Senior SIEM & Detection Engineer (Hybrid)

Corebridge Financial

Houston (TX)

Hybrid

USD 168,000 - 195,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401(k) with company match
Paid time off
Volunteer time off

Job summary

Corebridge Financial seeks a highly skilled Senior Cyber Security Engineer - SIEM and Automation to lead detection engineering, optimize logging, and integrate security tools. You will work with Security Operations, Threat Intelligence, and Engineering to deliver actionable SIEM insights and rapid incident detection across cloud, on‑prem, and hybrid environments.

The role focuses on developing high‑fidelity use cases, reducing false positives, and tuning alerts to balance detection fidelity with

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent experience).
  • 3–7+ years of experience in SIEM engineering, detection engineering, or security operations.
  • Hands‑on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar, Elastic).
  • Strong understanding of log sources (Windows, Linux, cloud platforms, network devices).
  • Experience with query languages (e.g., SPL, KQL, Lucene, SQL).
  • Knowledge of MITRE ATT&CK framework and adversary tactics/techniques.
  • Experience onboarding and parsing diverse data sources.

Responsibilities

  • Design, develop, and maintain SIEM detection use cases aligned with MITRE ATT&CK and threat intelligence.
  • Translate threat scenarios into actionable detection logic and correlation rules.
  • Continuously improve detection coverage through gap analysis and adversary simulation insights.
  • Define and implement logging requirements across cloud, endpoint, network, and application layers.
  • Analyze log sources to ensure data quality, normalization, and completeness.
  • Identify gaps in telemetry and recommend improvements to enhance visibility.
  • Integrate new data sources into the SIEM (e.g., EDR, IAM, firewall, SaaS platforms).
  • Work with engineering teams to onboard logs using APIs, agents, and log pipelines.
  • Ensure proper parsing, enrichment, and normalization of ingested data.
  • Reduce false positives through continuous alert tuning and threshold optimization.
  • Implement risk-based alerting and prioritization strategies.
  • Collaborate with SOC analysts to refine detection logic based on incident feedback.
  • Maintain and optimize SIEM performance, scalability, and cost efficiency.
  • Develop dashboards, reports, and visualizations for operational and leadership insights.
  • Support automation and orchestration efforts with SOAR integrations where applicable.
  • Partner with Threat Intelligence to operationalize indicators and emerging threats.
  • Support incident response investigations with log analysis and detection enhancements.
  • Stay current with evolving attack techniques and detection methodologies.

Skills

SIEM engineering
Detection engineering
Security operations
Splunk
Microsoft Sentinel
QRadar
Elastic
Windows logs
Linux logs
Cloud logs
SPL
KQL
Lucene
SQL
MITRE ATT&CK
Data onboarding

Education

Bachelor's degree in Cybersecurity/CS/related field

Tools

Splunk
Microsoft Sentinel
QRadar
Elastic

Job description

Corebridge Financial seeks a highly skilled Senior Cyber Security Engineer - SIEM and Automation to lead detection engineering, optimize logging, and integrate security tools. You will work with Security Operations, Threat Intelligence, and Engineering to deliver actionable SIEM insights and rapid incident detection across cloud, on‑prem, and hybrid environments.

The role focuses on developing high‑fidelity use cases, reducing false positives, and tuning alerts to balance detection fidelity with

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SIEM & Detection Engineer – Automation
Senior SIEM & Detection Engineer – Automation

corebridgefinancial • Jersey City (NJ)

On-site
USD 168,000 - 195,000
Senior SIEM & Automation Engineer - Hybrid
Senior SIEM & Automation Engineer - Hybrid

Corebridge Financial, Inc. • Jersey City (NJ)

Hybrid
USD 168,000 - 195,000
Senior SIEM & Automation Security Engineer
Senior SIEM & Automation Security Engineer

Corebridge Financial • Jersey City (NJ)

Hybrid
USD 168,000 - 195,000
Discretionary bonus
Hybrid work policy
Professional development
Senior Cyber Security Engineer - SIEM and Automation
Senior Cyber Security Engineer - SIEM and Automation

corebridgefinancial • Jersey City (NJ)

On-site
USD 168,000 - 195,000
Hybrid SIEM Engineer — Detection & Automation
Hybrid SIEM Engineer — Detection & Automation

IDBNY • New York (NY)

Hybrid
USD 140,000 - 160,000
Annual bonus
Medical, dental, and vision plans
Life and disability insurance
+5
Hybrid SIEM Engineer: Detection & Incident Response
Hybrid SIEM Engineer: Detection & Incident Response

IDBNY • New York

Hybrid
USD 140,000 - 160,000
SIEM Engineer — Detection, Automation & Hybrid Cloud
SIEM Engineer — Detection, Automation & Hybrid Cloud

IDB Bank • New York (NY)

Hybrid
USD 120,000 - 180,000
Cyber Detection Engineer: SIEM, Threat Hunting & Cloud
Cyber Detection Engineer: SIEM, Threat Hunting & Cloud

Prudential Financial • Newark (NJ)

On-site
USD 96,000 - 159,000
Market competitive base salaries
Medical, dental, vision
401(k) plan with company match
+4
Staff Detection Engineer: SIEM, Cloud & Threat Hunting
Staff Detection Engineer: SIEM, Cloud & Threat Hunting

LinkedIn • Mountain View (CA)

Hybrid
USD 156,000 - 255,000
Health and wellness programs
Annual performance bonus
Stock options
+1
Cyber Security Engineer – Threat Detection (1401)
Cyber Security Engineer – Threat Detection (1401)

Sharp Decisions • Charlotte (NC)

Hybrid
USD 105,000 - 145,000