Security Engineer Iii, Siem Engineer (secret Clearance)

This role focuses on security engineering for SIEM systems, including configuring and optimizing SIEM content, analyzing security events, and integrating log sources. It involves strengthening cyber defense capabilities for clients.

What you'd actually do

  1. Configure, maintain, and optimize SIEM content including correlation rules, alerts, dashboards, and reports
  2. Analyze security events and log data to identify suspicious activity, support investigations, and improve detection coverage
  3. Integrate and normalize log sources from endpoint, network, cloud, identity, and security platforms
  4. Partners with cybersecurity teams to support use case development, threat detection, incident triage, and response activities
  5. Document detection logic, operational procedures, and monitoring requirements to support consistent service delivery

Skills

Required

  • Splunk
  • Palo Alto XSIAM
  • Crowdstrike NG SIEM
  • SIEM content creation
  • Log analysis
  • Correlation rules
  • Alerting
  • Dashboarding
  • Reporting
  • Endpoint security
  • Network security
  • Cloud security
  • Identity management
  • Security platforms
  • Threat detection
  • Incident triage
  • Response activities
  • MITRE ATT&CK techniques
  • Cloud security monitoring (AWS, Azure, GCP)
  • Scripting or query languages for detection and log analysis

Nice to have

  • Enterprise monitoring in a Security Operations Center
  • Onboarding and normalizing log sources in a SIEM platform
  • CompTIA Security+
  • GIAC certification

What the JD emphasized

  • Active Secret Clearance
  • 3+ years of experience in cybersecurity, security operations, or SIEM engineering
  • 3+ years of experience with at least one of the following: Splunk, Palo Alto XSIAM, or Crowdstrike NG SIEM
  • 2+ years’ experience in the following areas:
  • Creating, tuning, and maintaining correlation searches, alerts, dashboards, and reports in a Security Information and Event Management platform
  • Reviewing and analyzing logs from endpoint, network, cloud, identity, and application sources
  • Security certification such as Splunk certification, Palo Alto Networks certification, or CrowdStrike certification is required