activities
  • Professional environment and the opportunity to work with experts at the top of their fields
  • Variety of health plan options, as well as dental, vision and 401(k) plans
  • Generous paid time off

The anticipated initial salary for someone who is hired into this position is $160,200 - $183,100.

Actual initial salary may be above or below the above-identified range and will be based on the relevant skills, training, experience, and other job-related factors, including the location where the position is filled, in all cases consistent with applicable law. This is an exempt role and the initial salary range listed above is just one component of Faegre Drinker's total compensation and benefits package for professional staff, which includes, but is not limited to, a discretionary bonus; life, health, accident, and disability insura

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Engineer – SIEM and Detection
Senior Information Security Engineer – SIEM and Detection

Faegre-Drinker-Biddle- • Philadelphia

Hybrid
USD 160,000 - 183,000
Hybrid work environment
Wellness programming
Health plan options
+3
Information Security Engineer - Threat and Vulnerability Management
Information Security Engineer - Threat and Vulnerability Management

esswd • Philadelphia

Hybrid
USD 122,000 - 138,000
Flexible working environment
Volunteer events
Wellness programs
+3
Senior SIEM & Detection Engineer – Incident Response Lead
Senior SIEM & Detection Engineer – Incident Response Lead

Faegre-Drinker-Biddle- • Philadelphia

Hybrid
USD 160,000 - 183,000
Hybrid work environment
Wellness programming
Health plan options
+3
Security Engineer
Security Engineer

Manatt, Phelps & Phillips, LLP • New York (NY)

Hybrid
USD 80,000 - 100,000
Senior Manager, SIEM/ SOAR Engineer (CrowdStrike)
Senior Manager, SIEM/ SOAR Engineer (CrowdStrike)

Kroll • United States

On-site
USD 150,000 - 200,000
Healthcare Coverage
Time Off and Leave Policies
Protective Insurances
+2
Senior Security Engineer - Crowdstrike
Senior Security Engineer - Crowdstrike

UltraViolet Cyber • Washington

Hybrid
USD 135,000 - 150,000
401(k) match
Medical/Dental/Vision insurance
Short-Term Disability
+3
Senior Security Engineer - Crowdstrike
Senior Security Engineer - Crowdstrike

UltraViolet Cyber • National Harbor (MD)

On-site
USD 135,000 - 150,000
401(k) match
Medical, Dental, and Vision Insurance
Group Life Insurance
+2
Sr. Director, Engineering - Next-Gen SIEM (Hybrid)
Sr. Director, Engineering - Next-Gen SIEM (Hybrid)

CrowdStrike • Redmond (WA)

Hybrid
USD 235,000 - 350,000
Market-leading compensation
Equity awards
Wellness programs
+5
Senior Information Security Engineer – SIEM, Detection
Senior Information Security Engineer – SIEM, Detection

Jobtailor • Washington

On-site
USD 170,000 - 250,000
Head of Engineering, AI-Driven NG-SIEM
Head of Engineering, AI-Driven NG-SIEM

CrowdStrike, Inc. • Sunnyvale (CA)

Hybrid
USD 235,000 - 350,000
Market-leading compensation
Wellness programs
Vacation and holidays
+5