> Markdown version of [/jobs/ext/564883-senior-siem-engineer](https://www.wearedevelopers.com/jobs/ext/564883-senior-siem-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior SIEM Engineer - **Company:** Valiant Solutions, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Application Layers, Audit Trail, Bash Shell, Cloud Computing, Computer Telephony Integration, Software Design Patterns, Issue Tracking Systems, Information Model, Python (Programming Language), Windows PowerShell, Zero Trust Network Access, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Cloud Platform System, Mitre Att&ck, Amazon Virtual Private Cloud (VPC), Git, 3-tier Architectures, Splunk, Software Version Control, Servicenow - **Published:** June 13, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6cdea07c5ad4d3c2 ## About the Role Do you have experience in Version control systems?, Eligibility Requirements: U.S. Citizenship is required due to federal contract obligations, and applicants must be able to successfully pass a federal background investigation. Required Experience: * Eight or more years of cybersecurity engineering experience, with at least five years dedicated to SIEM architecture, administration, and content development. * Hands-on experience designing and operating distributed SIEM deployments at enterprise scale, including indexer clusters, search head clusters, heavy and universal forwarders, deployment servers, and license management. * Demonstrated experience writing, tuning, and optimizing queries, correlation searches, data models, accelerated summaries, lookups, and macros. * Working knowledge of security focused SIEM components, including notable event framework, risk-based alerting, asset and identity frameworks, and adaptive response actions. * Experience in onboarding diverse data sources at scale, including operating system logs, network flow and packet data, cloud platform logs (AWS CloudTrail, GuardDuty, VPC Flow, Config), endpoint telemetry, application logs, and identity provider logs. * Experience integrating SIEM with SOAR platforms, Endpoint Detection and Response tools, Continuous Diagnostics and Mitigation (CDM) data feeds, vulnerability management platforms, and ticketing systems such as ServiceNow. * Working knowledge of AWS GovCloud services and the design patterns used to forward, normalize, and secure log data from cloud-native sources. * Familiarity with the MITRE ATT&CK framework and experience translating adversary techniques into SIEM detection content. * Working knowledge of NIST SP 800-53, NIST SP 800-61, and NIST SP 800-137, and the ability to map SIEM controls and continuous monitoring practices to those frameworks. * Experience supporting incident response activities, including building investigation dashboards, preserving log evidence, and producing artifacts for post-incident reporting. * Strong scripting and automation skills in at least one of Python, Bash, or PowerShell, and comfort with version control using Git. * Beneficial Splunk certifications: Splunk Core Certified Power User and Splunk Enterprise Certified Admin. Splunk Certified Architect, Splunk Enterprise Security Certified Admin, or Splunk Core Certified Consultant is strongly preferred. * Required to obtain and maintain a Non-Sensitive / High Risk (Public Trust) security clearance at the Tier 4/6c level. * Strong written and verbal communication skills, with the ability to brief technical findings to SOC leadership, ISSOs, and senior Government officials. ## Description Valiant Solutions is seeking a Senior SIEM Engineer to join our rapidly growing and innovative cybersecurity team! The Senior SIEM Engineer serves as the technical lead for the design, deployment, tuning, and sustainment of the enterprise Security Information and Event Management (SIEM) platform that supports the client's Security Operations Center (SOC). This role owns the health and performance of the SIEM environment that ingests logs and telemetry across endpoint, network, cloud, operating system, and application layers, and feeds the 24x7x365 monitoring mission. Working alongside SOC analysts, threat hunters, engineering teams, and the client's stakeholders, the Senior SIEM Engineer translates detection requirements into production-ready content, integrates the SIEm with SOAR, EDR, CDM, and identity platforms, and builds the dashboards, correlation searches, and data models that allow Tier 1 through Tier 3 analysts to triage, investigate, and respond to threats within the client's's contractual timeframes. The position requires deep, hands-on SIEM expertise, strong cloud and federal cybersecurity context, and the judgment to balance ingest costs, data quality, detection coverage, and compliance with OMB M-26-14, NIST SP 800-53, NIST SP 800-61, and NIST SP 800-137., * Lead the architecture, deployment, upgrade, and sustainment of the SIEM environment supporting the client's SOC, including indexer and search head clusters, forwarders, and supporting infrastructure. * Monitor SIEM platform health, license usage, indexing latency, search performance, and ingest rates, and proactively address capacity, performance, and availability issues. * Onboard new data sources by defining requirements, configuring inputs and forwarders, building parsing and field extractions, and validating Common Information Model (CIM) compliance. * Develop, tune, and maintain correlation searches, notable events, dashboards, reports, and data models that support Tier 1 triage within fifteen minutes of detection and Tier 2 analysis within four hours of escalation. * Build and maintain SOC dashboards that provide real-time visibility into the client's security posture, supporting both day-to-day operations and executive reporting. * Translate detection requirements from threat hunters, CTI analysts, and engineering teams into production SIEM content mapped to the MITRE ATT&CK framework. * Integrate SIEM with SOAR, EDR, NDR, DLP, CDM, vulnerability management, and identity platforms to support automated triage, enrichment, and response. * Reduce false positive rates and alert fatigue by tuning correlation rules, refining thresholds, and applying risk-based alerting techniques. * Support incident response by building investigation queries, producing timeline reconstructions, preserving evidence, and contributing artifacts to initial incident reports within one hour of confirmation and final reports within seventy-two hours. * Author and maintain Engineering Design Documents, Standard Operating Procedures, runbooks, and configuration guides for the SIEM environment, and review them on the cadence required by the SOC CONOPS. * Partner with the Security Architect and engineering leads to align SIEM design with Zero Trust principles, the client's Technology Standards, and the agency's broader cybersecurity reference architecture. * Manage SIEM-related changes through the client's change control process, including impact assessments, back-out plans, and presentations to the Engineering Review Board and Change Control Board. * Provide knowledge transfer and informal training to SOC analysts, engineers, and system owners on SIEM usage, search development, and dashboard interpretation. * Apply secure configuration baselines, role-based access controls, and audit logging to the SIEM environment to meet federal compliance requirements. * Track and report on SIEM-related metrics, including ingest volume by source, detection coverage by MITRE technique, mean time to detect, and platform availability. * Stay current on SIEM product roadmap items, new applications and add-ons, and emerging detection techniques, and recommend improvements to the client's SIEM strategy. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)