Principal SIEM Engineer

Posted 4 days ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Develop and sustain SOAR content, which includes configuring case management, escalation playbooks, and automations.

• Create and manage playbook templates, including bulk escalation templates for various source types, while coordinating modifications with SOC leadership.

• Configure and oversee the SIEM, which involves relay build and joining, log source tagging, regular expressions, parsing validation, and alert definitions.

• Construct and refine detection content across Suricata, CrowdStrike, Albert, endpoint, firewall, and network telemetry.

• Diagnose issues with the ingestion and case creation pipeline end to end, taking ownership of problems until resolution as the tier 2 escalation point.

• Engage in platform incident response and uphold alerting and routing duties for the after-hours on-call rotation.

• Handle technical escalations with the SIEM and SOAR vendor, identify vendor defects and regressions, and devise remediation strategies.

• Provide engineering guidance for MDR and SOC-as-a-service customer onboarding, encompassing use case verification, relay build, log collection verification, parsing validation, alert definitions, SOAR automation, user acceptance testing, and health monitoring.

• Create connector and log source integrations while automating repeatable build processes.

• Manage, develop, and refine queries, alerts, inputs, and scripts across cyber defense offerings and operations infrastructure.

• Design operational and customer-facing SIEM and SOAR dashboards utilizing live SOAR case data.

• Audit ingestion volume and reconfigure source volume and filtering to remain compliant with contractual limits.

• Maintain escalation runbooks, onboarding guides, and log source documentation.

• Offer technical insights to Product and leadership regarding SIEM/SOAR platform strategies, vendor renewals, ingest ceilings, licensing, and functionalities.

• Perform other assigned tasks and responsibilities.


⛳️ Requirements

• Bachelor’s degree in Information Technology, Cybersecurity, or a related discipline.

• Over 7 years of experience in deploying, engineering, and managing enterprise security monitoring and logging platforms, including log source onboarding, parsing, and detection content development.

• More than 7 years of experience in security operations or security engineering supporting a security operations center.

• At least 5 years of experience in creating SOAR automation within a production environment, including case management content, escalation playbooks, and integration with ticketing systems and third-party APIs.

• Proven experience troubleshooting a log pipeline end to end and resolving issues.

• Experience acting as a technical escalation point and managing platform vendor escalations.

• Familiarity with using or producing Cyber Threat Intelligence for network defense.

• Willingness to participate in an after-hours on-call rotation.

• Experience analyzing data from firewalls, intrusion detection and prevention systems, data loss prevention, endpoint security tools, host-based logs, network logs, syslog, and other sources.

• Proficiency in security log data enrichment, regular expressions (RegEx), SQL, Python, and analytical techniques.

• Experience in network forensics and tools such as Wireshark, PCAP, tcpdump, and MITRE ATT&CK.

• Knowledge of cloud technologies and providers such as Amazon, Azure, and Google.

• Strong client-facing and internal communication skills.

• Excellent organizational skills, attention to detail, and ability to multitask.

• Must be authorized to work in the United States.

• An advanced degree in Computer Science, Business, or a related field is a plus.

• Practical experience with SIEM and SOAR platforms is a plus.

• Experience onboarding customers to managed detection and response or SOC-as-a-service offerings is a plus.

• Familiarity with building relays or log collectors and connecting them to a SIEM, including TLS termination and client-side collection configuration is a plus.

• Experience creating detection content for network intrusion detection, endpoint detection and response, or firewall telemetry is a plus.

• Experience managing ingestion volume against a contracted licensing or volume ceiling is a plus.

• Experience mentoring engineers and cross-training peers on a SIEM or SOAR platform is a plus.

• Relevant industry certifications such as CISSP, GCIH, GCIA, GMON are a plus.

• Experience in incident response, vulnerability management, and security operations is a plus.

• Experience in vendor management and relationship building is a plus.

• Familiarity with Agile DevOps and project management methodologies is a plus.

• Strong knowledge of scripting languages such as Python and PowerShell is a plus.


🏝️ Benefits

• Participation in Tier 2 after-hours on-call rotation.

• An inclusive work environment that values diverse backgrounds, experiences, and perspectives.

• Additional years of relevant experience or a combination of an Associate’s degree or equivalent and relevant experience may substitute for the Bachelor’s degree.

People also viewed

Kigen IT21 hours ago

Microsoft 365 Engineer

DE flagGermany OnlyFull-timeEngineer
ApplyView job
CmdScale GmbH1 day ago

Senior Go Consultant – Engineer

DE flagGermany OnlyFull-timeEngineer€70k – €85k/year
ApplyView job
Cornelis Networks1 day ago

Senior ASIC Verification Engineer

US flagCalifornia OnlyFull-timeEngineer
ApplyView job
Sargent & Lundy2 days ago

Renewable Performance Engineer

US flagUnited States OnlyFull-timeEngineer$84.8k – $129.5k/year
ApplyView job
FusionTek2 days ago

IT Project Engineer

ZA flagSouth Africa OnlyFull-timeEngineerR500k – R750k/year
ApplyView job
Coretek2 days ago

Level 3 Managed Services Engineer – Microsoft

US flagUnited States OnlyFull-timeEngineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers