Senior SIEM Engineer

atCoalfireRemoteUS flagUnited StatesFull-timeEngineerSenior$85k – $141k/year

Posted Sep 1

This is a fully remote position, open to applicants in United States.

📋 Description

• Design, implement, and sustain SIEM platform architectures across AWS, Azure, and GCP environments.

• Construct and manage log collection and ingestion pipelines utilizing forwarders, collectors, connectors, APIs, syslog, agents, and cloud-native services.

• Onboard, normalize, validate, and troubleshoot data sources spanning cloud platforms, operating systems, applications, network devices, identity systems, endpoint tools, and security controls.

• Establish platform standards for parsing, data models, field mappings, naming conventions, tagging, retention policies, archival processes, access protocols, and lifecycle management.

• Oversee SIEM platforms, including configuration, upgrades, patching, capacity planning, performance tuning, storage optimization, licensing, and availability monitoring.

• Develop and uphold infrastructure-as-code, automation, and deployment workflows.

• Implement platform monitoring and health checks.

• Integrate SIEM platforms with endpoint, identity, vulnerability management, threat intelligence, network security, ticketing, and incident response systems.

• Provide data and platform services to detection engineering and security operations teams.

• Support FedRAMP continuous monitoring and associated compliance requirements.

• Engage in platform changes, releases, migrations, and modernization initiatives.

• Adhere to and enhance operational runbooks for incidents, outages, ingestion failures, and performance degradation.

• Troubleshoot complex platform and integration issues, escalating as necessary.

• Create technical documentation, architecture diagrams, standard operating procedures, knowledge-base articles, and handoff materials.

• Participate in client meetings as a technical resource.

• Contribute to platform roadmaps, operational metrics, service improvements, and reusable patterns.


⛳️ Requirements

• Demonstrated experience in implementing, administering, or operating SIEM and security logging platforms within enterprise, cloud, or high-compliance environments.

• Proven ability to deliver platform capabilities from requirements and design phases through implementation, validation, documentation, and operational handoff.

• Successful track record of integrating security, cloud, endpoint, identity, network, and operational tools into a unified monitoring platform.

• Experience in diagnosing issues related to data quality, ingestion, pipeline, performance, availability, access, and integration.

• Background in working within strict regulatory or industry frameworks.

• Hands-on experience in systems engineering and architecture.

• Familiarity with cloud services, particularly AWS, Azure, or GCP.

• Administration and troubleshooting experience with Splunk, Microsoft Sentinel, Elastic, or Sumo Logic.

• Knowledge of log collection, ingestion, parsing, normalization, enrichment, and retention workflows.

• Working knowledge of cloud-native logging and security services, operating systems, networking, identity, APIs, and enterprise security tools.

• Experience with automation and infrastructure-as-code using Terraform, Ansible, GitLab, GitHub, Python, or similar technologies.

• Understanding of monitoring, alerting, capacity planning, performance management, availability, backup, recovery, and disaster recovery practices.

• Ability to work effectively in Agile environments with cross-functional technical teams.

• Strong communication, organizational, documentation, and problem-solving abilities.

• Capacity to work independently as well as collaboratively.

• Critical-thinking skills to balance security, compliance, reliability, cost, and mission requirements.

• Ability to adapt swiftly in fast-paced, dynamic settings.

• Possession of one SIEM or security operations certification, such as Splunk Enterprise Certified Admin, Sumo Logic Administration, or Microsoft Security Operations Analyst Associate.

• Holding one professional-level cloud certification, such as AWS Solutions Architect Professional, AWS DevOps Engineer Professional, Azure Solutions Architect Expert, or GCP Cloud Architect.

• Bachelor’s degree in information technology, computer science, cybersecurity, or a related field, or equivalent combination of education and work experience.


🏝️ Benefits

• Flexible work model allowing employees to choose when and where they work most effectively.

• Employee resource groups.

• In-person and virtual events.

• Paid parental leave.

• Flexible time off.

• Certification and training reimbursement.

• Digital mental health and wellbeing support membership.

• Comprehensive insurance options.

• Equal opportunity and pay equity.

• Reasonable accommodation for individuals with disabilities.

People also viewed

Contentstack1 day ago

Partner Engineer

EuropeFull-timeEngineer€80k – €100k/year
ApplyView job
Rich Products Australia1 day ago

Senior Foundry Engineer

US flagAlabama, +42 more statesFull-timeEngineer$135.9k – $183.9k/year
ApplyView job
Energy Systems Group (ESG)1 day ago

Performance Engineer

US flagNew York OnlyFull-timeEngineer
ApplyView job
Mitsubishi Electric Power Products, Inc.1 day ago

Systems Studies Engineer III

US flagPennsylvania OnlyFull-timeEngineer
ApplyView job
Energy Systems Group (ESG)1 day ago

Performance Engineer

US flagNew Hampshire, +1 more stateFull-timeEngineer
ApplyView job
Energy Systems Group (ESG)1 day ago

Performance Engineer

US flagConnecticut, +6 more statesFull-timeEngineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers