
Senior Information Security Engineer
Posted Jul 30

Posted Jul 30
This is a fully remote position, open to applicants in Massachusetts.
• Oversee, sustain, and enhance the on-premise SIEM platform, focusing on log ingestion, parsing, correlation rules, dashboards, and alerting mechanisms.
• Guarantee the SIEM's availability, performance, and scalability to effectively meet enterprise security monitoring demands.
• Create and refine detection rules, correlation logic, and use cases that align with threat intelligence and organizational risk assessments.
• Supervise the onboarding, configuration, and validation of log sources across servers, applications, network devices, and security tools.
• Perform regular health assessments of the SIEM, including capacity planning and lifecycle management.
• Manage and uphold on-premise IDS/IPS platforms to ensure accurate detection and prevention of malicious activities.
• Adjust signatures, policies, and rulesets to minimize false positives while maintaining robust detection coverage.
• Track IDS/IPS performance, availability, and event trends to detect anomalies or operational problems.
• Collaborate with network and security teams to implement policy updates, rule modifications, and architectural enhancements.
• Ensure alignment of SIEM and IDS/IPS solutions with security governance frameworks, compliance mandates, and organizational policies.
• Keep documentation updated for system configurations, processes, runbooks, and governance controls.
• Assist in audit activities by providing evidence, reports, and details of system configurations.
• Engage in incident response initiatives by delivering insights from SIEM/IDS/IPS, event analysis, and technical expertise.
• Analyze emerging threats and propose improvements to detection logic and monitoring capabilities.
• Work in partnership with architecture and leadership teams to align SIEM and IDS/IPS strategies with long-term security goals.
• Recognize opportunities for process automation, detection fidelity enhancement, and operational efficiency improvements.
• A minimum of 5 years of practical experience in administering, managing, and maintaining:
• An on-premise SIEM security solution, and
• An on-premise IDS/IPS security solution.
• Proven experience in ensuring high availability, governance compliance, and operational effectiveness of security monitoring technologies.
• Strong comprehension of SIEM architecture, log ingestion pipelines, correlation logic, and event normalization.
• Expertise in IDS/IPS technologies, signature tuning, network traffic analysis, and threat detection techniques.
• Proficient in security log formats (syslog, JSON, CEF, LEEF, etc.).
• Knowledgeable about network protocols, firewall rules, and enterprise network architecture.
• Experience in Linux/Windows server administration as it pertains to security tools.
• Ability to analyze security events, recognize patterns, and support incident response efforts.
• Strong analytical and problem-solving skills.
• Excellent communication abilities for cross-team collaboration.
• Capability to work autonomously in a remote setting while managing multiple priorities.
• Detail-oriented approach with a commitment to governance, documentation, and operational discipline.
• Preferred Qualifications (Optional Enhancements):
• Industry certifications such as:
• GIAC (GCIA, GCDA, GCED, GMON)
• CompTIA Security+ / CySA+
• CISSP or equivalent.
• Experience in automation (Python, PowerShell, or similar).
• Familiarity with threat intelligence platforms and frameworks (MITRE ATT&CK, NIST CSF).
•
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.