SIEM Engineer III

ECS Corporate Services

Fairfax (VA)

On-site

USD 120,000 - 170,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

ECS Corporate Services seeks a Senior SIEM Engineer to design, deploy, and optimize enterprise SIEM platforms across cloud, on-premises, and hybrid environments. You will support telemetry integrations and data pipelines, driving reliability and security operations in collaboration with SOC teams.

Ideal candidates have 5+ years in security engineering with hands-on experience across Elastic, CrowdStrike, Splunk, and Microsoft Sentinel, plus scripting skills for automation.

Qualifications

  • Bachelor's degree in computer science, information security, or a related field. Will consider experience in lieu of a degree.

Responsibilities

  • Engineer, deploy, configure, maintain, and optimize enterprise SIEM platforms across cloud, on-premises, and hybrid environments.
  • Support SIEM infrastructure components: collectors, aggregators, data nodes, forwarders, agents, connectors, APIs.
  • Design, configure, and maintain integrations for security telemetry from endpoints, network devices, cloud environments, applications, OSs.
  • Configure data collection, forwarding, parsing, normalization, enrichment, filtering, and routing for reliable telemetry.
  • Perform SIEM platform upgrades, patches, and lifecycle management with minimal disruption.
  • Monitor SIEM health, ingestion pipelines, storage, and capacity; optimize performance.
  • Lead complex troubleshooting and root-cause analysis; coordinate with vendors as needed.
  • Maintain and optimize SIEM configurations; follow change-management processes.
  • Support security operations with telemetry for monitoring, investigation, threat hunting, and incident response.
  • Collaborate with stakeholders to define requirements and coordinate engineering activities.
  • Mentor junior engineers and document procedures and runbooks.
  • Engage vendors for support and upgrade activities.
  • Identify opportunities to improve reliability, automation, and scalability.

Skills

SIEM Engineering
Cloud & Hybrid
Scripting & Automation
Incident Response

Education

Bachelor's degree in CS or InfoSec

Tools

Elastic Security
CrowdStrike Falcon
Splunk Enterprise Security
Microsoft Sentinel

Job description

Responsibilities
  • SIEM Platform Engineering: Engineer, deploy, configure, maintain, and optimize enterprise SIEM platforms such as Elastic Security, CrowdStrike Falcon Next-Gen SIEM, Splunk Enterprise Security, Microsoft Sentinel, or similar technologies across cloud, on-premises, and hybrid environments.
  • SIEM Infrastructure Management: Support the underlying infrastructure and components required for SIEM operations, including collectors, aggregators, data nodes, forwarders, agents, connectors, APIs, and other supporting services.
  • Log Source & Data Integration: Design, configure, and maintain integrations for security telemetry from endpoints, network devices, firewalls, identity platforms, cloud environments, applications, operating systems, and other enterprise technologies.
  • Data Pipeline Engineering: Configure and troubleshoot data collection, forwarding, parsing, normalization, enrichment, filtering, and routing to ensure security telemetry is reliably delivered and usable within supported SIEM platforms.
  • Platform Maintenance & Upgrades: Perform SIEM platform upgrades, patches, configuration changes, migrations, and lifecycle management activities while minimizing operational disruption and maintaining security visibility.
  • Performance & Health Monitoring: Conduct routine health checks and proactively monitor SIEM infrastructure, ingestion pipelines, storage, system performance, capacity, and availability. Identify and remediate issues before they impact security operations.
  • Complex Troubleshooting: Serve as a senior escalation point for complex SIEM infrastructure, integration, ingestion, and platform issues. Lead root-cause analysis and coordinate resolution with internal teams and technology vendors when necessary.
  • Configuration Management: Maintain and optimize SIEM configurations to support changing environments, new data sources, platform requirements, and operational needs while following established change-management processes.
  • Security Operations Support: Partner with SOC analysts and other cybersecurity teams to ensure required telemetry and SIEM capabilities are available to support monitoring, investigation, threat hunting, incident response, and other security operations.
  • Client & Stakeholder Support: Work directly with internal stakeholders and client organizations to understand technical requirements, coordinate SIEM engineering activities, communicate risks or dependencies, and support successful implementation of security monitoring capabilities.
  • Technical Leadership & Mentoring: Provide technical guidance and mentorship to junior SIEM engineers, support knowledge transfer, and assist with troubleshooting and complex engineering activities without serving as the team's formal people manager.
  • Documentation: Develop and maintain detailed technical documentation, including architecture diagrams, integration procedures, configuration standards, troubleshooting guides, operational runbooks, and standard operating procedures.
  • Vendor Management: Engage SIEM and security technology vendors to troubleshoot complex issues, evaluate platform capabilities, coordinate support cases, and assist with implementation or upgrade activities.
  • Continuous Improvement: Identify opportunities to improve SIEM reliability, scalability, automation, operational efficiency, and engineering processes across supported environments.
Education Requirements
  • Bachelor's degree in computer science, information security, or a related field. Will consider experience in lieu of a degree.

Salary Range: $120,000 - $170,000

General Description of Benefits

At least five years of relevant cybersecurity, SIEM, security engineering, or systems engineering experience, with demonstrated experience supporting enterprise security monitoring technologies. Strong knowledge of SIEM concepts and hands-on experience with one or more enterprise SIEM platforms such as Elastic Security, CrowdStrike Falcon Next-Gen SIEM, Splunk Enterprise Security, Microsoft Sentinel, or comparable technologies. Demonstrated experience deploying, configuring, maintaining, upgrading, and troubleshooting enterprise SIEM platforms and supporting infrastructure. Experience integrating enterprise data sources and security technologies into SIEM platforms, including troubleshooting ingestion, connectivity, parsing, normalization, and data quality issues. Strong understanding of Windows and Linux operating systems and the infrastructure, networking, and security concepts required to support enterprise SIEM environments. Working knowledge of cloud environments and cloud-based security telemetry, including platforms such as AWS, Microsoft Azure, and/or Google Cloud. Proficiency with scripting or automation technologies such as Python, PowerShell, Bash, REST APIs, or similar technologies. SIEM Query Languages: Proficiency with SIEM search, query, and analytics languages such as KQL, SPL, CQL, EQL, ES|QL, or similar technologies used to search, analyze, and troubleshoot security telemetry. Strong troubleshooting and problem-solving skills with the ability to independently investigate and resolve complex technical issues. Comprehensive understanding of cybersecurity concepts, security monitoring, common attack methodologies, and the role of SIEM technologies within security operations. Ability to lead complex technical efforts and provide guidance and mentorship to junior engineers. Strong verbal and written communication skills, including the ability to create technical documentation and communicate complex technical concepts to both technical and non-technical stakeholders. Ability to think strategically about SIEM technologies and identify opportunities to improve platform reliability, scalability, automation, and overall security capabilities using traditional methods and/or AI driven technologies.

Other Requirements of the position include:
  • Able and willing to obtain a US Security Clearance.
  • On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capabilities.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Engineer - SIEM, Automation & Elastic Security
Sr. Security Engineer - SIEM, Automation & Elastic Security

Red Lobster, Inc. • Orlando (FL)

On-site
USD 90,000 - 130,000
Information Security Engineer
Information Security Engineer

LanceSoft, Inc. • Melbourne (FL)

On-site
USD 90,000 - 120,000
SOC Engineer
SOC Engineer

Amentum • Columbia (MD)

On-site
USD 120,000 - 180,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Senior SIEM Engineer (Splunk)
Senior SIEM Engineer (Splunk)

Quantum Sky • Washington

On-site
USD 140,000 - 210,000
Senior SIEM Analyst
Senior SIEM Analyst

theserverlab • United States

On-site
USD 80,000 - 100,000
Medical benefits
Dental benefits
Vision benefits
+2
SIEM Engineer - 174035
SIEM Engineer - 174035

Zachary Piper Solutions • Newington (VA)

Hybrid
USD 95,000 - 135,000
Full Benefits Package
SIEM Engineer - 174035
SIEM Engineer - 174035

Piper Companies • Newington (VA)

On-site
USD 110,000 - 150,000
PTO
Paid Holidays
Medical
+5
Engineer, Security
Engineer, Security

11:11 Systems • United States

On-site
USD 120,000 - 160,000
Senior SIEM Engineer: Platform, Automation & Security Ops
Senior SIEM Engineer: Platform, Automation & Security Ops

ECS Corporate Services • Fairfax (VA)

On-site
USD 120,000 - 170,000