SIEM & UEBA Engineer (Mid) – Threat Detection

Socket.dev

Washington (District of Columbia)

Hybrid

USD 125,000 - 165,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
401(k) with company matching
Flexible spending accounts
Paid time off
Paid holidays

Job summary

Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced SIEM/UEBA Engineer (Mid) to support enterprise cybersecurity operations for a federal client. Primary work will be at the client site in Washington, DC, with approved remote/telework options.

The role focuses on engineering, administering, and continuously improving SIEM and UEBA platforms, building high‑fidelity detection content, and supporting threat detection and incident response across on‑prem and cloud

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or related field.
  • 3–5 years of hands‑on experience in SIEM engineering, security operations, or a closely related cybersecurity discipline within a federal government IT contracting or enterprise security environment.
  • Hands‑on experience administering and engineering enterprise SIEM platforms, including log source onboarding, parser development, detection rule creation, alert tuning, and platform administration.
  • Experience developing detection content aligned with the MITRE ATT&CK framework, including correlation rules, behavioral analytics, and threshold‑based alerting.
  • Experience with log ingestion architecture design, including the onboarding and normalization of diverse log source types across endpoint, network, application, cloud, and identity platforms.
  • Active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations.

Responsibilities

  • SIEM Platform Engineering & Administration: administer, engineer, and maintain the enterprise SIEM platform; design and maintain log ingestion architectures; develop onboarding docs and runbooks; monitor health and capacity; manage access controls; support upgrades and changes; document architecture.
  • UEBA Platform Engineering & Administration: integrate data sources, model baselines, tune risk scores and anomalies; develop UEBA use cases for insider threats and credential abuse; monitor health and documentation.
  • Detection Engineering & Content Development: design and tune detection rules and queries aligned with MITRE ATT&CK; conduct coverage assessments; develop content for high‑priority threat scenarios; perform tuning to reduce false positives.
  • Log Source Management & Data Normalization: maintain log source inventory; develop custom parsers and mappings; ensure data quality and onboarding of new sources.
  • Security Analytics & Threat Intelligence Integration: develop analytics, ingest threat intel, enrich alerts, support threat hunting and investigate findings.
  • Incident Investigation Support: provide targeted queries, timelines, and playbooks; develop dashboards; support post‑incident reviews.
  • Reporting, Metrics & Documentation: produce performance metrics, executive reports, and engineering docs; support metrics dashboards.
  • Compliance & ATO Support: ensure configurations comply with federal frameworks; support SSP and continuous monitoring.

Skills

SIEM engineering
Security operations
UEBA administration
Incident investigation support
Threat detection

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or related field

Tools

Splunk
Microsoft Sentinel
IBM QRadar
Elastic SIEM

Job description

Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced SIEM/UEBA Engineer (Mid) to support enterprise cybersecurity operations for a federal client. Primary work will be at the client site in Washington, DC, with approved remote/telework options.

The role focuses on engineering, administering, and continuously improving SIEM and UEBA platforms, building high‑fidelity detection content, and supporting threat detection and incident response across on‑prem and cloud

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM & UEBA Engineer (Mid) - Federal
SIEM & UEBA Engineer (Mid) - Federal

Koniag Services, Inc. • Washington, Northern (KY)

Hybrid
USD 110,000 - 150,000
Health, dental & vision insurance
401K with company match
Flexible spending accounts
+2
Remote Junior SIEM & UEBA Engineer
Remote Junior SIEM & UEBA Engineer

Socket.dev • Washington

Hybrid
USD 65,000 - 90,000
Health insurance
401K with company matching
Paid holidays
Junior SIEM & UEBA Engineer - Federal Ops
Junior SIEM & UEBA Engineer - Federal Ops

Koniag Government Services • Washington

On-site
USD 70,000 - 90,000
Health insurance
Dental insurance
Vision insurance
+4
Senior SIEM & Detection Engineering Lead
Senior SIEM & Detection Engineering Lead

K2United, LLC. • Washington

On-site
USD 150,000 - 190,000
Mid-Level SIEM Engineer: Real-Time Security & Monitoring
Mid-Level SIEM Engineer: Real-Time Security & Monitoring

ECS Corporate Services • Washington

On-site
USD 108,000 - 125,000
Strong communication skills
STIGs knowledge
CRIBL knowledge
+3
AI Security Engineer (Mid) - Federal Cyber Defense
AI Security Engineer (Mid) - Federal Cyber Defense

Koniag Government Services • Washington

Hybrid
USD 110,000 - 165,000
Health insurance
Dental insurance
401K with company match
+2
Mid-Level SIEM Engineer — Federal Cyber Defense
Mid-Level SIEM Engineer — Federal Cyber Defense

Everforth ECS • Washington

On-site
USD 90,000 - 130,000
Mid-Level SOC Analyst: Threat Detection & Incident Response
Mid-Level SOC Analyst: Threat Detection & Incident Response

Koniag Services, Inc. • Washington

On-site
USD 85,000 - 120,000
Senior SIEM & Security Monitoring Engineer
Senior SIEM & Security Monitoring Engineer

K2Share LLC • Washington

On-site
USD 140,000 - 190,000
SIEM Engineer - Mid
SIEM Engineer - Mid

ECS Corporate Services • Washington

On-site
USD 108,000 - 125,000
Strong communication skills
STIGs knowledge
CRIBL knowledge
+3