> Markdown version of [/jobs/ext/1421563-cyber-security-siem-engineer](https://www.wearedevelopers.com/jobs/ext/1421563-cyber-security-siem-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security SIEM Engineer - **Company:** Morrow Group - **Location:** Houston, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Apple Mac Systems, Cyber Security, System Configuration, Linux, Intrusion Detection Systems, Storage Area Network (SAN), OSI Models, McAfee VirusScan, Microsoft Visio, Microsoft SQL Server, Oracle (Applications), Security Information and Event Management, SQL Databases, Syslog, Systems Integration, TCP/IP, In-Plane Switching (IPS), Firewalls (Computer Science), Information Technology, Search Engines, Database Monitoring - **Published:** July 24, 2026 - **Apply:** http://www.themorrowgrp.com/pages/career-opportunities/jobs-list.html?dis=detail&ID=226 ## About the Role of support for all products offered by Security Operations Travel Job Type Regular Date Required Job Requirements • Expert-level understanding and knowledge of the principles of log management and preferably the McAfee (Nitro) SIEM toolset • Experience planning, scaling, implementing, monitoring, and troubleshooting an SIEM environment • Expert-level knowledge of the OSI model • Knowledge of core security principles and tool management that is product agnostic • Clear understanding of Windows AD logs, SQL and Oracle events • Excellent problem-solving and technical skills dealing with technical users • Must possess the ability to provide best practices subject matter expertise regarding log management system integration, alerting and reporting. • High analytical skills: must be able to perform analysis and tuning of all incoming security events for threat detection, and increase the efficiency of processing, maximize true threat identification, and ensure accurate reports for auditing. Has the ability to draw meaningful conclusions from reported events, and implement appropriate reporting. • Required to understand the business and technical requirements, architecture and design specifications and developing the associated content and documentation. • Detail-oriented, self-motivated and disciplined, with excellent time management skills • 5+ years of Information Technology experience • 4+ years of Information Security experience • 3+ years administrative experience deploying, configuring, troubleshooting, and maintaining SIEM components • 3+ years engineering experience creating correlation, dashboard, and reporting content using SIEM • Advanced knowledge of content creation concepts and best practices • Advanced networking experience • Excellent problem-solving and technical skills • Experience with any combination of the following: Visio, Syslog, Syslog-NG, TCP/IP, Networking, Linux/Unix, Windows, OSX, Active Directory, Event Analysis, NIST standards and guidelines, Database Activity Monitoring, MS SQL, Oracle, SAN architecture, firewalls, IPS/IDS, A/V, advanced networking, McAfee ## Description Job Title Cyber Security SIEM Engineer Job Description • Administer, operate, and maintain SIEM environment, including installation, configuration, tuning, and maintenance of SIEM components, such as: event collectors, loggers, correlation engine, and databases • Upgrade and patch the SIEM and other security platforms to the latest versions • Develop processes and documentation to magnify the benefits of existing tools • Perform security gap analysis in support of new products as well as the tuning of existing tools • Work with internal customers to develop requirements to meet their security objectives related to Log Management and SIEM • Provide Security Consulting services to their IT and other Business Units • Create collaborative environment that encourages growth and information sharing including mentoring and educating team members • Review current reporting and compliance goals, and verify reports to ensure they are meeting these goals • Provide the highest level ## Related Videos - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)