Senior SIEM/EDR Engineer – Managed Services

Critical-Start-

Washington (District of Columbia)

On-site

USD 120,000 - 140,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Competitive salary with bonuspotential
Comprehensive health benefits
Unlimited PTO
401(k) with matching
Life Insurance & Disability
Parental & Military Leave

Job summary

Critical Start seeks a Sr. Cybersecurity Engineer to join our Managed Security Services team. You will design, implement, and improve deliverables for our MSS program, onboarding and supporting security technologies such as Microsoft Sentinel, Sumo Logic, and Splunk, while maintaining multiple SIEM environments.

The role requires 5+ years in cybersecurity engineering, 3+ years with SIEM, and 2+ years with EDR;Plano, TX-based office with strong collaboration and growth opportunities is offered.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent experience and industry certifications.
  • 5+ years of experience in a cybersecurity engineering role
  • 3+ years of experience with SIEM tools like Splunk or Microsoft Sentinel.
  • Proficiency in handling security data sources, log formats, and data ingestion methods.
  • Experience creating SIEM content such as alerts, reports, and dashboards.
  • Strong communication and customer service skills.
  • 2+ years of experience with next-gen antivirus (AV) or endpoint detection and response (EDR) solutions.
  • Scripting capabilities in Bash, PowerShell, Python, or others.
  • Ability to establish trust and rapport with customers, even when dealing with complex technical issues.

Responsibilities

  • Maintain Expertise: Stay at the forefront of the industry by continuously updating your knowledge in SIEM tools and EDR/XDR integrations.
  • Client Engagement: Deliver our managed services to clients through project-based workflows related to SIEM and EDR/XDR technologies.
  • Technical Guidance: Provide technical leadership, expertise, and configuration assistance to both colleagues and clients, helping them maintain robust and effective SIEM and Endpoint security programs.
  • Technical Development: Collaborate on developing technical pathways to foster growth within the organization and lead cross-functional training sessions.
  • Best Practices: Create and maintain best practices and assist clients in deploying and configuring endpoint agents, security policies, log forwarders, data sources, content, and alerts.
  • Security Maturation: Assist clients in maturing their SIEM and Endpoint security products in alignment with industry standards and our program offerings.
  • Problem Resolution: Act as a senior technical escalation resource on the team. Troubleshoot interactions between data sources and SIEM technologies, as well as API interactions between supported security integrations and our platform (CORR).
  • Automation: Identify opportunities to automate aspects of SIEM and Endpoint engineering workload, enhancing efficiency and accuracy.
  • Client Collaboration: Work closely with clients to address technical concerns, provide value reporting, and configure their environments effectively.
  • Documentation: Develop and maintain comprehensive security documentation, including playbooks, standard operating procedures, and training materials as needed.
  • Continuous Learning: Stay up-to-date with the latest security threats and trends, incorporating this knowledge into our security solutions. Obtain and maintain relevant security certifications.
  • Team Collaboration: Collaborate with fellow cybersecurity engineers, product managers, and architects to design and implement innovative security solutions, ensuring the highest level of protection for our clients.

Skills

SIEM expertise
EDR/XDR knowledge
Scripting Bash/PowerShell/Python
Communication skills
Customer service
Security engineering

Education

Bachelor's degree in CS/Cybersecurity/IT
Industry certifications

Tools

Splunk
Microsoft Sentinel
Sumo Logic
Palo Alto Cortex XDR
Defender for Endpoint/Server
SentinelOne

Job description

Critical Start seeks a Sr. Cybersecurity Engineer to join our Managed Security Services team. You will design, implement, and improve deliverables for our MSS program, onboarding and supporting security technologies such as Microsoft Sentinel, Sumo Logic, and Splunk, while maintaining multiple SIEM environments.

The role requires 5+ years in cybersecurity engineering, 3+ years with SIEM, and 2+ years with EDR;Plano, TX-based office with strong collaboration and growth opportunities is offered.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SIEM Engineer, Managed Security Services
Senior SIEM Engineer, Managed Security Services

Critical Start • Dallas (TX)

On-site
USD 120,000 - 140,000
Competitive salary with bonus潜
Health benefits
Unlimited PTO
+3
Senior Cybersecurity Engineer, Managed Services (Remote)
Senior Cybersecurity Engineer, Managed Services (Remote)

Critical Start • Washington

On-site
USD 120,000 - 140,000
Comprehensive health benefits
Unlimited PTO
401(k) Matching
Senior Cybersecurity Engineer, Managed Services
Senior Cybersecurity Engineer, Managed Services

Critical Start • Dallas (TX)

On-site
USD 120,000 - 140,000
Competitive salary with bonus潜
Health benefits
Unlimited PTO
+3
Cybersecurity Projects Lead - SIEM & SentinelOne Delivery
Cybersecurity Projects Lead - SIEM & SentinelOne Delivery

SentinelOne • United States

On-site
USD 120,000 - 160,000
Medical coverage
Dental coverage
Vision coverage
+3
Microsoft Sentinel SIEM Engineer
Microsoft Sentinel SIEM Engineer

InnoCore Solutions, Inc. • Dallas (TX)

On-site
USD 120,000 - 180,000
Remote SIEM Engineer: Detection & Analytics Lead
Remote SIEM Engineer: Detection & Analytics Lead

PowerToFly • Washington

On-site
USD 89,000 - 163,000
Remote SIEM Engineer: Detection & Content Architect
Remote SIEM Engineer: Detection & Content Architect

Relha LLC • Washington, Northern (KY)

Hybrid
USD 89,000 - 163,000
Senior Splunk SIEM Engineer — Threat Detection & Response
Senior Splunk SIEM Engineer — Threat Detection & Response

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Mid Cybersecurity Engineer — SIEM/EDR & Cloud Security
Mid Cybersecurity Engineer — SIEM/EDR & Cloud Security

Interclypse, Inc. • Maryland

On-site
USD 95,000 - 140,000
Health Insurance
401K with match up to 8%
Parental Leave
+1
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Delan Associates Inc. • Richmond (VA)

On-site
USD 110,000 - 160,000