Security Engineer SIEM
Job Summary
Role Overview
We are seeking an experienced Security Engineer to design implement and continuously enhance enterprise security monitoring detection response and automation capabilities. The role focuses on building scalable SIEM and SOAR platforms developing advanced detection content integrating security telemetry across IT/OT/Cloud environments and enabling automated security operations through secure DevSecOps practices.
Key Responsibilities
SIEM Engineering
- Design deploy and optimize SIEM platforms and security monitoring architectures.
- Onboard and normalize logs from enterprise cloud OT/IoT and security technologies.
- Develop use-case-driven dashboards reports and monitoring frameworks.
- Improve log ingestion quality data retention and operational efficiency.
Detection Engineering
- Develop and maintain threat detection use cases aligned with MITRE ATT&CK.
- Build detection rules correlation searches behavioral analytics and threat indicators.
- Continuously tune detections to reduce false positives and improve coverage.
- Validate and measure detection effectiveness through adversary simulations.
Response Engineering & SOAR
- Design and implement automated response workflows and playbooks.
- Integrate SIEM SOAR EDR IAM Ticketing and Threat Intelligence platforms.
- Develop automated containment enrichment investigation and remediation actions.
- Improve incident response processes through orchestration and automation.
Threat Hunting
- Lead proactive threat hunting activities across enterprise environments.
- Analyze attacker tactics techniques and procedures (TTPs).
- Develop hypotheses-based hunting methodologies.
- Identify advanced threats insider risks and suspicious behaviors.
Security Telemetry Integration
- Integrate logs and telemetry from cloud endpoint network identity OT/IoT and SaaS platforms.
- Establish security data pipelines and event normalization standards.
- Ensure complete visibility across hybrid environments.
Secure CI/CD & DevSecOps
- Integrate security controls within CI/CD pipelines.
- Implement automated security testing and policy enforcement.
- Enable Infrastructure-as-Code (IaC) security validation.
- Support secure software delivery practices and DevSecOps initiatives.
Required Skills
- Hands-on experience with SIEM platforms (Microsoft Sentinel Splunk QRadar Elastic LogRhythm etc.)
- SOAR implementation and automation expertise.
- Threat detection engineering and MITRE ATT&CK mapping.
- Threat hunting methodologies and incident response.
- Security telemetry onboarding and data engineering concepts.
- Scripting experience (Python PowerShell Bash).
- Cloud security monitoring (Azure AWS GCP).
- DevSecOps and CI/CD security integration.
Preferred Certifications
- GIAC GCDA GCIH GCFA
- Microsoft SC-200
- Splunk Core Consultant/Architect
- CISSP
- Azure Security Engineer Associate
Required Skills:
SIEM