Senior SIEM Engineer

Rockwell Automation, Inc.
Mayfield Heights, United States of America
1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Mayfield Heights, United States of America

Tech stack

Artificial Intelligence
Amazon Web Services (AWS)
Azure
Cloud Computing Security
Computer Security
Data Normalization
Query Languages
Intrusion Detection and Prevention
Python
Log Analysis
Powershell
Kusto Query Language
Security Information and Event Management
SQL Databases
Scripting (Bash/Python/Go/Ruby)
Google Cloud Platform
Mitre Att&ck
QRadar
Information Technology
Splunk

Job description

The Senior SIEM Engineer is responsible for engineering, optimizing, and scaling the enterprise SIEM platform to enhance threat detection and incident response across the organization. You will develop detection logic, integrates diverse log sources, collaborates with SOC/IR teams, and drives automation to elevate security maturity. Responsibilities

  • Administer, enhance, and maintain the SIEM platform, including agent/app/addon upgrades and log source onboarding.
  • Build and optimize correlation rules, detection use cases, dashboards, and reporting content.
  • Integrate threat intelligence feeds to strengthen detection capabilities.
  • Analyze logs and security events to identify anomalies or advanced attack patterns.
  • Partner with SOC/IR teams on investigations, tuning, enrichment, and automation workflows.
  • Create and maintain runbooks, documentation, and SIEM best practices.
  • Lead SIEM improvements, scaling efforts, and crossfunctional enablement.

Requirements

  • Bachelor's Degree or Equivalent Years of Relevant Work Experience
  • Legal authorization to work in the U.S. We will not sponsor individuals for employment visas, now or in the future, for this job opening.

The Preferred - You Might Also Have:

  • Bachelor's degree in Cybersecurity, Computer Science, or related field OR equivalent experience.
  • 5+ years of experience with SIEM platforms (e.g., Sentinel, Splunk, QRadar, LogRhythm).
  • Strong knowledge of detection engineering, log parsing, and data normalization.
  • Proficiency with KQL, SQL, or similar query languages.
  • Understanding of incident response, SOC workflows, and security operations.
  • Experience with SOAR, automation workflows, or Logic Apps.
  • Cloud security experience (Azure, AWS, GCP).
  • Scripting (Python, PowerShell).
  • Familiarity with MITRE ATT&CK, NIST, or ISO frameworks.
  • Relevant certifications: AZ-500, AZ-104, AZ-900, AZ-303/304, DP-900, AI-900, Splunk certifications, etc.

Benefits & conditions

Rockwell Automation paid time off, 401(k) 1 Allen Bradley Drive (Show on map) Mar 03, 2026 Milwaukee, Wisconsin, United States United States of America Houston (N. Dairy Ashford Road) Mequon, Wisconsin, United States Mayfield Heights, Ohio, United States, What We Offer:

  • Health Insurance including Medical, Dental and Vision
  • 401k
  • Paid Time off
  • Parental and Caregiver Leave
  • Flexible Work Schedule where you will work with your manager to enjoy a work schedule that can be flexible with your personal life.

About the company

Rockwell Automation is a global technology leader focused on helping the world's manufacturers be more productive, sustainable, and agile. With more than 28,000 employees who make the world better every day, we know we have something special. Behind our customers - amazing companies that help feed the world, provide life-saving medicine on a global scale, and focus on clean water and green mobility -our people are energized problem solvers that take pride in how thework we do changes the world for the better. We welcome all makers, forward thinkers, and problem solvers who are looking for a place to do their best work. And if that's you we would love to have you join us!

Apply for this position