> Markdown version of [/jobs/ext/1179768-ts-sci-siem-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/1179768-ts-sci-siem-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # TS/SCI Siem Cyber Security Engineer - **Company:** Insight Global - **Location:** San Antonio, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Intrusion Detection Systems, Python (Programming Language), Log Analysis, Machine Learning, Network Forensics, Windows PowerShell, ArcSight SIEM Tool, Security Information and Event Management, Mitre Att&ck, Information Technology, Cybercrime, Cyber Warfare, Splunk, Custom Reports, Programming Languages - **Published:** July 4, 2026 - **Apply:** https://www.juju.com/job/00000000gdjeg6 ## About the Role * Active Top-Secret SCI (TS/SCI) security clearance * Active GIAC Machine Learning Engineer (GMLE) certification or a bachelor's degree in computer science * 2-3+ years of experience using SIEM technology (ArcSight, Splunk, and/or ELK) for log handling, reports, filters, rule creation, etc. * 2-3+ years of network traffic analysis experience (understanding protocols and identifying ports) * Experience with DoD (Air Force, Navy, Army, etc.) Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) * Experience with MITRE ATT&CK framework * Experience with Security, Orchestration, Automation, and Response (SOAR) platforms such as Phantom or Demisto * Experience with Python and PowerShell ## Description Insight Global is seeking a SIEM Cyber Security Engineer to support a critical mission focused on detecting, analyzing, and responding to cyber threats across a large enterprise environment. This role plays a key part in improving security visibility, reducing false positives, and ensuring early detection of malicious activity through effective SIEM content and automation. Key responsibilities include: * Analyze cyber defense (DCO) events and security logs to identify malicious or suspicious activity * Apply current industry SIEM best practices to improve detection accuracy and overall performance * Correlate security alerts with enriched log data to distinguish legitimate threats from false positives * Monitor and assess the effectiveness of security controls, including identifying unauthorized outbound connections * Develop and maintain SIEM detections and use cases through enterprise-wide log analysis * Build dashboards and visualizations that highlight adversary behavior and security trends * Create virtual "tripwires" using log data to enable early threat detection * Design, implement, test, and tune SIEM solutions to optimize performance and reliability * Build, test, and validate SIEM rules, filters, and correlation logic * Continuously tune SIEM content to reduce noise caused by known behavior, false positives, and system errors * Analyze malware threats and develop behavior-based detections to alert on or prevent malicious activity * Automate SIEM tasks using scripting or programming languages * Create scheduled and ad-hoc reports using SIEM tools to support operational and compliance needs * Develop and maintain SIEM documentation, processes, and knowledge repositories * Track metrics and trends to measure detection effectiveness and improve mission outcomes * Support operational leadership with SIEM content development and reporting needs ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)