Senior Information Security Engineer – SIEM, Detection

Jobtailor

Washington (District of Columbia)

On-site

USD 170,000 - 250,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Jobtailor in Washington, DC seeks a senior security engineer to own SIEM architecture, data ingestion, and cost management in partnership with CrowdStrike as the MSSP. You will design and tune detections aligned to MITRE ATT&CK and lead incident response.

You’ll onboard log sources across Defender, Entra ID, M365, Purview, Azure, and ServiceNow, shaping IR playbooks and automation workflows while advising leadership on risk and remediation.

Qualifications

  • Bachelor’s degree or equivalent years of experience in cybersecurity or related field.
  • Eight years or more of information security experience including security operations and incident response in an enterprise environment.
  • Hands-on experience engineering a SIEM platform including log source onboarding, forwarding, parsing, and normalization.
  • Experience tuning detections with knowledge of MITRE ATT&CK and KQL or similar query languages.
  • Experience owning enterprise EDR configuration including policy management, tuning, integrations, and containment; CrowdStrike Falcon preferred.
  • Demonstrated incident response leadership including IR plans/playbooks and tabletop exercises.
  • Experience managing MDR/MSSP relationships as primary technical counterpart.
  • Working knowledge of Microsoft security tooling and network/email security controls.

Responsibilities

  • Own architecture, configuration, health, and performance of the firm’s SIEM platform with CrowdStrike as MSSP.
  • Onboard and maintain log sources across Defender, Entra ID, M365, Purview, Azure, CrowdStrike, network and firewall infrastructure, and key apps.
  • Design, build, test, and tune detections mapped to MITRE ATT&CK.
  • Serve as senior technical lead for the Security Incident Response Team and guide investigations from analysis to reporting.
  • Advise leadership on incident decisions and risk.
  • Own IR Plan and playbooks as environment evolves.
  • Own CrowdStrike Falcon configuration across endpoints/identities, including policy management and integrations.
  • Manage adjacent security technologies and feed Falcon data.
  • Build security automation/workflows for response actions and case management.
  • Complete special projects and communicate issues and risks to peers and management.

Skills

SIEM Platform Engineering
CrowdStrike Falcon Configuration
Incident Response Leadership
MITRE ATT&CK Knowledge
Microsoft Security Tooling

Education

Bachelor’s degree in cybersecurity, information systems, or a related field

Tools

CrowdStrike Falcon
Microsoft Defender
Entra ID
Microsoft 365
Microsoft Purview
Event Hub
Graph API
ServiceNow
EDR Platform
Firewall Infrastructure

Job description

  • Own the architecture, configuration, health, and performance of the firm’s SIEM platform, including data ingestion, parsing, normalization, retention, and cost management, in partnership with CrowdStrike as the managed security service provider
  • Onboard and maintain log sources across Microsoft Defender, Microsoft Entra ID, Microsoft 365, Microsoft Purview, Azure, CrowdStrike, network and firewall infrastructure, and key business applications using Event Hub, Graph API, and native connectors
  • Design, build, test, and tune detection rules and analytics mapped to the MITRE ATT&CK framework
  • Serve as senior technical lead for the Security Incident Response Team, guiding investigations from analysis and containment through recovery and reporting
  • Advise the Director and leadership on incident response decisions
  • Own and maintain the firm’s Incident Response Plan and playbooks as the environment, threats, and regulatory obligations evolve
  • Own configuration of the CrowdStrike Falcon platform and related modules across firm endpoints and identities, including EDR, Identity Protection, Data Protection, prevention and update policies, integrations, and day‑to‑day tuning
  • Manage adjacent security technologies that feed or act on Falcon data
  • Build security automation and orchestration workflows for response actions, enrichment, and case management, integrating the SIEM, CrowdStrike, and ServiceNow
  • Complete special projects and other duties as assigned
  • Communicate information security issues, risks, and recommendations to technical and non-technical peers and management
Requirements
  • Bachelor’s degree in cybersecurity, information systems, or a related field, or equivalent years of experience
  • Eight years or more of relevant information security experience, including security operations and incident response in an enterprise environment
  • Hands‑on experience engineering a SIEM platform, including log source onboarding, forwarding infrastructure, parsing and normalization, and at least one major deployment or migration
  • Experience developing and tuning detections, with working knowledge of the MITRE ATT&CK framework and query languages such as KQL or equivalent
  • Experience owning the configuration of an enterprise EDR platform, including policy management, tuning, integrations, and containment actions; CrowdStrike Falcon experience strongly preferred
  • Demonstrated experience leading incident response, including building or maintaining incident response plans and playbooks and running tabletop exercises
  • Experience managing a managed detection and response or managed security service provider relationship as the primary technical counterpart, including tuning, escalation, and service reviews
  • Working knowledge of Microsoft security tooling, including Microsoft Defender, Microsoft Entra ID, Microsoft 365, and Microsoft Purview
  • Working knowledge of network security, firewalls, and email security controls
  • Thorough understanding of current security principles, techniques, and protocols
  • Ability to effectively communicate information security issues, risks, and recommendations to both technical and non-technical peers and management, including through well‑written reports
  • Ability to problem‑solve
  • Excellent interpersonal, verbal and written communication skills, including the ability to communicate effectively in a virtual environment
  • Ability to concentrate on tasks, make decisions, and work calmly and effectively in a high‑pressure, deadline‑oriented environment
  • Demonstrated ability to use good judgment and take initiative while asking for direction or clarification and consulting others as appropriate
  • Willingness to be flexible with time and adjust to a changing work environment
  • Ability to build and maintain positive internal and external relationships while maintaining a client service orientation
  • Ability to use sound judgment and discretion with highly confidential information
  • Ability to take direction and accept supervision
  • Demonstrated ability to work independently, organize and accurately prioritize work, be detail‑oriented, understand when urgency is required, and use good judgment in varied situations
  • Ability to work effectively with co‑workers in a team‑oriented collaborative environment
Core Competencies

Demonstrates expertise in managing and configuring SIEM platforms, particularly CrowdStrike Falcon, while leading incident response efforts and developing security automation workflows. Proficient in onboarding log sources and applying the MITRE ATT&CK framework to enhance security operations.

Highest‑signal resume keywords
  • SIEM Platform Engineering
  • CrowdStrike Falcon Configuration
  • Incident Response Leadership
  • MITRE ATT&CK Framework Knowledge
  • Microsoft Security Tooling Experience
ATS Optimization Keywords
Hard Skills
  • SIEM Platform Management
  • Log Source Onboarding
  • Detection Rule Development
  • Policy Management
  • Data Parsing and Normalization
  • Security Automation Workflows
  • Incident Response Planning
  • KQL Query Language
  • Network Security
  • Email Security Controls
Soft Skills
  • Effective Communication
  • Problem‑Solving
  • Interpersonal Skills
  • Decision‑Making
  • Team Collaboration
Industry Keywords
  • Information Security
  • Incident Response
  • Managed Security Service Provider
  • Security Operations
  • Cybersecurity
Tools & Technologies
  • CrowdStrike
  • Microsoft Defender
  • Microsoft Entra ID
  • Microsoft 365
  • Microsoft Purview
  • Event Hub
  • Graph API
  • ServiceNow
  • EDR Platforms
  • Firewall Infrastructure
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer – Threat Intelligence, Detection
Senior Security Engineer – Threat Intelligence, Detection

Jobtailor • Seattle (WA)

On-site
USD 110,000 - 160,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Detection Engineer – Manager
Detection Engineer – Manager

Jobtailor • New York (NY)

On-site
USD 120,000 - 180,000
Security Operations & Engineering Lead
Security Operations & Engineering Lead

Jobtailor • Brea (CA)

On-site
USD 170,000 - 250,000
Senior SOC Engineer
Senior SOC Engineer

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Senior Manager, Cybersecurity – TVM, SIEM/SOAR
Senior Manager, Cybersecurity – TVM, SIEM/SOAR

Jobtailor • Chicago (IL)

On-site
USD 120,000 - 160,000
Security Engineer
Security Engineer

Jobtailor • Arizona

On-site
USD 85,000 - 130,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Jobtailor • United States

On-site
USD 120,000 - 180,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Network Security Engineering
Network Security Engineering

Jobtailor • Town of Florida (NY)

Hybrid
USD 120,000 - 160,000