Senior SIEM Engineer

Posted Yesterday
Hiring Remotely in United States
Remote
85K-141K Annually
Senior level
Cloud • Security • Cybersecurity
The Role
Design, implement, administer, and improve SIEM platforms across AWS, Azure, and GCP environments. Build reliable log ingestion pipelines, onboard and normalize data sources, manage platform reliability and performance, integrate security tools, and automate deployments using infrastructure as code. Support FedRAMP compliance, troubleshoot complex platform issues, maintain operational documentation and runbooks, contribute to platform roadmaps, and serve as a technical resource for clients and security operations teams.
Summary Generated by Built In
About Coalfire
 
Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.
 
But that’s not who we are – that’s just what we do.
 
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

POSITION SUMMARY: 

Coalfire is on a mission to make the world a safer place by solving our clients’ toughest cybersecurity challenges.

As a leading cybersecurity solutions provider serving both private and public sector clients, we work at the cutting edge of technology—advising, assessing, automating, and guiding organizations through the ever-changing security landscape. Our professionals thrive on delivering unbiased assessments, expert guidance, and innovative strategies tailored to each client’s unique needs.

We are looking for a SIEM Platform Engineer to design, implement, operate, and continuously improve the security information and event management platforms that support Coalfire’s managed security and compliance services. This role owns the reliability and scalability of SIEM platform capabilities across cloud and high-compliance environments, including log collection, data onboarding, platform health, retention, performance, access, integrations, and operational automation.

The SIEM Platform Engineer partners closely with detection engineering, security operations, cloud engineering, compliance, and client stakeholders. The role ensures that SIEM platforms deliver high-quality, accessible, and appropriately governed security data while supporting continuous monitoring and regulatory requirements such as FedRAMP.

What You'll Do

    ESSENTIAL RESPONSIBILITIES:

  • Design, implement, and maintain SIEM platform architectures across AWS, Azure, and GCP environments.
  • Build and operate reliable log collection and ingestion pipelines, including forwarders, collectors, connectors, APIs, syslog, agents, and cloud-native services.
  • Onboard, normalize, validate, and troubleshoot data sources from cloud platforms, operating systems, applications, network devices, identity systems, endpoint tools, and security controls.
  • Establish and maintain platform standards for parsing, data models, field mappings, naming, tagging, retention, archival, access, and lifecycle management.
  • Perform SIEM platform administration, including configuration, upgrades, patching, capacity planning, performance tuning, storage optimization, licensing, and availability monitoring.
  • Develop and maintain infrastructure-as-code, automation, and deployment workflows using tools such as Terraform, Ansible, GitLab, GitHub, Python, or comparable technologies.
  • Implement platform monitoring and health checks that identify ingestion gaps, pipeline failures, data quality issues, latency, resource constraints, and service degradation.
  • Support the secure integration of SIEM platforms with endpoint, identity, vulnerability management, threat intelligence, network security, ticketing, and incident response systems.
  • Provide dependable data and platform services to detection engineering and security operations teams; collaborate on use-case enablement without owning the full detection-development lifecycle.
  • Support FedRAMP continuous monitoring and related compliance requirements by maintaining platform configurations, operational records, evidence, and repeatable procedures.
  • Participate in platform changes, releases, migrations, and modernization efforts using documented change-management and testing practices.
  • Follow and improve runbooks for platform incidents, data-source outages, ingestion failures, degraded performance, and other operational issues.
  • Troubleshoot complex platform and integration issues, communicate impact clearly, and escalate appropriately when resolution requires additional expertise or authority.
  • Create and maintain technical documentation, architecture diagrams, standard operating procedures, knowledge-base articles, and operational handoff materials.
  • Participate in client meetings as a technical resource, explaining platform capabilities, requirements, constraints, risks, and remediation plans.
  • Contribute to platform roadmaps, operational metrics, service improvements, and the development of reusable patterns across client environments.
  • WORK ENVIRONMENT/TRAVEL REQUIRED:

    Remote or standard office environment.

    Travel of approximately 10% for corporate events, training, or client needs.

What You'll Bring

    EXPERIENCE:

  • Proven experience implementing, administering, or operating SIEM and security logging platforms in enterprise, cloud, or high-compliance environments.
  • Experience delivering platform capabilities from requirements and design through implementation, validation, documentation, and operational handoff.
  • Demonstrated success integrating multiple security, cloud, endpoint, identity, network, and operational tools into a cohesive monitoring platform.
  • Experience diagnosing data quality, ingestion, pipeline, performance, availability, access, and integration problems.
  • Experience working under strict regulatory or industry frameworks while maintaining practical, reliable, and supportable platform operations.
  • Demonstrable client-facing experience in a consulting, managed-services, or professional-services capacity is preferred.
  • Hands-on systems engineering and architecture experience, including requirements definition, architecture development, systems integration, testing, and operational support.
  • Cloud experience in architecture, design, implementation, operations, and automation within AWS, Azure, or GCP.
  • Practical administration and troubleshooting experience with one or more SIEM platforms, such as Splunk, Microsoft Sentinel, Elastic, or Sumo Logic.
  • Experience designing or operating log collection, ingestion, parsing, normalization, enrichment, and retention workflows.
  • Working knowledge of cloud-native logging and security services, operating systems, networking, identity, APIs, and enterprise security tools.
  • Experience with automation and infrastructure-as-code practices using tools such as Terraform, Ansible, GitLab, GitHub, Python, or similar technologies.
  • Understanding of platform reliability concepts, including monitoring, alerting, capacity planning, performance management, availability, backup, recovery, and disaster recovery.
  • Ability to work effectively in Agile environments with cross-functional technical teams.
  • Excellent communication, organizational, documentation, and problem-solving skills, with the ability to explain complex technical information clearly.
  • Demonstrated ability to work independently and collaboratively while maintaining a professional attitude and demeanor.
  • Critical-thinking skills to balance security, compliance, reliability, cost, and mission requirements.
  • Ability to adapt quickly and operate effectively in fast-paced, dynamic environments.
  • REQUIRED CERTIFICATIONS:

  • One SIEM or security operations certification, such as Splunk Enterprise Certified Admin, Sumo Logic Administration, or Microsoft Security Operations Analyst Associate.
  • One professional-level cloud certification, such as AWS Solutions Architect Professional, AWS DevOps Engineer Professional, Azure Solutions Architect Expert, or GCP Cloud Architect.

Bonus Points

    PREFERRED CERTIFICATIONS/SKILLS (not required):

  • Splunk Enterprise Certified Architect or Splunk Certified Automation Developer.
  • Cloud security, platform engineering, cybersecurity, or automation certifications.
  • CISSP, GIAC, or comparable security certification.
  • Experience with Terraform, Ansible, Python, GitLab CI/CD, GitHub Actions, or policy-as-code.
  • EDUCATION:

    Bachelor’s degree in information technology, computer science, cybersecurity, or a related field, or equivalent combination of education and work experience.

Why You’ll Want to Join Us
 
At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.
 
Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.
 
At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at [email protected].

Skills Required

  • Experience implementing, administering, or operating SIEM and security logging platforms in enterprise, cloud, or high-compliance environments
  • Experience delivering platform capabilities from requirements and design through implementation, validation, documentation, and operational handoff
  • Experience integrating security, cloud, endpoint, identity, network, and operational tools into a cohesive monitoring platform
  • Experience diagnosing data quality, ingestion, pipeline, performance, availability, access, and integration problems
  • Experience working under strict regulatory or industry frameworks
  • Hands-on systems engineering and architecture experience, including requirements definition, architecture development, systems integration, testing, and operational support
  • Cloud architecture, design, implementation, operations, and automation experience in AWS, Azure, or GCP
  • Administration and troubleshooting experience with Splunk, Microsoft Sentinel, Elastic, Sumo Logic, or another SIEM platform
  • Experience designing or operating log collection, ingestion, parsing, normalization, enrichment, and retention workflows
  • Working knowledge of cloud-native logging and security services, operating systems, networking, identity, APIs, and enterprise security tools
  • Experience with automation and infrastructure as code using Terraform, Ansible, GitLab, GitHub, Python, or similar technologies
  • Understanding of platform reliability concepts including monitoring, alerting, capacity planning, performance management, availability, backup, recovery, and disaster recovery
  • Ability to work effectively in Agile environments with cross-functional technical teams
  • Excellent communication, organizational, documentation, and problem-solving skills
  • Ability to work independently and collaboratively in fast-paced, dynamic environments
  • One SIEM or security operations certification, such as Splunk Enterprise Certified Admin, Sumo Logic Administration, or Microsoft Security Operations Analyst Associate
  • One professional-level cloud certification, such as AWS Solutions Architect Professional, AWS DevOps Engineer Professional, Azure Solutions Architect Expert, or GCP Cloud Architect
  • Bachelor's degree in information technology, computer science, cybersecurity, or a related field, or equivalent education and work experience
  • Client-facing experience in consulting, managed services, or professional services
  • Splunk Enterprise Certified Architect or Splunk Certified Automation Developer certification
  • Cloud security, platform engineering, cybersecurity, or automation certifications
  • CISSP, GIAC, or comparable security certification
  • Experience with Terraform, Ansible, Python, GitLab CI/CD, GitHub Actions, or policy as code

Coalfire Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Coalfire and has not been reviewed or approved by Coalfire.

  • Leave & Time Off Breadth Flexible paid time off and paid parental leave are prominently offered, with remote/WFH support enabling time away when workload allows.
  • Healthcare Strength Comprehensive medical, dental, vision, wellness resources, and an EAP are part of the core package. Carrier coverage and plan options are regularly highlighted across employer materials.
  • Retirement Support A company‑matched 401(k) is included alongside other financial and development perks. This retirement benefit is consistently featured across benefits overviews.

Coalfire Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
1,062 Employees
Year Founded: 2001

What We Do

Coalfire is the cybersecurity advisor that helps private and public sector organizations avert threats, close gaps, and effectively manage risk. By providing independent and tailored advice, assessments, technical testing, and cyber engineering services, we help clients develop scalable programs that improve their security posture, achieve their business objectives, and fuel their continued success. Coalfire has been a cybersecurity thought leader for more than 20 years and has offices throughout the United States and Europe.

Similar Jobs

Kroll Logo Kroll

Senior Manager, SIEM/ SOAR Engineer (CrowdStrike)

Big Data • Security • Software • Analytics • Cybersecurity
Remote
United States
5001 Employees
150K-200K Annually
Remote
USA
57802 Employees
155K-175K Annually

Kroll Logo Kroll

Senior Manager, SIEM/ SOAR Engineer, Cyber Engineered Defense

Big Data • Security • Software • Analytics • Cybersecurity
Remote
United States
5001 Employees
150K-200K Annually

Similar Companies Hiring

Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account