
Senior SIEM Engineer
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in United States.
• Design, implement, and sustain SIEM platform architectures across AWS, Azure, and GCP environments.
• Construct and manage log collection and ingestion pipelines utilizing forwarders, collectors, connectors, APIs, syslog, agents, and cloud-native services.
• Onboard, normalize, validate, and troubleshoot data sources spanning cloud platforms, operating systems, applications, network devices, identity systems, endpoint tools, and security controls.
• Establish platform standards for parsing, data models, field mappings, naming conventions, tagging, retention policies, archival processes, access protocols, and lifecycle management.
• Oversee SIEM platforms, including configuration, upgrades, patching, capacity planning, performance tuning, storage optimization, licensing, and availability monitoring.
• Develop and uphold infrastructure-as-code, automation, and deployment workflows.
• Implement platform monitoring and health checks.
• Integrate SIEM platforms with endpoint, identity, vulnerability management, threat intelligence, network security, ticketing, and incident response systems.
• Provide data and platform services to detection engineering and security operations teams.
• Support FedRAMP continuous monitoring and associated compliance requirements.
• Engage in platform changes, releases, migrations, and modernization initiatives.
• Adhere to and enhance operational runbooks for incidents, outages, ingestion failures, and performance degradation.
• Troubleshoot complex platform and integration issues, escalating as necessary.
• Create technical documentation, architecture diagrams, standard operating procedures, knowledge-base articles, and handoff materials.
• Participate in client meetings as a technical resource.
• Contribute to platform roadmaps, operational metrics, service improvements, and reusable patterns.
• Demonstrated experience in implementing, administering, or operating SIEM and security logging platforms within enterprise, cloud, or high-compliance environments.
• Proven ability to deliver platform capabilities from requirements and design phases through implementation, validation, documentation, and operational handoff.
• Successful track record of integrating security, cloud, endpoint, identity, network, and operational tools into a unified monitoring platform.
• Experience in diagnosing issues related to data quality, ingestion, pipeline, performance, availability, access, and integration.
• Background in working within strict regulatory or industry frameworks.
• Hands-on experience in systems engineering and architecture.
• Familiarity with cloud services, particularly AWS, Azure, or GCP.
• Administration and troubleshooting experience with Splunk, Microsoft Sentinel, Elastic, or Sumo Logic.
• Knowledge of log collection, ingestion, parsing, normalization, enrichment, and retention workflows.
• Working knowledge of cloud-native logging and security services, operating systems, networking, identity, APIs, and enterprise security tools.
• Experience with automation and infrastructure-as-code using Terraform, Ansible, GitLab, GitHub, Python, or similar technologies.
• Understanding of monitoring, alerting, capacity planning, performance management, availability, backup, recovery, and disaster recovery practices.
• Ability to work effectively in Agile environments with cross-functional technical teams.
• Strong communication, organizational, documentation, and problem-solving abilities.
• Capacity to work independently as well as collaboratively.
• Critical-thinking skills to balance security, compliance, reliability, cost, and mission requirements.
• Ability to adapt swiftly in fast-paced, dynamic settings.
• Possession of one SIEM or security operations certification, such as Splunk Enterprise Certified Admin, Sumo Logic Administration, or Microsoft Security Operations Analyst Associate.
• Holding one professional-level cloud certification, such as AWS Solutions Architect Professional, AWS DevOps Engineer Professional, Azure Solutions Architect Expert, or GCP Cloud Architect.
• Bachelor’s degree in information technology, computer science, cybersecurity, or a related field, or equivalent combination of education and work experience.
• Flexible work model allowing employees to choose when and where they work most effectively.
• Employee resource groups.
• In-person and virtual events.
• Paid parental leave.
• Flexible time off.
• Certification and training reimbursement.
• Digital mental health and wellbeing support membership.
• Comprehensive insurance options.
• Equal opportunity and pay equity.
• Reasonable accommodation for individuals with disabilities.
Rich Products Australia
Energy Systems Group (ESG)
Mitsubishi Electric Power Products, Inc.
Get handpicked remote jobs straight to your inbox weekly.