SIEM Engineer

Systemtec, Inc.
United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$180,960.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Data Analysis ARM Architecture Bash Shell Software as a Service Cloud Computing CompTIA Security+ Cyber Security Linux Identity and Access Management Intrusion Detection and Prevention Python (Programming Language)
+11 more
Parsing Performance Tuning Runbook Security Information and Event Management Systems Integration Scripting Cyber Threat Analysis Information Technology Cybercrime 3-tier Architectures Security Orchestration, Automation & Response

Job description

SYSTEMTEC is seeking a SIEM Engineer for a remote opportunity for candidates working EST hours. The Candidate will serve as a SIEM Security Engineer supporting the design, implementation, optimization, and administration of enterprise security monitoring and XDR platforms within a complex, multi-tenant environment. The role partners with security engineers, architects, and SOC analysts to strengthen threat detection, automate response processes, and ensure the reliability and performance of critical cybersecurity technologies supporting 24x7 operations., * Design, implement, administer, and optimize Palo Alto Cortex XSIAM and Cortex XDR platforms to enhance enterprise threat detection and response capabilities.

  • Develop and maintain detection content, analytics, dashboards, threat hunting queries, automation, and response playbooks to improve security operations.
  • Engineer and support Cribl log pipelines, including data modeling, normalization, enrichment, routing, and telemetry ingestion from diverse technology platforms.
  • Integrate security platforms with enterprise tools such as ticketing, identity management, threat intelligence, and notification systems while ensuring platform performance and reliability.
  • Support Security Operations Center teams through troubleshooting, detection tuning, threat hunting, documentation, and knowledge transfer activities.
  • Monitor platform health, optimize system performance, and collaborate with technical stakeholders to continuously improve enterprise security monitoring capabilities.

Requirements

  • Applicants must be authorized to work for any employer in the U.S. We are unable to provide sponsorship or work with Third-Party agencies.
  • Bachelor’s degree in Information Technology, Information Security, Cybersecurity, or a related field (8+ years of relevant experience may be substituted for a degree).
  • Minimum of five years of experience supporting large enterprise IT environments and/or enterprise technology deployments.
  • Hands-on experience designing, implementing, administering, and supporting Palo Alto Cortex XSIAM and Cortex XDR.
  • Experience engineering and supporting enterprise SIEM platforms within multi-tenant environments and 24x7 Security Operations Centers.
  • Strong experience developing and tuning detections, correlation rules, analytics, threat hunting queries, dashboards, and alert suppression logic.
  • Experience with Cribl data modeling, log pipeline design, parsing, normalization, enrichment, routing, and ingestion.
  • Experience creating security automation, integrations, and playbooks using scripting languages such as Python and Bash.
  • Experience onboarding and troubleshooting telemetry from cloud, endpoint, network, identity, SaaS, Windows, Linux, and custom application sources.
  • Strong understanding of enterprise security architecture, networking, incident response, access control, secure system design, and cybersecurity best practices.

Preferred Skills/Experience of the SIEM Engineer (Palo Alto Cortex XSIAM/XDR):

  • CISSP, Security+, GIAC, or similar cybersecurity certification.
  • Palo Alto Cortex, Cribl, or other SIEM/security platform certifications.
  • Experience administering Cortex XSIAM and Cortex XDR in large-scale, multi-tenant environments.
  • Experience supporting Tier 1-Tier 3 SOC analysts, threat hunting, and incident response activities.
  • Experience developing operational documentation, playbooks, runbooks, and technical procedures.

Benefits & conditions

4.44.4 out of 5 stars United States Remote Up to $87 an hour - Contract, Pulled from the full job description

  • Tuition reimbursement
  • 401(k)
  • Health insurance
  • Paid time off
  • Dental insurance
  • Life insurance
  • Disability insurance, Full-Time Employment with SYSTEMTEC means a competitive salary + paid OT, PTO, holidays, health, dental, disability, and life coverage, 401K, tuition reimbursement and more

Please note: SYSTEMTEC is not set up to employ workers in the states of California, New York, and New Jersey.

Pay: Up to $87.00 per hour

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:56 min

Open-sourcing a complex parsing library for game data

Johan Hutting Johan Hutting · WWC 2024

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:36 min

Managing complex operation sequence weights using recursive parsing

Florian Rappl · LIVE

Videos

See all

Related articles

See all