Senior Data Protection Engineer (REMOTE)

The Hanover Insurance Group Inc
United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$112,000.0 - $140,000.0
Working hours
Regular working hours
Job source

Tech stack

CompTIA Security+ Cyber Security Computer Networks System Configuration Linux Monitoring of Systems Networking Hardware Intrusion Detection and Prevention Intrusion Detection Systems JSON Python (Programming Language) Windows Servers
+12 more
Network Forensics Network Protocols Performance Tuning Windows PowerShell Runbook Security Log Security Information and Event Management Syslog Data Ingestion System Availability Mitre Att&ck Firewall Services Module

Job description

The Security Engineer (SIEM & IDS/IPS Administrator) is responsible for the end to end administration, maintenance, and optimization of the organization’s on premise Security Information and Event Management (SIEM) platform and Intrusion Detection/Prevention Systems (IDS/IPS). This role ensures that these critical security technologies remain highly available, strategically aligned with enterprise security objectives, governed according to policy, and operating at peak effectiveness.

The engineer will work closely with cybersecurity, infrastructure, and governance teams to ensure that threat detection, alerting, and response capabilities are robust, reliable, and continuously improving.

This is a full time, exempt position.

IN THIS ROLE, YOU WILL: SIEM Administration & Engineering

  • Manage, maintain, and optimize the on premise SIEM platform, including log ingestion, parsing, correlation rules, dashboards, and alerting.
  • Ensure SIEM availability, performance, and scalability to support enterprise security monitoring needs.
  • Develop and tune detection rules, correlation logic, and use cases aligned with threat intelligence and organizational risk.
  • Oversee log source onboarding, configuration, and validation across servers, applications, network devices, and security tools.
  • Conduct regular SIEM health checks, capacity planning, and lifecycle management.

IDS/IPS Administration & Engineering

  • Administer and maintain on premise IDS/IPS platforms, ensuring accurate detection and prevention of malicious activity.
  • Tune signatures, policies, and rulesets to reduce false positives while maintaining strong detection coverage.
  • Monitor IDS/IPS performance, availability, and event trends to identify anomalies or operational issues.
  • Coordinate with network and security teams to implement policy updates, rule changes, and architectural improvements.

Operational Excellence & Governance

  • Ensure both SIEM and IDS/IPS solutions are aligned with security governance frameworks, compliance requirements, and organizational policies.
  • Maintain documentation for system configurations, processes, runbooks, and governance controls.
  • Support audit activities by providing evidence, reports, and system configuration details.
  • Participate in incident response activities by providing SIEM/IDS/IPS insights, event analysis, and technical expertise.

Strategic Alignment & Continuous Improvement

  • Evaluate emerging threats and recommend enhancements to detection logic and monitoring capabilities.
  • Collaborate with architecture and leadership teams to align SIEM and IDS/IPS strategies with long term security objectives.
  • Identify opportunities to automate processes, improve detection fidelity, and enhance operational efficiency.

Requirements

Do you have experience in Windows Server administration?, * Minimum 5 years of hands on experience administering, managing, and maintaining:

  • An on premise SIEM security solution, and
  • An on premise IDS/IPS security solution
  • Demonstrated experience ensuring high availability, governance alignment, and operational effectiveness of security monitoring technologies.
  • Strong understanding of SIEM architecture, log ingestion pipelines, correlation logic, and event normalization.
  • Expertise with IDS/IPS technologies, signature tuning, network traffic analysis, and threat detection methodologies.
  • Proficiency with security log formats (syslog, JSON, CEF, LEEF, etc.).
  • Familiarity with network protocols, firewall rules, and enterprise network architecture.
  • Experience with Linux/Windows server administration as it relates to security tooling.
  • Ability to analyze security events, identify patterns, and support incident response.
  • Strong analytical and problem solving abilities.
  • Excellent communication skills for cross team collaboration.
  • Ability to work independently in a remote environment while managing multiple priorities.
  • Detail oriented mindset with a commitment to governance, documentation, and operational discipline.
  • Preferred Qualifications (Optional Enhancements)
  • Industry certifications such as:
  • GIAC (GCIA, GCDA, GCED, GMON)
  • CompTIA Security+ / CySA+
  • CISSP or equivalent
  • Experience with automation (Python, PowerShell, or similar).
  • Familiarity with threat intelligence platforms and frameworks (MITRE ATT&CK, NIST CSF).

Benefits & conditions

3.63.6 out of 5 stars Remote $112,000 - $140,000 a year - Full-time, Pulled from the full job description

  • Tuition reimbursement
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Disability insurance, We offer comprehensive benefits to help you be healthy, build financial security, and balance work and home life. At The Hanover, you’ll enjoy what you do and have the support you need to succeed.

Benefits include:

  • Medical, dental, vision, life, and disability insurance
  • 401K with a company match
  • Tuition reimbursement
  • PTO
  • Company paid holidays
  • Flexible work arrangements
  • Cultural Awareness Day in support of IDE
  • On-site medical/wellness center (Worcester only)
  • Click here for the full list of Benefits

About the company

For more than 170 years, The Hanover has been committed to delivering on our promises and being there when it matters the most. We live our values every day, demonstrating we CARE through our values, Sustainability initiatives and inclusive corporate culture.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

46 sec

Automating telemetry collection through robust Telegraf deployment

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

2:30 min

Discovering and instrumenting services using systemd process enumeration

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all