SIEM Engineer (Cybersecurity Specialist SME L4)

ER Select LLC
Fort Belvoir, VA, United States
1 day ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Software System Penetration Testing Bash Shell Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Data Security Linux Domain Name System (DNS) Monitoring of Systems Hypertext Transfer Protocols (HTTP)
+21 more
Intrusion Detection and Prevention Intrusion Detection Systems Python (Programming Language) Network Architecture Networking Basics Performance Tuning Windows PowerShell Security Information and Event Management TCP/IP Enterprise Software Applications Cloud Platform System Data Ingestion Mitre Att&ck QRadar Cyber Threat Analysis Firewalls (Computer Science) Cybercrime ArcSight Event Correlation Splunk Security Orchestration, Automation & Response Vulnerability Analysis

Job description

  • Engineer, administer, optimize, and support enterprise SIEM platforms, including Splunk Enterprise Security (ES) and IBM QRadar.
  • Develop, implement, and maintain SIEM correlation rules, alerts, dashboards, reports, and detection use cases.
  • Perform log ingestion, normalization, management, correlation, and analysis across enterprise security environments.
  • Tune alerts and detection logic to improve fidelity, reduce false positives, and enhance threat-detection capabilities.
  • Analyze security telemetry from Windows, Linux, firewalls, IDS/IPS, cloud platforms, applications, and network infrastructure.
  • Develop SIEM use cases and detection rules aligned with organizational threats, risk profiles, and mission requirements.
  • Assess current cybersecurity posture, define acceptable levels of risk, and support formal security maintenance procedures.
  • Identify potential cybersecurity and information-security vulnerabilities through security assessments, penetration- testing activities, and red-team findings.
  • Support cloud security monitoring and integrate cloud-generated security telemetry into enterprise monitoring platforms.
  • Integrate SIEM capabilities with Security Orchestration, Automation, and Response (SOAR) technologies to improve security operations and incident-response efficiency.
  • Develop scripts and automation using Python, Bash, and/or PowerShell.
  • Apply NIST and MITRE ATT&CK frameworks to threat detection, monitoring, and security operations.
  • Support privacy impact assessments, PII data security and monitoring, migration strategies, and System Privacy Plans.
  • Provide subject matter expertise, cybersecurity guidance, documentation, and operational best practices to mission stakeholders.

Requirements

The ideal candidate will bring deep technical expertise in cybersecurity operations and SIEM engineering, with the ability to assess security posture, identify vulnerabilities, develop advanced detection rules and use cases, and strengthen the organization’s ability to identify and respond to cyber threats. Candidates must possess an active TS/SCI clearance., * Active TS/SCI security clearance.

  • Senior-level experience in cybersecurity engineering, security operations, SIEM engineering, or a closely related discipline.
  • Demonstrated hands-on experience with enterprise SIEM platforms, preferably Splunk Enterprise Security and/or IBM QRadar.
  • Strong experience with log management, event correlation, alert development and tuning, SIEM use-case development, detection engineering, and cyber threat analysis.
  • Strong understanding of security logs generated by Windows, Linux, firewalls, IDS/IPS technologies, cloud environments, and enterprise applications and infrastructure.
  • Working knowledge of scripting and automation using Python, Bash, and/or PowerShell.
  • Strong understanding of networking fundamentals and protocols, including TCP/IP, DNS, HTTP, and HTTPS.
  • Working knowledge of cybersecurity frameworks and methodologies, including NIST and MITRE ATT&CK., * Experience with cloud security monitoring and cloud-native security telemetry.
  • Experience with SOAR platforms, security automation, and automated incident-response workflows.
  • Experience supporting cybersecurity operations within the Federal Government, Department of Defense, or Intelligence Community.
  • Experience with threat hunting, penetration testing, vulnerability assessment, or red-team activities.
  • Experience developing advanced detection content mapped to the MITRE ATT&CK framework.

Preferred Certifications

  • Splunk Enterprise Security certifications
  • CompTIA Security+
  • CompTIA CySA+
  • CISSP
  • Other relevant cybersecurity, SIEM, cloud security, or information-assurance certifications

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all