- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 3 days ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
The SIEM Engineer is tasked with the design, deployment, administration, and enhancement of Security Information and Event Management (SIEM) systems and security monitoring functions throughout enterprise and cloud infrastructures. This position includes managing various log sources, integrations, detection rules, ensuring system integrity, and facilitating compliance alongside Security Operations Center (SOC) activities.
Key Responsibilities
- Architect, deploy, maintain, and resolve issues related to SIEM infrastructure and deployments.
- Administer SIEM platforms such as Splunk, Microsoft Sentinel, and Google SecOps.
- Integrate a broad range of security products including Firewalls, Antivirus (AV), Authentication, Authorization and Accounting (AAA), Data Loss Prevention (DLP), Intrusion Detection and Prevention Systems (IDS/IPS), and other security solutions.
- Onboard and manage log connectors, parsers, custom integrations, and log sources.
- Create and update security monitoring rules, alerts, reports, watchlists, and ensure compliance with relevant use cases.
- Manage and monitor cloud security logs from AWS, Azure, Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI).
- Conduct SIEM system health assessments, execute upgrades, patching, backups, troubleshoot and optimize performance.
- Develop scripts and queries utilizing technologies like SPL, KQL, Python, and Regular Expressions.
- Draft technical designs, prepare documentation, generate health reports, and produce other solution deliverables.
- Support SOC processes, enable automation efforts, and lead continuous enhancement of SIEM functionalities.
- Provide mentorship to junior SIEM engineers and collaborate with internal teams, clients, and vendor partners.
Qualifications and Experience
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a related discipline.
- Minimum of five years in Security Engineering, including at least three years of direct experience with SIEM platforms.
- Comprehensive understanding of information security principles, networking, and security monitoring frameworks.
- Practical experience with leading SIEM solutions such as Splunk, Microsoft Sentinel, or Google SecOps.
- Proven expertise in SIEM design, implementation, operational administration, integrations, and log source management.
- Experience monitoring security within cloud-native environments and managing associated logs.
- Strong analytical skills paired with abilities in troubleshooting, communication, and managing stakeholders.
- Available to work on-call shifts including nights or weekends when necessary.
Preferred Attributes
- Experience with Managed Security Service Providers (MSSP) or Managed Detection and Response (MDR) services and familiarity with regional markets.
- Capability in managing several SIEM platforms concurrently.
- Relevant certifications for SIEM platforms such as Splunk, Microsoft Sentinel, or Google SecOps.
- Expertise in SIEM automation, development of custom parsers, connectors, and security use cases.
Minimum education
Bachelor's Degree
Tools & software
Splunk Enterprise
required
Microsoft Sentinel
· 2 to 5 years required
How they work
Communication
Problem Solving
Relationship Building