> Markdown version of [/jobs/ext/1888635-cyber-security-engineer-siem-and-automation](https://www.wearedevelopers.com/jobs/ext/1888635-cyber-security-engineer-siem-and-automation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer - SIEM and Automation - **Company:** Corebridge Financial - **Location:** Jersey City, NJ, United States - **Experience:** Expert - **Salary:** $168,000.0 - $195,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, Data Analysis, Application Layers, Microsoft Azure, Software as a Service, Cloud Computing, Apache Lucene, Cyber Security, Computer Programming, Query Languages, Linux, Identity and Access Management, Networking Hardware, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Parsing, Performance Tuning, Windows PowerShell, Kusto Query Language, Security Information and Event Management, SQL Databases, Data Logging, Scripting, Google Cloud, Cloud Platform System, Data Ingestion, Mitre Att&ck, QRadar, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Microsoft Sentinel, Splunk, Software Version Control, Security Orchestration, Automation & Response - **Published:** August 1, 2026 - **Apply:** https://www.dice.com/job-detail/e0a4b65a-dafb-41ab-9344-50c5a68713a5 ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent experience) * 3-7+ years of experience in SIEM engineering, detection engineering, or security operations * Hands-on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar, Elastic) * Strong understanding of log sources (Windows, Linux, cloud platforms, network devices) * Experience with query languages (e.g., SPL, KQL, Lucene, SQL) * Knowledge of MITRE ATT&CK framework and adversary tactics/techniques * Experience onboarding and parsing diverse data sources, * Experience with SOAR platforms and security automation * Familiarity with cloud environments (AWS, Azure, Google Cloud Platform) and their native logging tools * Scripting or programming skills (Python, PowerShell, etc.) * Experience with detection-as-code and version control practices * Security certifications (e.g., GCIA, GCIH, CISSP, Splunk Certified, Microsoft SC-200) Skills & Competencies * Strong analytical and problem-solving skills * Ability to balance detection fidelity with operational efficiency * Effective communication and collaboration across technical teams * Continuous learning mindset with a focus on threat-driven defense ## Description We are seeking a highly skilled Senior Cyber Security Engineer - SIEM and Automation to lead and enhance our detection engineering capabilities. This role is responsible for developing high-fidelity use cases, optimizing logging strategies, integrating security tools, and tuning alerts to improve signal-to-noise ratio. You will work closely with Security Operations, Threat Intelligence, and Engineering teams to ensure our SIEM platform delivers actionable insights and supports rapid incident detection and response. Responsibilities * Use Case Development + Design, develop, and maintain SIEM detection use cases aligned with MITRE ATT&CK and threat intelligence + Translate threat scenarios into actionable detection logic and correlation rules + Continuously improve detection coverage through gap analysis and adversary simulation insights * Logging & Data Analysis + Define and implement logging requirements across cloud, endpoint, network, and application layers + Analyze log sources to ensure data quality, normalization, and completeness + Identify gaps in telemetry and recommend improvements to enhance visibility * Tool Integration & Data Onboarding + Integrate new data sources into the SIEM (e.g., EDR, IAM, firewall, SaaS platforms) + Work with engineering teams to onboard logs using APIs, agents, and log pipelines + Ensure proper parsing, enrichment, and normalization of ingested data * Alert Tuning & Optimization + Reduce false positives through continuous alert tuning and threshold optimization + Implement risk-based alerting and prioritization strategies + Collaborate with SOC analysts to refine detection logic based on incident feedback * SIEM Platform Engineering + Maintain and optimize SIEM performance, scalability, and cost efficiency + Develop dashboards, reports, and visualizations for operational and leadership insights + Support automation and orchestration efforts with SOAR integrations where applicable * Collaboration & Continuous Improvement + Partner with Threat Intelligence to operationalize indicators and emerging threats + Support incident response investigations with log analysis and detection enhancements + Stay current with evolving attack techniques and detection methodologies ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)