SIEM and Detection Engineer
Minerva Cyber Technologies is seeking a SIEM and Detection Engineer to improve the quality and usefulness of security monitoring. You will onboard log sources and telemetry, develop threat detections, and help SOC analysts investigate meaningful signals with enough context to act.
What You Will Do
- Assess log coverage, collection health, parsing, normalization, and retention requirements.
- Build and test detection rules using endpoint, identity, network, application, and cloud data.
- Tune rules to reduce false positives and avoidable noise while measuring detection coverage and limitations.
- Create investigation guidance, dashboards, and escalation workflows with security operations teams.
- Version detection content (detection as code), document tests, and maintain change and deployment records.
Required Qualifications
- Hands-on experience administering a SIEM or developing production detection content.
- Ability to query security data and explain the behavior and limitations behind a detection.
- Understanding of common attack techniques, such as those in the MITRE ATT&CK framework, log sources, and investigation workflows.
- Practical scripting, version control, testing, and technical documentation skills.
- Ability to travel to client sites as needed.
Preferred Qualifications
- Experience with Splunk, Elastic, Microsoft Sentinel, Sigma, SOAR workflows, or similar technologies.
- Experience supporting threat hunts, safe detection validation, or security monitoring in regulated environments.
Why Join Minerva
- Work on meaningful missions tied to critical infrastructure resilience and cybersecurity.
- Join a team with deep hands‑on cyber and national security experience.
- Help build and shape Minerva’s growing OT and critical infrastructure practice.
- Contribute to practical, outcomes‑driven work rather than checkbox consulting.