
Principal SIEM Engineer
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in United States.
• Develop and sustain SOAR content, which includes configuring case management, escalation playbooks, and automations.
• Create and manage playbook templates, including bulk escalation templates for various source types, while coordinating modifications with SOC leadership.
• Configure and oversee the SIEM, which involves relay build and joining, log source tagging, regular expressions, parsing validation, and alert definitions.
• Construct and refine detection content across Suricata, CrowdStrike, Albert, endpoint, firewall, and network telemetry.
• Diagnose issues with the ingestion and case creation pipeline end to end, taking ownership of problems until resolution as the tier 2 escalation point.
• Engage in platform incident response and uphold alerting and routing duties for the after-hours on-call rotation.
• Handle technical escalations with the SIEM and SOAR vendor, identify vendor defects and regressions, and devise remediation strategies.
• Provide engineering guidance for MDR and SOC-as-a-service customer onboarding, encompassing use case verification, relay build, log collection verification, parsing validation, alert definitions, SOAR automation, user acceptance testing, and health monitoring.
• Create connector and log source integrations while automating repeatable build processes.
• Manage, develop, and refine queries, alerts, inputs, and scripts across cyber defense offerings and operations infrastructure.
• Design operational and customer-facing SIEM and SOAR dashboards utilizing live SOAR case data.
• Audit ingestion volume and reconfigure source volume and filtering to remain compliant with contractual limits.
• Maintain escalation runbooks, onboarding guides, and log source documentation.
• Offer technical insights to Product and leadership regarding SIEM/SOAR platform strategies, vendor renewals, ingest ceilings, licensing, and functionalities.
• Perform other assigned tasks and responsibilities.
• Bachelor’s degree in Information Technology, Cybersecurity, or a related discipline.
• Over 7 years of experience in deploying, engineering, and managing enterprise security monitoring and logging platforms, including log source onboarding, parsing, and detection content development.
• More than 7 years of experience in security operations or security engineering supporting a security operations center.
• At least 5 years of experience in creating SOAR automation within a production environment, including case management content, escalation playbooks, and integration with ticketing systems and third-party APIs.
• Proven experience troubleshooting a log pipeline end to end and resolving issues.
• Experience acting as a technical escalation point and managing platform vendor escalations.
• Familiarity with using or producing Cyber Threat Intelligence for network defense.
• Willingness to participate in an after-hours on-call rotation.
• Experience analyzing data from firewalls, intrusion detection and prevention systems, data loss prevention, endpoint security tools, host-based logs, network logs, syslog, and other sources.
• Proficiency in security log data enrichment, regular expressions (RegEx), SQL, Python, and analytical techniques.
• Experience in network forensics and tools such as Wireshark, PCAP, tcpdump, and MITRE ATT&CK.
• Knowledge of cloud technologies and providers such as Amazon, Azure, and Google.
• Strong client-facing and internal communication skills.
• Excellent organizational skills, attention to detail, and ability to multitask.
• Must be authorized to work in the United States.
• An advanced degree in Computer Science, Business, or a related field is a plus.
• Practical experience with SIEM and SOAR platforms is a plus.
• Experience onboarding customers to managed detection and response or SOC-as-a-service offerings is a plus.
• Familiarity with building relays or log collectors and connecting them to a SIEM, including TLS termination and client-side collection configuration is a plus.
• Experience creating detection content for network intrusion detection, endpoint detection and response, or firewall telemetry is a plus.
• Experience managing ingestion volume against a contracted licensing or volume ceiling is a plus.
• Experience mentoring engineers and cross-training peers on a SIEM or SOAR platform is a plus.
• Relevant industry certifications such as CISSP, GCIH, GCIA, GMON are a plus.
• Experience in incident response, vulnerability management, and security operations is a plus.
• Experience in vendor management and relationship building is a plus.
• Familiarity with Agile DevOps and project management methodologies is a plus.
• Strong knowledge of scripting languages such as Python and PowerShell is a plus.
• Participation in Tier 2 after-hours on-call rotation.
• An inclusive work environment that values diverse backgrounds, experiences, and perspectives.
• Additional years of relevant experience or a combination of an Associate’s degree or equivalent and relevant experience may substitute for the Bachelor’s degree.
CmdScale GmbH
Cornelis Networks
Sargent & Lundy
Get handpicked remote jobs straight to your inbox weekly.