SIEM Modernization Security Engineer

Posted 4 Days Ago
Be an Early Applicant
20814, Bethesda, MD, USA
In-Office
100K-120K Annually
Mid level
Information Technology • Security
The Role
Supports modernization from Splunk Enterprise to a cloud-native SIEM across 150+ servers. Responsibilities include SIEM platform evaluation, security baseline implementation, RMF and DoD compliance, vulnerability remediation, telemetry validation, asset onboarding, Tier 2 troubleshooting, SOP development, alert tuning, and training Tier 1 administrators.
Summary Generated by Built In

TIAG is now hiring a SIEM Modernization Security Engineer to support a modernization and transition initiative for a Uniformed Services University (USU) enclave. This position reports to our Bethesda, MD location in a Hybrid capacity.

The Security Engineer will work support the direction of the Lead SIEM Architect & provide ground-level engineering, technical enablement, and Tier 2 support to successfully transition approximately 150 on-premise and cloud-hosted servers from a legacy Splunk Enterprise environment to a modern, Government-selected cloud-native SIEM platform. The Engineer will actively enable this transition, validate telemetry, develop technical artifacts, and assist hands-on with implementation tasks where needed to ensure the project stays on track. 

Primary Responsibilities

  • Assist the Lead SIEM Architect in auditing the current USU Splunk Enterprise environment to evaluate onboarded log sources, telemetry coverage, ingestion methods, and parser configurations. 
  • Compare Splunk Cloud, Microsoft Sentinel, and Google Chronicle to identify the best SIEM solution for USU’s networks, ensuring it properly protects and handles their data.
  • Implement Security Configuration Baselines on the chosen platform to ensure compliance with DoD cybersecurity requirements, DISA STIG guidance, RMF controls, and Zero Trust principles. 
  • Ensure system vulnerabilities across the SIEM platform and associated infrastructure are proactively identified, tracked, and patched in a timely manner to maintain a secure operating environment.
  • Assist in navigating the Risk Management Framework (RMF) process, ensuring that the selected SIEM solution and integrated systems align with required RMF controls and USU security policies. 
  • Assist with the development, management, and resolution of Plan of Action and Milestones (POA&Ms) for any identified security deficiencies or configuration gaps discovered during the transition.
  • Develop, test, and package validated Reference Implementations for all supported OS categories using templates, scripts, Group Policy Objects (GPOs), and agent profiles. 
  • Work alongside GFL administrators to actively assist in the hands-on onboarding of 150+ enterprise assets into the selected cloud-native SIEM environment. 
  • Provide daily Tier 2 technical troubleshooting to resolve ingestion failures, parser inconsistencies, configuration errors, and transport connectivity issues encountered during transition. 
  • Perform structured telemetry validation by testing at least one representative server for each supported operating system flavor to “prove the pipe”. 
  • Confirm end-to-end event generation, transport, ingestion, parsing, normalization, and visibility within the selected SIEM platform. 
  • Maintain a structured Tier 2 support process, including centralized ticket tracking, root cause analysis, and issue prioritization. 
  • Author clear, practical, step-by-step Standard Operating Procedures (SOPs) tailored for Tier 1 GFL SIEM administrators covering log onboarding, telemetry validation, and health monitoring. 
  • Document standardized alert tuning processes, threshold configurations, and event categorization guidelines to improve the SOC’s signal-to-noise ratio. 
  • Support the Lead Architect in delivering targeted "delta" training on the selected SIEM platform's specific capabilities, such as query languages (KQL or UDM), telemetry management, and search optimization. 
  • Facilitate hands-on operational demonstrations, guided troubleshooting sessions, and practical exercises for GFL administrators to reinforce learning and validate operational readiness. 
     
Qualifications

Required Qualifications

  • 3–7 years of hands-on experience in cybersecurity engineering, specifically focusing on SIEM engineering, log routing, telemetry validation, and vulnerability management. Operational experience configuring and maintaining enterprise SIEM platforms such as Splunk Enterprise, Splunk Cloud, Microsoft Sentinel, or Google Chronicle. 
  • Proven ability to troubleshoot log transport connectivity, parser failures, agent misconfigurations, and data normalization issues across diverse OS environments. 
  • Hands-on experience developing and deploying configuration artifacts, including deployment scripts, GPOs, and hardened agent configurations. 
  • Working knowledge of Federal and DoD compliance frameworks, including DISA STIGs, Risk Management Framework (RMF), and Zero Trust logging requirements. Demonstrated experience assisting with POA&Ms and patching workflows. 
  • Strong technical writing skills to author operational SOPs, combined with the ability to provide over-the-shoulder mentoring and practical training to Tier 1 operational personnel.
  • IAT/IAM Level III Certification
  • Secret Clearance

TIAG is an equal opportunity employer and federal contractor or subcontractor.  Consequently, the parties agree that, as applicable, they will abide by the requirements of 41 CFR 60-1.4(a), 41 CFR 60-300.5(a), and 41 CFR 60-741.5(a)  and employment decisions shall be based solely on merit and without regard disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. TIAG takes proactive steps to employ and advance in employment qualified individuals without regard to disability or protected veteran status.  The parties also agree that, as applicable, they will abide by the requirements and may be subject and required to take action pursuant to the following laws and accompanying regulations:

The Vietnam Era Veterans Readjustment Assistance Act of 1974, as amended (and its implementing regulations at 41 C.F.R. 60-300);
Section 503 of the Rehabilitation Act of 1973, as amended (and its implementing regulations at 41 C.F.R 60-741); and 
Executive Order 13496 (and its implementing regulations at 29 C.F.R. part 471, Appendix A to Subpart A).

Skills Required

  • 3-7 years of hands-on cybersecurity engineering experience focused on SIEM engineering, log routing, telemetry validation, and vulnerability management
  • Operational experience configuring and maintaining Splunk Enterprise, Splunk Cloud, Microsoft Sentinel, or Google Chronicle
  • Ability to troubleshoot log transport connectivity, parser failures, agent misconfigurations, and data normalization issues across diverse operating systems
  • Hands-on experience developing and deploying configuration artifacts, deployment scripts, GPOs, and hardened agent configurations
  • Working knowledge of DISA STIGs, RMF, Zero Trust logging requirements, POA&Ms, and patching workflows
  • Strong technical writing skills for operational SOPs and ability to provide mentoring and practical training
  • IAT/IAM Level III Certification
  • Secret Clearance
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Reston, VA
348 Employees
Year Founded: 1999

What We Do

Delivering transformative technology solutions for the public sector and across the Department of Defense, TIAG drives modernization through synergistic processes and unique approaches. Our people are brilliant, well-credentialed business and technology experts who provide nimble, creative solutions to multidimensional problems. Our collective expertise results in refined, comprehensive services that truly make a difference. Customers choose TIAG because we drive genuine innovation and deliver value beyond the scope of work — ranging from complex enterprise-wide solutions to stand-alone custom projects. At TIAG, our greatest asset is our people. Our commitment to taking care of our employees inspires the dedication and longevity of our teams, ensuring success and continuity for client initiatives. TIAG’s strategic quality control management system and processes amplify our company-wide focus on excellence — ensuring the highest degree of management processes, solutions and work products we create and deliver for our customers. TIAG works to achieve and enhance our prestigious certifications for the ISO 9001:2015 Standard and for CMMI® (Capability Maturity Model® Integration) for Services (SVC) Level 3.

Similar Jobs

Optum Logo Optum

Healthcare Advocate - Field-Based Position

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Bethesda, MD, USA
160000 Employees
73K-130K Annually

CDW Logo CDW

Technical Writer

Information Technology
Remote or Hybrid
US
15100 Employees
64K-89K Annually

Pfizer Logo Pfizer

Senior Manager, HTA, Value and Evidence (HV&E), Genitourinary Cancer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
30 Locations
121990 Employees
139K-232K Annually

PNC Bank Logo PNC Bank

Product Owner

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
91K-203K Annually

Similar Companies Hiring

Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account