> Markdown version of [/jobs/ext/1274958-siem-engineer](https://www.wearedevelopers.com/jobs/ext/1274958-siem-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SIEM Engineer - **Company:** Zachary Piper - **Location:** Newington, VA, United States - **Salary:** $180,000.0 - $195,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Linux, Domain Name System (DNS), Monitoring of Systems, Hypertext Transfer Protocols (HTTP), Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Network Security, Log Analysis, Performance Tuning, Windows PowerShell, Security Information and Event Management, TCP/IP, Scripting, Google Cloud, In-Plane Switching (IPS), Data Ingestion, Mitre Att&ck, Cyber Threat Analysis, Firewalls (Computer Science), Cybercrime, ArcSight Event Correlation, Cyber Warfare, Splunk, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** July 15, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9031029/siem-engineer ## About the Role * Bachelor's degree in , or a related field (or equivalent experience). * of experience in . * Hands-on experience with , , or other SIEM platforms such as . * Experience with . * Strong understanding of . * Experience with , along with knowledge of , and cybersecurity frameworks including and . * Experience with , , , and supporting is preferred. * Active ## Description is seeking a to join a federal technology services organization supporting enterprise cybersecurity operations and mission-critical security programs. This role is and This role will involve designing, implementing, tuning, and optimizing Splunk Enterprise and Splunk Enterprise Security to strengthen enterprise security monitoring, threat detection, incident response, and SIEM operations while partnering with security engineering, SOC, threat intelligence, and infrastructure teams to enhance overall cybersecurity visibility and resilience. * Design, implement, configure, and maintain and to support enterprise-scale security monitoring and threat detection. * Develop, optimize, and tune to improve detection accuracy and reduce false positives. * Analyze and correlate security events across to identify threats and support incident response. * Manage log ingestion, normalization, retention, and event correlation to ensure effective SIEM operations and data visibility. * Partner with to improve monitoring capabilities and overall security posture. * Support cybersecurity investigations by identifying, analyzing, and responding to security events across multiple data sources. * Implement automation and scripting solutions using to improve operational efficiency and SIEM functionality. * Support continuous improvement initiatives by integrating threat intelligence, cloud security monitoring, SOAR capabilities, and cybersecurity best practices into the enterprise security platform., Keywords: Splunk, Splunk Enterprise, Splunk Enterprise Security, Splunk ES, SIEM, SIEM Engineering, SIEM Administration, Security Information and Event Management, Security Monitoring, Security Analytics, Detection Engineering, Detection Rules, Correlation Searches, Event Correlation, Log Management, Log Analysis, Log Ingestion, Alert Tuning, Use Case Development, Threat Detection, Threat Hunting, Incident Response, Incident Investigation, Cybersecurity, Cyber Defense, SOC, Security Operations Center, SOC Analyst, Security Engineering, Threat Intelligence, Threat Intelligence Integration, Windows Logs, Linux Logs, Firewall Logs, IDS, IPS, IDS/IPS, Cloud Logs, AWS, Azure, GCP, Cloud Security, Cloud Security Monitoring, SOAR, Security Automation, Python, Bash, PowerShell, Scripting, Automation, TCP/IP, DNS, HTTP, HTTPS, Networking, Network Security, NIST, MITRE ATT&CK, Security Frameworks, Enterprise Security, Security Operations, Vulnerability Analysis, Security Event Analysis, Enterprise Monitoring, Data Correlation, Security Visibility, Federal, DoD, Department of Defense, Government, TS/SCI, Top Secret, SCI, Cleared, Security+, CompTIA Security+, CySA+, CISSP ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)