SIEM Engineer (Cybersecurity Specialist SME L4)
ER Select LLC
Fort Belvoir, VA, United States
1 day ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.juju.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source
Tech stack
Microsoft Windows
Software System Penetration Testing
Bash Shell
Cloud Computing
Cloud Computing Security
CompTIA Security+
Cyber Security
Data Security
Linux
Domain Name System (DNS)
Monitoring of Systems
Hypertext Transfer Protocols (HTTP)
+21 more
Intrusion Detection and Prevention
Intrusion Detection Systems
Python (Programming Language)
Network Architecture
Networking Basics
Performance Tuning
Windows PowerShell
Security Information and Event Management
TCP/IP
Enterprise Software Applications
Cloud Platform System
Data Ingestion
Mitre Att&ck
QRadar
Cyber Threat Analysis
Firewalls (Computer Science)
Cybercrime
ArcSight Event Correlation
Splunk
Security Orchestration, Automation & Response
Vulnerability Analysis
Job description
- Engineer, administer, optimize, and support enterprise SIEM platforms, including Splunk Enterprise Security (ES) and IBM QRadar.
- Develop, implement, and maintain SIEM correlation rules, alerts, dashboards, reports, and detection use cases.
- Perform log ingestion, normalization, management, correlation, and analysis across enterprise security environments.
- Tune alerts and detection logic to improve fidelity, reduce false positives, and enhance threat-detection capabilities.
- Analyze security telemetry from Windows, Linux, firewalls, IDS/IPS, cloud platforms, applications, and network infrastructure.
- Develop SIEM use cases and detection rules aligned with organizational threats, risk profiles, and mission requirements.
- Assess current cybersecurity posture, define acceptable levels of risk, and support formal security maintenance procedures.
- Identify potential cybersecurity and information-security vulnerabilities through security assessments, penetration- testing activities, and red-team findings.
- Support cloud security monitoring and integrate cloud-generated security telemetry into enterprise monitoring platforms.
- Integrate SIEM capabilities with Security Orchestration, Automation, and Response (SOAR) technologies to improve security operations and incident-response efficiency.
- Develop scripts and automation using Python, Bash, and/or PowerShell.
- Apply NIST and MITRE ATT&CK frameworks to threat detection, monitoring, and security operations.
- Support privacy impact assessments, PII data security and monitoring, migration strategies, and System Privacy Plans.
- Provide subject matter expertise, cybersecurity guidance, documentation, and operational best practices to mission stakeholders.
Requirements
The ideal candidate will bring deep technical expertise in cybersecurity operations and SIEM engineering, with the ability to assess security posture, identify vulnerabilities, develop advanced detection rules and use cases, and strengthen the organization’s ability to identify and respond to cyber threats. Candidates must possess an active TS/SCI clearance., * Active TS/SCI security clearance.
- Senior-level experience in cybersecurity engineering, security operations, SIEM engineering, or a closely related discipline.
- Demonstrated hands-on experience with enterprise SIEM platforms, preferably Splunk Enterprise Security and/or IBM QRadar.
- Strong experience with log management, event correlation, alert development and tuning, SIEM use-case development, detection engineering, and cyber threat analysis.
- Strong understanding of security logs generated by Windows, Linux, firewalls, IDS/IPS technologies, cloud environments, and enterprise applications and infrastructure.
- Working knowledge of scripting and automation using Python, Bash, and/or PowerShell.
- Strong understanding of networking fundamentals and protocols, including TCP/IP, DNS, HTTP, and HTTPS.
- Working knowledge of cybersecurity frameworks and methodologies, including NIST and MITRE ATT&CK., * Experience with cloud security monitoring and cloud-native security telemetry.
- Experience with SOAR platforms, security automation, and automated incident-response workflows.
- Experience supporting cybersecurity operations within the Federal Government, Department of Defense, or Intelligence Community.
- Experience with threat hunting, penetration testing, vulnerability assessment, or red-team activities.
- Experience developing advanced detection content mapped to the MITRE ATT&CK framework.
Preferred Certifications
- Splunk Enterprise Security certifications
- CompTIA Security+
- CompTIA CySA+
- CISSP
- Other relevant cybersecurity, SIEM, cloud security, or information-assurance certifications
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.juju.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
about 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
KD
Krissy Davis
Best Paying Jobs in Technology
over 3 years ago
LM
Luis Minvielle
The 12 Best Jobs for Software Engineers
over 2 years ago