SIEM Engineer

Zachary Piper
Newington, VA, United States
28 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$180,000.0 - $195,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Linux Domain Name System (DNS) Monitoring of Systems Hypertext Transfer Protocols (HTTP)
+22 more
Intrusion Detection and Prevention Intrusion Detection Systems Python (Programming Language) Network Security Log Analysis Performance Tuning Windows PowerShell Security Information and Event Management TCP/IP Scripting Google Cloud In-Plane Switching (IPS) Data Ingestion Mitre Att&ck Cyber Threat Analysis Firewalls (Computer Science) Cybercrime ArcSight Event Correlation Cyber Warfare Splunk Security Orchestration, Automation & Response Vulnerability Analysis

Job description

is seeking a to join a federal technology services organization supporting enterprise cybersecurity operations and mission-critical security programs. This role is and

This role will involve designing, implementing, tuning, and optimizing Splunk Enterprise and Splunk Enterprise Security to strengthen enterprise security monitoring, threat detection, incident response, and SIEM operations while partnering with security engineering, SOC, threat intelligence, and infrastructure teams to enhance overall cybersecurity visibility and resilience.

  • Design, implement, configure, and maintain and to support enterprise-scale security monitoring and threat detection.
  • Develop, optimize, and tune to improve detection accuracy and reduce false positives.
  • Analyze and correlate security events across to identify threats and support incident response.
  • Manage log ingestion, normalization, retention, and event correlation to ensure effective SIEM operations and data visibility.
  • Partner with to improve monitoring capabilities and overall security posture.
  • Support cybersecurity investigations by identifying, analyzing, and responding to security events across multiple data sources.
  • Implement automation and scripting solutions using to improve operational efficiency and SIEM functionality.
  • Support continuous improvement initiatives by integrating threat intelligence, cloud security monitoring, SOAR capabilities, and cybersecurity best practices into the enterprise security platform., Keywords: Splunk, Splunk Enterprise, Splunk Enterprise Security, Splunk ES, SIEM, SIEM Engineering, SIEM Administration, Security Information and Event Management, Security Monitoring, Security Analytics, Detection Engineering, Detection Rules, Correlation Searches, Event Correlation, Log Management, Log Analysis, Log Ingestion, Alert Tuning, Use Case Development, Threat Detection, Threat Hunting, Incident Response, Incident Investigation, Cybersecurity, Cyber Defense, SOC, Security Operations Center, SOC Analyst, Security Engineering, Threat Intelligence, Threat Intelligence Integration, Windows Logs, Linux Logs, Firewall Logs, IDS, IPS, IDS/IPS, Cloud Logs, AWS, Azure, GCP, Cloud Security, Cloud Security Monitoring, SOAR, Security Automation, Python, Bash, PowerShell, Scripting, Automation, TCP/IP, DNS, HTTP, HTTPS, Networking, Network Security, NIST, MITRE ATT&CK, Security Frameworks, Enterprise Security, Security Operations, Vulnerability Analysis, Security Event Analysis, Enterprise Monitoring, Data Correlation, Security Visibility, Federal, DoD, Department of Defense, Government, TS/SCI, Top Secret, SCI, Cleared, Security+, CompTIA Security+, CySA+, CISSP

Requirements

  • Bachelor’s degree in , or a related field (or equivalent experience).
  • of experience in .
  • Hands-on experience with , , or other SIEM platforms such as .
  • Experience with .
  • Strong understanding of .
  • Experience with , along with knowledge of , and cybersecurity frameworks including and .
  • Experience with , , , and supporting is preferred.
  • Active

Benefits & conditions

  • Salary Range: $180,000 - $195,000 depending on experience
  • Comprehensive Benefits: Cigna Medical, Dental, Vision, 401k Plan, PTO, Holidays, Sick Leave if required by law

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · WWC 2022

Videos

See all

Related articles

See all