
Senior Information Security Engineer
Posted Jul 30

Posted Jul 30
This is a fully remote position, open to applicants in Massachusetts.
• Oversee, sustain, and enhance the on-premise SIEM platform, covering aspects such as log ingestion, parsing, correlation rules, dashboards, and alert notifications.
• Ensure the SIEM system's availability, performance, and scalability to meet the enterprise's security monitoring requirements.
• Develop and refine detection rules, correlation logic, and use cases that align with threat intelligence and organizational risk assessment.
• Manage the onboarding, configuration, and validation of log sources across servers, applications, network devices, and security tools.
• Conduct routine health checks of the SIEM, along with capacity planning and lifecycle management.
• Administer and sustain on-premise IDS/IPS platforms, ensuring precise detection and prevention of malicious activities.
• Adjust signatures, policies, and rulesets to minimize false positives while maintaining robust detection capabilities.
• Monitor the performance, availability, and event trends of IDS/IPS to detect anomalies or operational challenges.
• Collaborate with network and security teams to implement policy updates, rule modifications, and architectural enhancements.
• Ensure that both SIEM and IDS/IPS solutions comply with security governance frameworks, compliance standards, and organizational policies.
• Maintain comprehensive documentation for system configurations, processes, runbooks, and governance controls.
• Assist with audit processes by providing necessary evidence, reports, and system configuration information.
• Engage in incident response efforts by offering insights from SIEM/IDS/IPS, analyzing events, and providing technical expertise.
• Assess emerging threats and propose improvements to detection logic and monitoring capabilities.
• Work together with architecture and leadership teams to align SIEM and IDS/IPS strategies with long-term security goals.
• Identify opportunities to automate processes, enhance detection accuracy, and improve operational efficiency.
• At least 5 years of practical experience in administering, managing, and maintaining:
• An on-premise SIEM security solution, and
• An on-premise IDS/IPS security solution.
• Proven experience ensuring high availability, governance alignment, and operational efficiency of security monitoring technologies.
• Strong knowledge of SIEM architecture, log ingestion pipelines, correlation logic, and event normalization.
• Expertise in IDS/IPS technologies, signature tuning, network traffic analysis, and threat detection methods.
• Proficient with security log formats (syslog, JSON, CEF, LEEF, etc.).
• Familiarity with network protocols, firewall rules, and enterprise network architecture.
• Experience in Linux/Windows server administration as it pertains to security tools.
• Capability to analyze security events, recognize patterns, and assist in incident response.
• Strong analytical and problem-solving skills.
• Excellent communication abilities for effective cross-team collaboration.
• Capacity to work independently in a remote setting while handling multiple priorities.
• Detail-oriented approach with a strong commitment to governance, documentation, and operational discipline.
• Remote work arrangement
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.