← Back to jobs

SIEM Engineer

Location
New York City. NY
Work type
Full Time
Posted
2026-08-03

Job description

Key Responsibilities

SIEM Administration & Engineering
Manage and maintain enterprise SIEM platforms.
Configure and optimize log ingestion, normalization, parsing, and retention.
Integrate security data sources including:
Firewalls
IDS/IPS
EDR/XDR
Active Directory / Entra ID
Cloud platforms (Azure, AWS, GCP)
Network and endpoint security solutions
Ensure availability, scalability, and performance of SIEM infrastructure.
Detection Engineering & Use Case Development
Develop and maintain correlation rules, analytics, and detection content.
Create use cases aligned with MITRE ATT&CK techniques.
Tune detection rules to reduce false positives and improve alert fidelity.
Work with Purple Team, Red Team, and Threat Intelligence teams to improve detection coverage.
Implement new monitoring capabilities for emerging threats.
Security Monitoring & Incident Support
Support SOC operations through advanced threat detection and alert analysis.
Assist incident responders during investigations.
Correlate events across multiple technologies to identify malicious activity.
Perform root cause analysis and recommend containment improvements.
Develop dashboards and reporting for operational visibility.
Threat Hunting & Threat Intelligence Integration
Develop hunting queries to identify malicious behavior not detected by automated alerts.
Integrate threat intelligence feeds into the SIEM platform.
Create indicators of compromise (IOC) monitoring and enrichment processes.
Identify suspicious trends and emerging attack patterns.
Automation & Optimization
Automate SIEM administration and monitoring tasks using scripting.
Integrate SIEM with SOAR platforms and ticketing systems.
Develop workflows for alert enrichment, escalation, and incident response.
Improve operational efficiency through automation and orchestration.
Governance, Compliance & Reporting
Support regulatory and audit requirements.
Maintain SIEM documentation, runbooks, and standards.
Produce security metrics and executive reporting.
Ensure log retention and monitoring practices meet compliance requirements.

Required Qualifications

Experience

5+ years of cybersecurity experience.
3+ years managing and engineering SIEM platforms.
Experience supporting SOC operations and incident response.
Experience in financial services or regulated industries preferred.
Technical Skills

Expertise in platforms such as:
Microsoft Sentinel
Splunk
QRadar
LogRhythm
Elastic Security
CrowdStrike NG-SIEM
Cribl
Strong knowledge of:
Windows and Linux security logs
Network security monitoring
EDR/XDR technologies
Threat hunting methodologies
MITRE ATT&CK framework
Data ingestion pipelines
Scripting experience:
KQL
PowerShell
Python
SQL

Security Knowledge

Log management and event correlation.
Detection engineering.
Threat intelligence.
Incident response processes.
Vulnerability management concepts.
Zero Trust security principles.

Preferred Certifications

Microsoft Certified: Security Operations Analyst (SC-200)
Microsoft Sentinel Specialty
Splunk Enterprise Security Certified Admin
GIAC Certified Incident Handler (GCIH)
GIAC Certified Intrusion Analyst (GCIA)
CISSP

Original source