Senior SIEM Architect & Threat Detection Lead (Hybrid/Remote)

Ally Bank

New York (NY)

Hybrid

USD 110,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Time off & holidays
401K with match
Healthcare benefits

Job summary

Ally Financial is seeking a Principal Cyber Security Engineer to own end-to-end SIEM capability, from architecture to content engineering and automation. You will collaborate with SOC analysts, incident responders, threat hunters, and IT teams to ensure high-fidelity detections and compliant log management.

The role involves design of data ingestion pipelines, log onboard from diverse sources, and ongoing optimization for performance, availability, and cost.

Qualifications

  • 5+ years in SIEM engineering or related security engineering roles.
  • Bachelor’s degree in Computer Science, Information Security, or related field; or equivalent experience.
  • Proven expertise with at least one enterprise SIEM platform end-to-end (e.g., Splunk).
  • Strong proficiency in data parsing/normalization (regex, grok, KQL, SPL).
  • Experience with security operations, incident response workflows, and threat detection frameworks.

Responsibilities

  • Design and maintain the SIEM architecture including ingestion pipelines and retention strategies.
  • Onboard logs from diverse sources (EDR, firewalls, cloud services, SaaS, containers).
  • Implement data quality monitoring and SLA-driven dashboards for ingestion health and latency.
  • Optimize SIEM performance, storage tiers, and cost control.
  • Ensure RBAC, multitenancy, data governance, and disaster recovery plans.

Skills

SIEM engineering
Security engineering
Incident response
Threat detection
Cloud security
Scripting
Automation

Education

Bachelor's degree in Computer Science or Information Security

Tools

Splunk
Cribl
Microsoft Sentinel
QRadar
Elastic Security
Snowflake

Job description

Ally Financial is seeking a Principal Cyber Security Engineer to own end-to-end SIEM capability, from architecture to content engineering and automation. You will collaborate with SOC analysts, incident responders, threat hunters, and IT teams to ensure high-fidelity detections and compliant log management.

The role involves design of data ingestion pipelines, log onboard from diverse sources, and ongoing optimization for performance, availability, and cost.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SIEM Architect - Hybrid/Remote
Senior SIEM Architect - Hybrid/Remote

Ally-Financial • Detroit (MI)

Hybrid
USD 110,000 - 180,000
Time off and holidays
401K matching and financial wellness
Health insurance
+1
Senior SIEM Architect & Threat Detection Leader
Senior SIEM Architect & Threat Detection Leader

Ally Bank • Detroit (MI)

Hybrid
USD 110,000 - 180,000
Total Rewards program
Time Away: 20 PTO days plus holidays
Relocation assistance
+1
Principal SIEM Architect & Threat Detection Lead
Principal SIEM Architect & Threat Detection Lead

Cybersecurity Jobs • Detroit (MI)

On-site
USD 110,000 - 180,000
20 paid time off days
11 paid holidays
401(k) retirement plan
+2
Principal SIEM Architect: Scale, Automation & Detection
Principal SIEM Architect: Scale, Automation & Detection

Ally • Detroit (MI)

Hybrid
USD 140,000 - 190,000
Principal Cyber Security Engineer
Principal Cyber Security Engineer

Ally • Detroit (MI)

Hybrid
USD 140,000 - 190,000
Remote SIEM Engineer: Detection & Analytics Lead
Remote SIEM Engineer: Detection & Analytics Lead

PowerToFly • Washington

On-site
USD 89,000 - 163,000
Principal SIEM Engineer — Lead AI-Driven Security (Remote)
Principal SIEM Engineer — Lead AI-Driven Security (Remote)

Huntress • United States

Remote
CAD 298,000 - 333,000
Remote-first culture
Generous paid time off (vacation, sick
Paid holidays
+8
Senior Purple Team Operator - Cyber Defense & Red Team Lead
Senior Purple Team Operator - Cyber Defense & Red Team Lead

1611 Ally Bank • North Carolina

Hybrid
USD 110,000 - 180,000
Paid time off
Holidays
401K retirement
+4
Senior Threat Detection Engineer - SIEM & Hunting (Remote)
Senior Threat Detection Engineer - SIEM & Hunting (Remote)

Beacon Hill Staffing Group, LLC • Richmond (VA)

Remote
USD 130,000 - 170,000
Senior SIEM & Threat Detection Analyst (Remote)
Senior SIEM & Threat Detection Analyst (Remote)

Trigyn Technologies Limited • United States

Remote
USD 90,000 - 130,000