Responsibilities
- SIEM Platform Engineering: Engineer, deploy, configure, maintain, and optimize enterprise SIEM platforms such as Elastic Security, CrowdStrike Falcon Next-Gen SIEM, Splunk Enterprise Security, Microsoft Sentinel, or similar technologies across cloud, on-premises, and hybrid environments.
- SIEM Infrastructure Management: Support the underlying infrastructure and components required for SIEM operations, including collectors, aggregators, data nodes, forwarders, agents, connectors, APIs, and other supporting services.
- Log Source & Data Integration: Design, configure, and maintain integrations for security telemetry from endpoints, network devices, firewalls, identity platforms, cloud environments, applications, operating systems, and other enterprise technologies.
- Data Pipeline Engineering: Configure and troubleshoot data collection, forwarding, parsing, normalization, enrichment, filtering, and routing to ensure security telemetry is reliably delivered and usable within supported SIEM platforms.
- Platform Maintenance & Upgrades: Perform SIEM platform upgrades, patches, configuration changes, migrations, and lifecycle management activities while minimizing operational disruption and maintaining security visibility.
- Performance & Health Monitoring: Conduct routine health checks and proactively monitor SIEM infrastructure, ingestion pipelines, storage, system performance, capacity, and availability. Identify and remediate issues before they impact security operations.
- Complex Troubleshooting: Serve as a senior escalation point for complex SIEM infrastructure, integration, ingestion, and platform issues. Lead root-cause analysis and coordinate resolution with internal teams and technology vendors when necessary.
- Configuration Management: Maintain and optimize SIEM configurations to support changing environments, new data sources, platform requirements, and operational needs while following established change-management processes.
- Security Operations Support: Partner with SOC analysts and other cybersecurity teams to ensure required telemetry and SIEM capabilities are available to support monitoring, investigation, threat hunting, incident response, and other security operations.
- Client & Stakeholder Support: Work directly with internal stakeholders and client organizations to understand technical requirements, coordinate SIEM engineering activities, communicate risks or dependencies, and support successful implementation of security monitoring capabilities.
- Technical Leadership & Mentoring: Provide technical guidance and mentorship to junior SIEM engineers, support knowledge transfer, and assist with troubleshooting and complex engineering activities without serving as the team's formal people manager.
- Documentation: Develop and maintain detailed technical documentation, including architecture diagrams, integration procedures, configuration standards, troubleshooting guides, operational runbooks, and standard operating procedures.
- Vendor Management: Engage SIEM and security technology vendors to troubleshoot complex issues, evaluate platform capabilities, coordinate support cases, and assist with implementation or upgrade activities.
- Continuous Improvement: Identify opportunities to improve SIEM reliability, scalability, automation, operational efficiency, and engineering processes across supported environments.
Education Requirements
- Bachelor's degree in computer science, information security, or a related field. Will consider experience in lieu of a degree.
Salary Range: $120,000 - $170,000
General Description of Benefits
At least five years of relevant cybersecurity, SIEM, security engineering, or systems engineering experience, with demonstrated experience supporting enterprise security monitoring technologies. Strong knowledge of SIEM concepts and hands-on experience with one or more enterprise SIEM platforms such as Elastic Security, CrowdStrike Falcon Next-Gen SIEM, Splunk Enterprise Security, Microsoft Sentinel, or comparable technologies. Demonstrated experience deploying, configuring, maintaining, upgrading, and troubleshooting enterprise SIEM platforms and supporting infrastructure. Experience integrating enterprise data sources and security technologies into SIEM platforms, including troubleshooting ingestion, connectivity, parsing, normalization, and data quality issues. Strong understanding of Windows and Linux operating systems and the infrastructure, networking, and security concepts required to support enterprise SIEM environments. Working knowledge of cloud environments and cloud-based security telemetry, including platforms such as AWS, Microsoft Azure, and/or Google Cloud. Proficiency with scripting or automation technologies such as Python, PowerShell, Bash, REST APIs, or similar technologies. SIEM Query Languages: Proficiency with SIEM search, query, and analytics languages such as KQL, SPL, CQL, EQL, ES|QL, or similar technologies used to search, analyze, and troubleshoot security telemetry. Strong troubleshooting and problem-solving skills with the ability to independently investigate and resolve complex technical issues. Comprehensive understanding of cybersecurity concepts, security monitoring, common attack methodologies, and the role of SIEM technologies within security operations. Ability to lead complex technical efforts and provide guidance and mentorship to junior engineers. Strong verbal and written communication skills, including the ability to create technical documentation and communicate complex technical concepts to both technical and non-technical stakeholders. Ability to think strategically about SIEM technologies and identify opportunities to improve platform reliability, scalability, automation, and overall security capabilities using traditional methods and/or AI driven technologies.
Other Requirements of the position include:
- Able and willing to obtain a US Security Clearance.
- On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capabilities.