> Markdown version of [/jobs/ext/3093038-siem-engineer-cybersecurity-specialist-sme-l4](https://www.wearedevelopers.com/jobs/ext/3093038-siem-engineer-cybersecurity-specialist-sme-l4). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SIEM Engineer (Cybersecurity Specialist SME L4) - **Company:** ER Select LLC - **Location:** Fort Belvoir, VA, United States - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software System Penetration Testing, Bash Shell, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Data Security, Linux, Domain Name System (DNS), Monitoring of Systems, Hypertext Transfer Protocols (HTTP), Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Network Architecture, Networking Basics, Performance Tuning, Windows PowerShell, Security Information and Event Management, TCP/IP, Enterprise Software Applications, Cloud Platform System, Data Ingestion, Mitre Att&ck, QRadar, Cyber Threat Analysis, Firewalls (Computer Science), Cybercrime, ArcSight Event Correlation, Splunk, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** September 26, 2026 - **Apply:** https://www.juju.com/job/16_d890c8071 ## About the Role The ideal candidate will bring deep technical expertise in cybersecurity operations and SIEM engineering, with the ability to assess security posture, identify vulnerabilities, develop advanced detection rules and use cases, and strengthen the organization's ability to identify and respond to cyber threats. Candidates must possess an active TS/SCI clearance., * Active TS/SCI security clearance. * Senior-level experience in cybersecurity engineering, security operations, SIEM engineering, or a closely related discipline. * Demonstrated hands-on experience with enterprise SIEM platforms, preferably Splunk Enterprise Security and/or IBM QRadar. * Strong experience with log management, event correlation, alert development and tuning, SIEM use-case development, detection engineering, and cyber threat analysis. * Strong understanding of security logs generated by Windows, Linux, firewalls, IDS/IPS technologies, cloud environments, and enterprise applications and infrastructure. * Working knowledge of scripting and automation using Python, Bash, and/or PowerShell. * Strong understanding of networking fundamentals and protocols, including TCP/IP, DNS, HTTP, and HTTPS. * Working knowledge of cybersecurity frameworks and methodologies, including NIST and MITRE ATT&CK., * Experience with cloud security monitoring and cloud-native security telemetry. * Experience with SOAR platforms, security automation, and automated incident-response workflows. * Experience supporting cybersecurity operations within the Federal Government, Department of Defense, or Intelligence Community. * Experience with threat hunting, penetration testing, vulnerability assessment, or red-team activities. * Experience developing advanced detection content mapped to the MITRE ATT&CK framework. Preferred Certifications * Splunk Enterprise Security certifications * CompTIA Security+ * CompTIA CySA+ * CISSP * Other relevant cybersecurity, SIEM, cloud security, or information-assurance certifications ## Description * Engineer, administer, optimize, and support enterprise SIEM platforms, including Splunk Enterprise Security (ES) and IBM QRadar. * Develop, implement, and maintain SIEM correlation rules, alerts, dashboards, reports, and detection use cases. * Perform log ingestion, normalization, management, correlation, and analysis across enterprise security environments. * Tune alerts and detection logic to improve fidelity, reduce false positives, and enhance threat-detection capabilities. * Analyze security telemetry from Windows, Linux, firewalls, IDS/IPS, cloud platforms, applications, and network infrastructure. * Develop SIEM use cases and detection rules aligned with organizational threats, risk profiles, and mission requirements. * Assess current cybersecurity posture, define acceptable levels of risk, and support formal security maintenance procedures. * Identify potential cybersecurity and information-security vulnerabilities through security assessments, penetration- testing activities, and red-team findings. * Support cloud security monitoring and integrate cloud-generated security telemetry into enterprise monitoring platforms. * Integrate SIEM capabilities with Security Orchestration, Automation, and Response (SOAR) technologies to improve security operations and incident-response efficiency. * Develop scripts and automation using Python, Bash, and/or PowerShell. * Apply NIST and MITRE ATT&CK frameworks to threat detection, monitoring, and security operations. * Support privacy impact assessments, PII data security and monitoring, migration strategies, and System Privacy Plans. * Provide subject matter expertise, cybersecurity guidance, documentation, and operational best practices to mission stakeholders. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)