1,745 siem engineer jobs at 952 companies in United States
1mo
Save
Mark Applied
Hide
1mo
SIEM Engineer
New York City, New York, United States
$140k-$160k/yrHybridFull Time
Israel Discount Bank of New York: New York-based private and commercial bank serving personal, commercial, private-banking, wealth-management, and high-tech clients.
5+ YOE5+ years cybersecurity experience with 3+ years managing SIEM; SOC and incident response experience; detection engineering, threat hunting, log ingestion, and scripting (KQL, PowerShell, Python, SQL).
State StreetNYSE: STT: Global financial services and bank holding.
5+ YOERequires 5+ years in SIEM, security data engineering, cybersecurity platform operations, or log analytics; 2+ years with Cribl Stream and Databricks; experience with Splunk, telemetry pipelines, data validation, and troubleshooting.
ASRC Federal: Providing technology, engineering, and infrastructure solutions for federal missions.
5+ YOE5+ years Elastic engineering experience, active Secret clearance, Bachelor's in information security or equivalent, DoD 8140/8570-compliant cert (e.g., Security+, CISSP), AWS experience preferred, Python/Bash scripting, Elastic Stack and SIEM expertise.
Accenture Federal ServicesNew York Stock Exchange: ACN: Technology and management consulting for U.S. federal agencies.
10+ YOEBachelor's degree in IT, computer science, cybersecurity, or related field, or equivalent experience; 10 years of cybersecurity experience; U.S. citizenship; DOD 8140 IAT 2 compliance; active TS/SCI clearance.
Koniag Data Solutions, LLC: Alaska Native-owned IT consulting firm serving defense and civilian agencies with data, AI, modernization, and cybersecurity services.
1+ YOEBachelor's degree in a relevant technology field and 1–3 years of cybersecurity, SIEM, or log management experience. Requires foundational SIEM/UEBA knowledge and ability to obtain government access authorizations.
Security Information and Event Management (SIEM), User and Entity Behavior Analytics (UEBA), Splunk, Microsoft Sentinel, IBM QRadar, Elastic SIEM, Splunk UBA, Securonix, Microsoft 365, Microsoft Azure, AWS CloudTrail, Microsoft KQL, Python, PowerShell, Bash, MITRE ATT&CK, Microsoft Office Suite, Microsoft Teams, Microsoft SharePoint, Active Directory, Azure AD, FISMA, NIST SP 800-53, NIST SP 800-207, OMB M-22-09, ITIL, syslog, Windows Event Forwarding, Beats
Danaher CorporationNYSE: DHR: A global life sciences and diagnostics innovator.
5+ YOE5+ years deploying and optimizing enterprise log pipelines and SIEMs; hands-on experience with leading SIEMs and pipeline tools; cloud (AWS/Azure/GCP) integrations; scripting and documentation skills.
CrowdStrike Next-Gen SIEM, Splunk, Microsoft Sentinel, Palo Alto XSIAM, Google SecOps (Chronicle), Humio, Elastic, Cribl, Databahn, Bindplane, Vector, Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), Python, Bash, PowerShell, Linux, UNIX
SAICNASDAQ: SAIC: Premier technology integrator for defense, space, and civilian markets.
5+ YOEBachelor's degree or equivalent experience, 5+ years of IT/cybersecurity experience, 3+ years of SIEM administration, Splunk Enterprise expertise, SQL, Elastic technologies, Linux, networking, and troubleshooting skills.
Expel: U.S. cybersecurity providing managed detection and response services to businesses through human analysts and AI.
3+ YOERequires 3+ years with SIEM, SOAR, or EDR tooling; 3+ years developing custom detections; SIEM migration experience; MITRE ATT&CK knowledge; Python or Go; Git/GitHub; and willingness to travel up to 20%.
Splunk, Microsoft Sentinel, CrowdStrike NG SIEM, SOAR, EDR, MITRE ATT&CK, Windows Event Logs, auditd, CloudTrail, Windows, macOS, Linux, TCP/IP, OSI, Python, Go, Git, GitHub, Sigma, CI/CD
CrowdStrikeNASDAQ: CRWD: AI-native platform for cybersecurity and threat protection.
6+ YOE6+ years cybersecurity experience with SIEM integrations, expertise in data ingestion, log formats, and security products; proficiency in Python or Go; strong documentation and customer-facing skills.
7+ YOERequires 7–10+ years in cybersecurity delivery, operations, or consulting; leadership deploying CrowdStrike technologies; SIEM/SOAR expertise; and Terraform, PowerShell, or Python automation proficiency.
CrowdStrike Falcon, CrowdStrike LogScale, Terraform, Ansible, Microsoft PowerShell, Python, Flight Control, Azure Lighthouse, Defender Suite, XDR, Microsoft
SMX: Private U.S. IT and advanced-engineering provider delivering cloud, C5ISR, and digital-transformation services to government and commercial clients.
2+ YOERequires active TS clearance with SCI eligibility, Splunk Enterprise Certified Architect, Security+, bachelor's degree or 5 years of Splunk experience, and 2–3 years in Elastic SIEM environments.
Splunk, Elastic Stack, Elasticsearch, Logstash, Kibana, Splunk Search Processing Language (SPL), Python, Bash, Splunk Enterprise Security (ES), IT Service Intelligence (ITSI)
HCLTechNSE: HCLTECH: Supercharging progress through technology, engineering, and digital transformation.
3+ YOE3+ years in security engineering or SIEM administration; hands-on with Splunk, Microsoft Sentinel or Google SecOps (Chronicle); experience with syslog, WEF, HEC, Regex, and scripting (Python, PowerShell, Bash).
Splunk Enterprise/Cloud, Microsoft Sentinel, Google SecOps (Chronicle), Syslog-ng, Rsyslog, Windows Event Forwarding (WEF), HTTP Event Collector (HEC), REST API, Regex, Python, PowerShell, Bash, AWS CloudTrail, Azure Activity, GCP Audit, Splunk CIM, Sentinel ASIM, Google SecOps UDM
SIEM and Data Management Engineer – Managed Security
United States
$120k-$160k/yrRemoteFull Time
AHEAD: Builds platforms and solutions for digital business.
2+ YOERequires 2–4 years in information security or related work, Cortex XSIAM/SIEM administration, security data pipelines, parser tuning, storage management, Python, and strong communication skills. Bachelor's degree or equivalent experience preferred.
Charlotte or New York City or Los Angeles or California
$150k-$210k/yrHybridFull Time
TSG Risk Management: Security and IT provider serving businesses with staffing, cybersecurity, investigations, and consulting.
4+ YOERequires 4–5 years of data, security, or SIEM engineering; production Cribl experience; cybersecurity data pipeline expertise; Python or Bash; cloud platform experience; and strong troubleshooting and communication skills.
SentinelOneNYSE: S: AI-native cybersecurity platform for autonomous threat protection.
15+ YOE15+ years building large-scale distributed backend systems, strong architecture reasoning, API and service-contract design, cloud and data systems experience, SIEM/SOAR familiarity, mentoring and cross-team influence.
SIEM Engineering & Operations Lead - Vice President
Jacksonville, Florida, United States
$100k-$157k/yrHybridFull Time
Deutsche BankXETRA: DBK: Global banking and financial services organization.
Proven leadership of SIEM engineering and operations, strong experience with Splunk or Microsoft Sentinel, regulatory/audit risk management, vendor and budget oversight, and stakeholder communication.
PingWind: Service-disabled veteran-owned IT and management consulting serving federal agencies with cybersecurity, software, supply-chain, and digital-transformation services.
8+ YOEBachelor's degree, Public Trust clearance, and 8 years of experience required. Requires SIEM, EL3 logging, federal cybersecurity compliance, remediation, vulnerability tracking, encryption, and documentation expertise.
SIEM, Security Event and Incident Management (SIEM), AES-256, SHA-256, TLS, FISMA, Ongoing Security Assessments (OSA), Plan of Action and Milestones (POA&M), CSAM, Continuous Diagnostics and Monitoring (CDM), Common Vulnerabilities and Exposures (CVE), Cybersecurity Framework (CSF), Microsoft Office
The Home DepotNYSE: HD: World's largest home improvement specialty retailer.
2+ YOERequires 2+ years of cybersecurity experience, 1+ year with SIEM or EDR, networking knowledge, detection engineering skills, communication ability, and a bachelor's degree or equivalent.
STS Systems Defense: Alaska Native engineering and technical-services contractor supporting the U.S. Department of Defense and other government agencies.
5+ YOEActive TS/SCI clearance, DoD 8570 IAT Level III CND, GMLE or degree in computer science, 5+ years SIEM experience (ArcSight/Splunk/ELK), 3+ years network traffic analysis, SOAR and scripting (Python, PowerShell) experience preferred.