SIEM Engineer III

Posted 7 Days Ago
Be an Early Applicant
Homeland, VA, USA
In-Office
120K-170K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Security • Software
The Role
Engineer, deploy, maintain, and optimize enterprise SIEM platforms across cloud, on-premises, and hybrid environments. Integrate security telemetry, manage data pipelines, monitor platform health, perform upgrades, troubleshoot complex issues, and support SOC operations. Provide technical guidance to junior engineers, coordinate with clients and vendors, create technical documentation, and improve SIEM reliability, scalability, automation, and operational effectiveness. Participate in on-call support for security incidents and operational issues.
Summary Generated by Built In
Job Summary & Responsibilities

Everforth ECS is seeking a SIEM Engineer III to join our team remotely.


At ECS Federal, we're driven by a commitment to excellence and innovation in solving complex challenges. As a premier provider of advanced technology solutions and services, our mission is to secure and optimize the most critical commercial, government, defense, and intelligence projects across the country. Our team is composed of dynamic professionals who thrive in a collaborative and empowering environment, where our team members leverage the latest technologies and insights to make a real-world impact. Join us and be part of a forward-thinking organization that values your expertise and supports your professional growth.


The SIEM Engineer III is responsible for engineering, implementing, maintaining, and optimizing enterprise Security Information and Event Management (SIEM) platforms and the supporting infrastructure that enables effective security monitoring and incident response operations. This role works closely with Security Engineering teams, SOC analysts, enterprise IT teams, platform owners, vendors, and client organizations to ensure the reliability, scalability, security, and operational effectiveness of SIEM capabilities. The SIEM Engineer III serves as a senior technical resource for complex SIEM initiatives, including platform deployments, upgrades, data source integrations, infrastructure migrations, performance optimization, automation, and troubleshooting. This role will also provide technical guidance to junior engineers and contribute to the continuous improvement of SIEM engineering processes, documentation, and operational standards.


Responsibilities

  • SIEM Platform Engineering: Engineer, deploy, configure, maintain, and optimize enterprise SIEM platforms such as Elastic Security, CrowdStrike Falcon Next-Gen SIEM, Splunk Enterprise Security, Microsoft Sentinel, or similar technologies across cloud, on-premises, and hybrid environments.
  • SIEM Infrastructure Management: Support the underlying infrastructure and components required for SIEM operations, including collectors, aggregators, data nodes, forwarders, agents, connectors, APIs, and other supporting services.
  • Log Source & Data Integration: Design, configure, and maintain integrations for security telemetry from endpoints, network devices, firewalls, identity platforms, cloud environments, applications, operating systems, and other enterprise technologies.
  • Data Pipeline Engineering: Configure and troubleshoot data collection, forwarding, parsing, normalization, enrichment, filtering, and routing to ensure security telemetry is reliably delivered and usable within supported SIEM platforms.
  • Platform Maintenance & Upgrades: Perform SIEM platform upgrades, patches, configuration changes, migrations, and lifecycle management activities while minimizing operational disruption and maintaining security visibility.
  • Performance & Health Monitoring: Conduct routine health checks and proactively monitor SIEM infrastructure, ingestion pipelines, storage, system performance, capacity, and availability. Identify and remediate issues before they impact security operations.
  • Complex Troubleshooting: Serve as a senior escalation point for complex SIEM infrastructure, integration, ingestion, and platform issues. Lead root-cause analysis and coordinate resolution with internal teams and technology vendors when necessary.
  • Configuration Management: Maintain and optimize SIEM configurations to support changing environments, new data sources, platform requirements, and operational needs while following established change-management processes.
  • Security Operations Support: Partner with SOC analysts and other cybersecurity teams to ensure required telemetry and SIEM capabilities are available to support monitoring, investigation, threat hunting, incident response, and other security operations.
  • Client & Stakeholder Support: Work directly with internal stakeholders and client organizations to understand technical requirements, coordinate SIEM engineering activities, communicate risks or dependencies, and support successful implementation of security monitoring capabilities.
  • Technical Leadership & Mentoring: Provide technical guidance and mentorship to junior SIEM engineers, support knowledge transfer, and assist with troubleshooting and complex engineering activities without serving as the team's formal people manager.
  • Documentation: Develop and maintain detailed technical documentation, including architecture diagrams, integration procedures, configuration standards, troubleshooting guides, operational runbooks, and standard operating procedures.
  • Vendor Management: Engage SIEM and security technology vendors to troubleshoot complex issues, evaluate platform capabilities, coordinate support cases, and assist with implementation or upgrade activities.
  • Continuous Improvement: Identify opportunities to improve SIEM reliability, scalability, automation, operational efficiency, and engineering processes across supported environments.

Education Requirements

  • Bachelor’s degree in computer science, information security, or a related field. Will consider experience in lieu of a degree.

Salary Range: $120,000 - $170,000

General Description of Benefits 

Preferred Qualifications
  • At least five years of relevant cybersecurity, SIEM, security engineering, or systems engineering experience, with demonstrated experience supporting enterprise security monitoring technologies.
  • Strong knowledge of SIEM concepts and hands-on experience with one or more enterprise SIEM platforms such as Elastic Security, CrowdStrike Falcon Next-Gen SIEM, Splunk Enterprise Security, Microsoft Sentinel, or comparable technologies.
  • Demonstrated experience deploying, configuring, maintaining, upgrading, and troubleshooting enterprise SIEM platforms and supporting infrastructure.
  • Experience integrating enterprise data sources and security technologies into SIEM platforms, including troubleshooting ingestion, connectivity, parsing, normalization, and data quality issues.
  • Strong understanding of Windows and Linux operating systems and the infrastructure, networking, and security concepts required to support enterprise SIEM environments.
  • Working knowledge of cloud environments and cloud-based security telemetry, including platforms such as AWS, Microsoft Azure, and/or Google Cloud.
  • Proficiency with scripting or automation technologies such as Python, PowerShell, Bash, REST APIs, or similar technologies.
  • SIEM Query Languages: Proficiency with SIEM search, query, and analytics languages such as KQL, SPL, CQL, EQL, ES|QL, or similar technologies used to search, analyze, and troubleshoot security telemetry.
  • Strong troubleshooting and problem-solving skills with the ability to independently investigate and resolve complex technical issues.
  • Comprehensive understanding of cybersecurity concepts, security monitoring, common attack methodologies, and the role of SIEM technologies within security operations.
  • Ability to lead complex technical efforts and provide guidance and mentorship to junior engineers.
  • Strong verbal and written communication skills, including the ability to create technical documentation and communicate complex technical concepts to both technical and non-technical stakeholders.
  • Ability to think strategically about SIEM technologies and identify opportunities to improve platform reliability, scalability, automation, and overall security capabilities using traditional methods and/or AI driven technologies.

Other Requirements of the position include:

  • Able and willing to obtain a US Security Clearance.
  • On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capabilities.

Skills Required

  • Bachelor's degree in computer science, information security, or a related field; equivalent experience may substitute
  • At least five years of relevant cybersecurity, SIEM, security engineering, or systems engineering experience
  • Hands-on experience with enterprise SIEM platforms such as Elastic Security, CrowdStrike Falcon Next-Gen SIEM, Splunk Enterprise Security, Microsoft Sentinel, or comparable technologies
  • Experience deploying, configuring, maintaining, upgrading, and troubleshooting enterprise SIEM platforms and supporting infrastructure
  • Experience integrating enterprise data sources and security technologies into SIEM platforms, including ingestion, connectivity, parsing, normalization, and data quality troubleshooting
  • Strong knowledge of Windows and Linux operating systems, infrastructure, networking, and security concepts
  • Working knowledge of AWS, Microsoft Azure, and/or Google Cloud environments and cloud security telemetry
  • Proficiency with Python, PowerShell, Bash, REST APIs, or similar scripting and automation technologies
  • Proficiency with SIEM query and analytics languages such as KQL, SPL, CQL, EQL, ES|QL, or similar technologies
  • Strong troubleshooting and problem-solving skills for independently resolving complex technical issues
  • Comprehensive understanding of cybersecurity, security monitoring, common attack methodologies, and SIEM use in security operations
  • Ability to lead complex technical efforts and mentor junior engineers
  • Strong verbal and written communication skills, including technical documentation and stakeholder communication
  • Ability to identify improvements in SIEM reliability, scalability, automation, and security capabilities
  • Ability and willingness to obtain a United States security clearance
  • Participation in on-call support for security incidents, operational issues, and investigations

ECS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ECS and has not been reviewed or approved by ECS.

  • Healthcare Strength ECS advertises multiple national-network medical plan options with HSA eligibility alongside dental and vision coverage. Coverage generally begins quickly and is paired with company-paid short- and long-term disability, adding stability to the health package.
  • Retirement Support A 401(k) with Safe Harbor and immediate vesting on employer contributions is emphasized, with an employer match available. Access to an employee stock purchase plan via the parent company provides an additional savings avenue.
  • Parental & Family Support Paid parental leave up to 30 days, adoption assistance, and other family-oriented leaves are highlighted. Feedback suggests these offerings add meaningful value beyond base pay for many roles.

ECS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Elkhorn, NE
2,129 Employees
Year Founded: 1993

What We Do

ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries. ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies. Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.

Similar Jobs

PNC Bank Logo PNC Bank

Technology Solution Center Analyst Lead

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
41K-83K Annually

PNC Bank Logo PNC Bank

Software Engineer

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees

TransUnion Logo TransUnion

Fp&a Analyst

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
4 Locations
13000 Employees
72K-105K Annually

Enverus Logo Enverus

Sales Compensation Specialist - 26356

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
4 Locations
1800 Employees
90K-105K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account