Sr. SIEM Engineering Consultant

Reposted 16 Days Ago
Be an Early Applicant
Homeland, VA, USA
In-Office
140K-180K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Security • Software
The Role
The Sr. SIEM Engineering Consultant will design, deploy, and maintain Microsoft Sentinel environments, automate operations, and optimize SIEM capabilities while collaborating with multiple teams.
Summary Generated by Built In
Job Summary & Responsibilities

Everforth ECS is seeking a Sr. SIEM Engineering Consultant to join our team remotely.  This position is contingent upon contract award.

 

Are you passionate about building and scaling cloud-native SIEM solutions and eager to make an immediate technical impact? Join ECS, a leading provider of cloud, AI, data, and enterprise transformation solutions. In this role, you will implement, optimize, and maintain Microsoft Sentinel environments at scale while contributing to architecture, automation, and integrations that improve security visibility, detection, and operational efficiency.

We are seeking a Sr. SIEM Engineering Consultant to join our Managed Security Services (MSSP) team. The ideal candidate has hands-on experience with Microsoft Sentinel and enjoys designing, coding, and deploying complex security monitoring and detection solutions. You will collaborate with engineering, DevOps, cloud, and client teams to deliver resilient, high-performance SIEM capabilities while maintaining visibility into threats, system health, and operational workflows.

 

Key Responsibilities:

  • Design, deploy, and maintain Microsoft Sentinel environments, including Log Analytics Workspaces and data connectors.
  • Build and optimize data ingestion pipelines, detection rules (analytics), queries (KQL), dashboards (Workbooks), and automation workflows.
  • Write scripts, automation, and integrations (Python, PowerShell, Bash, etc.) to streamline security operations, data processing, and monitoring.
  • Deploy and manage Sentinel across cloud environments, primarily Azure, with integrations into AWS, GCP, and hybrid/on-premises environments.
  • Leverage automation and orchestration tools such as Terraform, Ansible, CI/CD pipelines, and infrastructure-as-code to manage deployments and operational tasks.
  • Integrate Sentinel with enterprise tools such as Microsoft Defender, identity providers, firewalls, EDR platforms, and other telemetry sources.
  • Monitor system health, troubleshoot ingestion and performance issues, and optimize for cost, reliability, and scalability.
  • Develop and tune detection use cases aligned to threat frameworks (e.g., MITRE ATT&CK).
  • Configure incident management, alert grouping, and response workflows within Sentinel.
  • Implement automation and response using playbooks (Logic Apps) for alert enrichment and remediation.
  • Lead design reviews, provide guidance on SIEM best practices, and support knowledge sharing across teams.
  • Maintain documentation for architectures, detection logic, deployment patterns, runbooks, and operational best practices.
  • Stay current with Microsoft security technologies, Sentinel features, and emerging SIEM capabilities.

Salary Range: $140,000 - $180,000

Preferred Qualifications
  • Deep, hands-on expertise with Microsoft Sentinel and Azure Monitor (Log Analytics, KQL, data connectors).
  • Strong experience with SIEM engineering, including log ingestion, normalization, detection engineering, and incident response workflows.
  • Proficiency in Kusto Query Language (KQL) for detection development and data analysis.
  • Strong scripting and automation skills (Python, PowerShell, Bash, etc.).
  • Solid understanding of security operations, threat detection, and observability in distributed systems.
  • Experience designing, deploying, and optimizing production-scale SIEM environments.
  • Strong knowledge of Azure, cloud security architecture, networking, and identity systems.
  • Ability to mentor, guide, and influence engineering teams on SIEM and security best practices.
  • Outstanding verbal and written communication skills.
  • Willingness and ability to support domestic or international on-site engagements.
  • U.S. Passport required.
  • Must be eligible to obtain a U.S. Security Clearance.

Skills Required

  • Deep hands-on expertise with Microsoft Sentinel and Azure Monitor
  • Strong experience with SIEM engineering, including log ingestion, normalization, detection engineering, and incident response workflows
  • Proficiency in Kusto Query Language (KQL) for detection development and data analysis
  • Strong scripting and automation skills (Python, PowerShell, Bash, etc.)
  • Experience designing, deploying, and optimizing production-scale SIEM environments

ECS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ECS and has not been reviewed or approved by ECS.

  • Healthcare Strength ECS advertises multiple national-network medical plan options with HSA eligibility alongside dental and vision coverage. Coverage generally begins quickly and is paired with company-paid short- and long-term disability, adding stability to the health package.
  • Retirement Support A 401(k) with Safe Harbor and immediate vesting on employer contributions is emphasized, with an employer match available. Access to an employee stock purchase plan via the parent company provides an additional savings avenue.
  • Parental & Family Support Paid parental leave up to 30 days, adoption assistance, and other family-oriented leaves are highlighted. Feedback suggests these offerings add meaningful value beyond base pay for many roles.

ECS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fairfax, VA
2,129 Employees
Year Founded: 1993

What We Do

ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries. ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies. Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.

Similar Jobs

Hybrid
10 Locations
1100 Employees
264K-423K Annually

General Motors Logo General Motors

Talent Planning Lead

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees
88K-141K Annually

General Motors Logo General Motors

Field Service Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees
70K-107K Annually

DFIN Logo DFIN

Zendesk Solutions Analyst

Fintech • Software
Remote or Hybrid
United States
1750 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account