Sr. SIEM Engineering Consultant

ecsfederal

Virginia (MN)

Hybrid

USD 140,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Everforth ECS is seeking a Sr. SIEM Engineering Consultant to join our MSSP team remotely.

You will design, deploy, and maintain Microsoft Sentinel environments at scale, building ingestion pipelines, analytics, dashboards, and automation to improve security visibility and response. You will work with engineering, DevOps, cloud, and client teams to implement security monitoring across Azure, AWS, GCP, and hybrid environments, using Terraform, Ansible, and CI/CD to automate deployments, while

Qualifications

  • Hands-on experience with Microsoft Sentinel and Azure Monitor
  • Proficient in KQL for detection development
  • Strong scripting skills (Python, PowerShell, Bash)
  • Experience designing, deploying, and operating production-scale SIEM environments
  • Familiarity with data connectors, log ingestion, and analytics rules
  • Ability to mentor teams and collaborate across engineering, DevOps, cloud, and client teams

Responsibilities

  • Design, deploy, and maintain Microsoft Sentinel environments
  • Build data ingestion pipelines, detection rules, queries, dashboards, and automation workflows
  • Write scripts and integrations to streamline security operations
  • Deploy and manage Sentinel across Azure with AWS/GCP and hybrid/on-prem
  • Use Terraform, Ansible, CI/CD for deployments
  • Integrate Sentinel with Defender, identity providers, firewalls, EDR and telemetry sources
  • Monitor health and optimize for cost, reliability, and scalability
  • Develop detection use cases aligned to MITRE ATT&CK
  • Configure incident management, alert grouping, and response workflows
  • Implement playbooks for automation and response
  • Lead design reviews and share SIEM best practices
  • Maintain architecture docs, runbooks, and best practices
  • Stay current with Microsoft security technologies

Skills

Microsoft Sentinel
Azure Monitor
KQL
Python
PowerShell
Bash
Terraform
Ansible
CI/CD
Incident response
Data ingestion

Tools

Log Analytics
Workbooks
Terraform
Ansible

Job description

Everforth ECS is seeking aSr. SIEM Engineering Consultant to join our team remotely. This position is contingent upon contract award.

Are you passionate about building and scaling cloud-native SIEM solutions and eager to make an immediate technical impact? Join ECS, a leading provider of cloud, AI, data, and enterprise transformation solutions. In this role, you will implement, optimize, and maintain Microsoft Sentinel environments at scale while contributing to architecture, automation, and integrations that improve security visibility, detection, and operational efficiency.

We are seeking a Sr. SIEM Engineering Consultant to join our Managed Security Services (MSSP) team. The ideal candidate has hands-on experience with Microsoft Sentinel and enjoys designing, coding, and deploying complex security monitoring and detection solutions. You will collaborate with engineering, DevOps, cloud, and client teams to deliver resilient, high-performance SIEM capabilities while maintaining visibility into threats, system health, and operational workflows.

Key Responsibilities:
  • Design, deploy, and maintain Microsoft Sentinel environments, including Log Analytics Workspaces and data connectors.
  • Build and optimize data ingestion pipelines, detection rules (analytics), queries (KQL), dashboards (Workbooks), and automation workflows.
  • Write scripts, automation, and integrations (Python, PowerShell, Bash, etc.) to streamline security operations, data processing, and monitoring.
  • Deploy and manage Sentinel across cloud environments, primarily Azure, with integrations into AWS, GCP, and hybrid/on-premises environments.
  • Leverage automation and orchestration tools such as Terraform, Ansible, CI/CD pipelines, and infrastructure-as-code to manage deployments and operational tasks.
  • Integrate Sentinel with enterprise tools such as Microsoft Defender, identity providers, firewalls, EDR platforms, and other telemetry sources.
  • Monitor system health, troubleshoot ingestion and performance issues, and optimize for cost, reliability, and scalability.
  • Develop and tune detection use cases aligned to threat frameworks (e.g., MITRE ATT&CK).
  • Configure incident management, alert grouping, and response workflows within Sentinel.
  • Implement automation and response using playbooks (Logic Apps) for alert enrichment and remediation.
  • Lead design reviews, provide guidance on SIEM best practices, and support knowledge sharing across teams.
  • Maintain documentation for architectures, detection logic, deployment patterns, runbooks, and operational best practices.
  • Stay current with Microsoft security technologies, Sentinel features, and emerging SIEM capabilities.

Salary Range: $140,000 - $180,000

General Description of Benefits

  • Deep, hands-on expertise with Microsoft Sentinel and Azure Monitor (Log Analytics, KQL, data connectors).
  • Strong experience with SIEM engineering, including log ingestion, normalization, detection engineering, and incident response workflows.
  • Proficiency in Kusto Query Language (KQL) for detection development and data analysis.
  • Strong scripting and automation skills (Python, PowerShell, Bash, etc.).
  • Solid understanding of security operations, threat detection, and observability in distributed systems.
  • Experience designing, deploying, and optimizing production-scale SIEM environments.
  • Strong knowledge of Azure, cloud security architecture, networking, and identity systems.
  • Ability to mentor, guide, and influence engineering teams on SIEM and security best practices.
  • Outstanding verbal and written communication skills.
  • Willingness and ability to support domestic or international on-site engagements.
  • U.S. Passport required.
  • Must be eligible to obtain a U.S. Security Clearance.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Senior SIEM Engineer — Microsoft Sentinel Expert
Remote Senior SIEM Engineer — Microsoft Sentinel Expert

ecsfederal • Virginia (MN)

Hybrid
USD 140,000 - 180,000
Sentinel Engineer (Fully remote, Westcoast Hours)
Sentinel Engineer (Fully remote, Westcoast Hours)

SkyeBiz • United States

Remote
USD 135,000 - 155,000
SIEM Engineer III
SIEM Engineer III

ecsfederal • Virginia (MN)

Hybrid
USD 120,000 - 170,000
Microsoft Sentinel Security Platform Engineer
Microsoft Sentinel Security Platform Engineer

Allied Consultants, Inc. • Austin (TX)

On-site
USD 120,000 - 190,000
Highly competitive pay rates
Medical insurance
401(k) plan with company match
+1
Azure Engineer (Sentinel)
Azure Engineer (Sentinel)

Primo Talents Inc • Sentinel (OK)

On-site
USD 83,000 - 138,000
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)

LevelBlue, LLC. • Northern (KY)

Hybrid
USD 120,000 - 190,000
Senior SIEM Engineer — Remote
Senior SIEM Engineer — Remote

ecsfederal • Virginia (MN)

Hybrid
USD 120,000 - 170,000
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)

Trustwave • United States

On-site
USD 140,000 - 190,000
Software Developer - Microsoft Sentinel
Software Developer - Microsoft Sentinel

Cyberobotix • Austin (TX)

On-site
USD 90,000 - 120,000
Competitive salary
Flexible work environment
Remote Senior SIEM Engineer — Cloud & On-Prem
Remote Senior SIEM Engineer — Cloud & On-Prem

ECS • Richmond (VA)

On-site
USD 120,000 - 170,000