Senior SIEM Architect & Incident-Response Leader

Jobtailor

Washington (District of Columbia)

On-site

USD 170,000 - 250,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Jobtailor in Washington, DC seeks a senior security engineer to own SIEM architecture, data ingestion, and cost management in partnership with CrowdStrike as the MSSP. You will design and tune detections aligned to MITRE ATT&CK and lead incident response.

You’ll onboard log sources across Defender, Entra ID, M365, Purview, Azure, and ServiceNow, shaping IR playbooks and automation workflows while advising leadership on risk and remediation.

Qualifications

  • Bachelor’s degree or equivalent years of experience in cybersecurity or related field.
  • Eight years or more of information security experience including security operations and incident response in an enterprise environment.
  • Hands-on experience engineering a SIEM platform including log source onboarding, forwarding, parsing, and normalization.
  • Experience tuning detections with knowledge of MITRE ATT&CK and KQL or similar query languages.
  • Experience owning enterprise EDR configuration including policy management, tuning, integrations, and containment; CrowdStrike Falcon preferred.
  • Demonstrated incident response leadership including IR plans/playbooks and tabletop exercises.
  • Experience managing MDR/MSSP relationships as primary technical counterpart.
  • Working knowledge of Microsoft security tooling and network/email security controls.

Responsibilities

  • Own architecture, configuration, health, and performance of the firm’s SIEM platform with CrowdStrike as MSSP.
  • Onboard and maintain log sources across Defender, Entra ID, M365, Purview, Azure, CrowdStrike, network and firewall infrastructure, and key apps.
  • Design, build, test, and tune detections mapped to MITRE ATT&CK.
  • Serve as senior technical lead for the Security Incident Response Team and guide investigations from analysis to reporting.
  • Advise leadership on incident decisions and risk.
  • Own IR Plan and playbooks as environment evolves.
  • Own CrowdStrike Falcon configuration across endpoints/identities, including policy management and integrations.
  • Manage adjacent security technologies and feed Falcon data.
  • Build security automation/workflows for response actions and case management.
  • Complete special projects and communicate issues and risks to peers and management.

Skills

SIEM Platform Engineering
CrowdStrike Falcon Configuration
Incident Response Leadership
MITRE ATT&CK Knowledge
Microsoft Security Tooling

Education

Bachelor’s degree in cybersecurity, information systems, or a related field

Tools

CrowdStrike Falcon
Microsoft Defender
Entra ID
Microsoft 365
Microsoft Purview
Event Hub
Graph API
ServiceNow
EDR Platform
Firewall Infrastructure

Job description

Jobtailor in Washington, DC seeks a senior security engineer to own SIEM architecture, data ingestion, and cost management in partnership with CrowdStrike as the MSSP. You will design and tune detections aligned to MITRE ATT&CK and lead incident response.

You’ll onboard log sources across Defender, Entra ID, M365, Purview, Azure, and ServiceNow, shaping IR playbooks and automation workflows while advising leadership on risk and remediation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SIEM & Detection Engineer – Incident Response Lead
Senior SIEM & Detection Engineer – Incident Response Lead

Faegre-Drinker-Biddle- • Philadelphia

Hybrid
USD 160,000 - 183,000
Hybrid work environment
Wellness programming
Health plan options
+3
Senior Threat Intelligence & Detection Architect
Senior Threat Intelligence & Detection Architect

Jobtailor • Seattle (WA)

On-site
USD 110,000 - 160,000
Security Operations Analyst - SIEM & Incident Response
Security Operations Analyst - SIEM & Incident Response

Jobtailor • Arlington (MA)

On-site
USD 95,000 - 125,000
Senior SOC Engineer - Lead Threat Detection & IR (On-Site)
Senior SOC Engineer - Lead Threat Detection & IR (On-Site)

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Senior Cybersecurity Incident Response Lead
Senior Cybersecurity Incident Response Lead

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Senior Incident Response Lead: Threat Hunting & Automation
Senior Incident Response Lead: Threat Hunting & Automation

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Senior Incident Response Lead — Automation & SOAR
Senior Incident Response Lead — Automation & SOAR

Jobtailor • United States

On-site
USD 150,000 - 190,000
Health insurance
Detection Engineer: SIEM/XDR & Cloud Security
Detection Engineer: SIEM/XDR & Cloud Security

Jobtailor • Arizona

On-site
USD 85,000 - 130,000
AI-Driven Threat Detection & Incident Response Engineer
AI-Driven Threat Detection & Incident Response Engineer

Jobtailor • California (MO)

On-site
USD 125,000 - 180,000
Senior SIEM & Detection Engineering Lead
Senior SIEM & Detection Engineering Lead

K2United, LLC. • Washington

On-site
USD 150,000 - 190,000