SIEM Engineer II

Scigon Solutions, Inc.
Austin, TX, United States
25 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$149,000.0 - $166,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Cyber Security Data Auditing Data Integration Query Languages Intrusion Detection and Prevention Python (Programming Language) Performance Tuning
+12 more
Regular Expressions Kusto Query Language Security Information and Event Management Data Streaming Syslog Data Logging Scripting Google Cloud Cybercrime Data Analytics Microsoft Sentinel Splunk

Job description

What You’ll Do Are you a hands-on security engineer ready to deepen your expertise in SIEM platforms and help build scalable, data-driven detection capabilities? As a SIEM Engineer II, you will play a key role in the implementation, optimization, and day-to-day management of the organization//’s Security Information and Event Management (SIEM) platform. You’ll contribute to the ingestion, normalization, and enrichment of security telemetry while supporting detection engineering, incident response, and security analytics. Working within the Cybersecurity function, you’ll collaborate with Cybersecurity Operations, IT, Infrastructure, Cloud, and Application teams to onboard log sources, develop detections, and create dashboards that drive visibility and response. This is an opportunity to grow your technical depth while making a measurable impact on the organization’s security posture.

  • SIEM Platform Support - Assist in the implementation, administration, and ongoing optimization of the organization//’s SIEM platform (e.g., Google Security Operations (SecOps), Splunk, Exabeam, Microsoft Sentinel).
  • Cribl Development - Support the design and maintenance of Cribl pipelines, including data routing, filtering, enrichment, and performance optimization.
  • Log Integration - Build and maintain integrations for standard and custom log sources using APIs, agents, syslog, and cloud-native logging services.
  • Detection Enablement - Partner with Cybersecurity Operations to develop and refine SIEM use cases, correlation rules, and alerting logic.
  • Dashboards & Reporting - Create and enhance dashboards, searches, and reports to support Security Operations Center (SOC) activities and threat hunting.
  • Documentation - Contribute to documentation of SIEM architecture, data flows, onboarding processes, and operational procedures.
  • Data Quality Assurance - Help establish and monitor data quality standards to ensure reliable and accurate telemetry.
  • Cross-Team Collaboration - Work with IT, Cloud, and Application teams to onboard new systems and ensure proper logging coverage.
  • Incident Support - Provide support during security incidents, assisting with investigation and analysis efforts.
  • Continuous Learning - Stay current on SIEM technologies, security analytics, and observability trends to enhance capabilities.

Requirements

  • Education - Bachelor’s degree or equivalent professional experience required.
  • Experience - Minimum of 3-5 years in IT or engineering, with at least 2-3 years focused on SIEM, logging, or security analytics.
  • SIEM Fundamentals - Hands-on experience working with SIEM platforms such as Google SecOps (Chronicle), Splunk, Exabeam, or Microsoft Sentinel.
  • Cribl Exposure - Experience working with Cribl, including pipeline configuration and log onboarding, preferred.
  • Data Integration Skills - Familiarity with integrating log sources using APIs, syslog, or agents.
  • Analytics & Visualization - Experience building dashboards, alerts, and queries to support security monitoring and operations.
  • Security Knowledge - Understanding of common log sources, including endpoint, network, identity, cloud, SaaS (Software as a Service), and application logs.
  • Collaboration & Communication - Ability to work effectively with cross-functional teams and communicate technical concepts clearly.
  • Technical Foundation - Exposure to scripting or query languages (e.g., SPL, KQL, Python, Regex) and cloud platforms (AWS, Azure, GCP) is a plus.
  • Problem Solving & Growth Mindset - Strong analytical skills, attention to detail, and a proactive approach to learning and improvement.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

46 sec

Automating telemetry collection through robust Telegraf deployment

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all