1,763 siem engineer jobs at 959 companies in United States

1mo
Save
Mark Applied
Hide
SIEM Engineer
New York City, New York, United States
$140k-$160k/yr HybridFull Time
Israel Discount Bank of New York
Israel Discount Bank of New York: New York-based private and commercial bank serving personal, commercial, private-banking, wealth-management, and high-tech clients.
5+ YOE5+ years cybersecurity experience with 3+ years managing SIEM; SOC and incident response experience; detection engineering, threat hunting, log ingestion, and scripting (KQL, PowerShell, Python, SQL).
Microsoft Sentinel, Splunk, QRadar, LogRhythm, Elastic Security, CrowdStrike NG-SIEM, Cribl, KQL, PowerShell, Python, SQL
2w
Save
Mark Applied
Hide
SIEM Data Engineer
Quincy, Massachusetts, United States
$90k-$158k/yr HybridFull Time
State Street
State StreetNYSE: STT: Global financial services and bank holding.
5+ YOERequires 5+ years in SIEM, security data engineering, cybersecurity platform operations, or log analytics; 2+ years with Cribl Stream and Databricks; experience with Splunk, telemetry pipelines, data validation, and troubleshooting.
Splunk, Databricks, Cribl Stream, Fluent Bit, Fluentd, Vector, Kafka, Syslog, HEC, REST APIs, JSON, XML, CSV, Windows Event Logs, SPL, SQL, Spark SQL, Python, Shell, PowerShell
1mo
Save
Mark Applied
Hide
Elastic SIEM Engineer
Hanover, Maryland, United States
$150k-$165k/yr HybridFull Time
ASRC Federal
ASRC Federal: Providing technology, engineering, and infrastructure solutions for federal missions.
5+ YOE5+ years Elastic engineering experience, active Secret clearance, Bachelor's in information security or equivalent, DoD 8140/8570-compliant cert (e.g., Security+, CISSP), AWS experience preferred, Python/Bash scripting, Elastic Stack and SIEM expertise.
Elasticsearch, Logstash, Kibana, Elastic Security, AWS, Azure, GCP, Python, Bash
1w
Save
Mark Applied
Hide
SIEM Engineer
Fort Belvoir, Virginia, United States
$171k-$205k/yr OnsiteFull Time
Accenture Federal Services
Accenture Federal ServicesNew York Stock Exchange: ACN: Technology and management consulting for U.S. federal agencies.
10+ YOEBachelor's degree in IT, computer science, cybersecurity, or related field, or equivalent experience; 10 years of cybersecurity experience; U.S. citizenship; DOD 8140 IAT 2 compliance; active TS/SCI clearance.
Security Information and Event Management (SIEM)
1d
Save
Mark Applied
Hide
Jr SIEM/UEBA Engineer
Washington, District of Columbia, United States
$95k-$125k/yr HybridFull Time
Koniag Data Solutions, LLC
Koniag Data Solutions, LLC: Alaska Native-owned IT consulting firm serving defense and civilian agencies with data, AI, modernization, and cybersecurity services.
1+ YOEBachelor's degree in a relevant technology field and 1–3 years of cybersecurity, SIEM, or log management experience. Requires foundational SIEM/UEBA knowledge and ability to obtain government access authorizations.
Security Information and Event Management (SIEM), User and Entity Behavior Analytics (UEBA), Splunk, Microsoft Sentinel, IBM QRadar, Elastic SIEM, Splunk UBA, Securonix, Microsoft 365, Microsoft Azure, AWS CloudTrail, Microsoft KQL, Python, PowerShell, Bash, MITRE ATT&CK, Microsoft Office Suite, Microsoft Teams, Microsoft SharePoint, Active Directory, Azure AD, FISMA, NIST SP 800-53, NIST SP 800-207, OMB M-22-09, ITIL, syslog, Windows Event Forwarding, Beats
1mo
Save
Mark Applied
Hide
Senior SIEM Engineer - USA Remote
United States
$155k-$175k/yr RemoteFull Time
Danaher Corporation
Danaher CorporationNYSE: DHR: A global life sciences and diagnostics innovator.
5+ YOE5+ years deploying and optimizing enterprise log pipelines and SIEMs; hands-on experience with leading SIEMs and pipeline tools; cloud (AWS/Azure/GCP) integrations; scripting and documentation skills.
CrowdStrike Next-Gen SIEM, Splunk, Microsoft Sentinel, Palo Alto XSIAM, Google SecOps (Chronicle), Humio, Elastic, Cribl, Databahn, Bindplane, Vector, Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), Python, Bash, PowerShell, Linux, UNIX
1w
Save
Mark Applied
Hide
SIEM Administrator/Engineer
Washington, District of Columbia, United States
HybridFull Time
SAIC
SAICNASDAQ: SAIC: Premier technology integrator for defense, space, and civilian markets.
5+ YOEBachelor's degree or equivalent experience, 5+ years of IT/cybersecurity experience, 3+ years of SIEM administration, Splunk Enterprise expertise, SQL, Elastic technologies, Linux, networking, and troubleshooting skills.
Splunk Enterprise, Splunk ES, SPL, Elastic, Elasticsearch, Kibana, SQL, Linux, Windows, TCP/IP, DNS, HTTP/HTTPS, TLS, syslog, EDR, IDS/IPS, Elastic Stack, Elastic Security, Elastic Agent/Fleet, Beats, Logstash, KQL, ES|QL, EQL, Query DSL, Splunk CIM, Elastic Common Schema (ECS), MITRE ATT&CK, Python, PowerShell, Bash, REST APIs, SOC
2w
Save
Mark Applied
Hide
Managed SIEM Detection Engineer
United States
$112k-$162k/yr RemoteFull Time
Expel
Expel: U.S. cybersecurity providing managed detection and response services to businesses through human analysts and AI.
3+ YOERequires 3+ years with SIEM, SOAR, or EDR tooling; 3+ years developing custom detections; SIEM migration experience; MITRE ATT&CK knowledge; Python or Go; Git/GitHub; and willingness to travel up to 20%.
Splunk, Microsoft Sentinel, CrowdStrike NG SIEM, SOAR, EDR, MITRE ATT&CK, Windows Event Logs, auditd, CloudTrail, Windows, macOS, Linux, TCP/IP, OSI, Python, Go, Git, GitHub, Sigma, CI/CD
1mo
Save
Mark Applied
Hide
Engineer III – SIEM Integrations (Hybrid)
New York City, New York, United States
$120k-$180k/yr HybridFull Time
CrowdStrike
CrowdStrikeNASDAQ: CRWD: AI-native platform for cybersecurity and threat protection.
6+ YOE6+ years cybersecurity experience with SIEM integrations, expertise in data ingestion, log formats, and security products; proficiency in Python or Go; strong documentation and customer-facing skills.
Splunk, Sentinel, Exabeam, QRadar, Syslog, CEF, LEEF, JSON, XML, Cribl, Splunk Forwarder, Azure monitoring agent, LogScale, AWS CloudWatch, Azure Monitor, GCP Logging, Python, Go
2w
Save
Mark Applied
Hide
Senior Manager, SIEM/ SOAR Engineer (CrowdStrike)
United States
$150k-$200k/yr RemoteFull Time
Kroll
Kroll: Global risk and financial advisory firm.
7+ YOERequires 7–10+ years in cybersecurity delivery, operations, or consulting; leadership deploying CrowdStrike technologies; SIEM/SOAR expertise; and Terraform, PowerShell, or Python automation proficiency.
CrowdStrike Falcon, CrowdStrike LogScale, Terraform, Ansible, Microsoft PowerShell, Python, Flight Control, Azure Lighthouse, Defender Suite, XDR, Microsoft
5d
Save
Mark Applied
Hide
Splunk/SIEM Engineer (5522) (TS/SCI) (Ft. Meade, MD)
Fort Meade, Maryland, United States
$160k-$190k/yr OnsiteFull Time
SMX
SMX: Private U.S. IT and advanced-engineering provider delivering cloud, C5ISR, and digital-transformation services to government and commercial clients.
2+ YOERequires active TS clearance with SCI eligibility, Splunk Enterprise Certified Architect, Security+, bachelor's degree or 5 years of Splunk experience, and 2–3 years in Elastic SIEM environments.
Splunk, Elastic Stack, Elasticsearch, Logstash, Kibana, Splunk Search Processing Language (SPL), Python, Bash, Splunk Enterprise Security (ES), IT Service Intelligence (ITSI)
2mo
Save
Mark Applied
Hide
SME - Security Investigations, SIEM (119295)
United States
OnsiteFull Time
HCLTech
HCLTechNSE: HCLTECH: Supercharging progress through technology, engineering, and digital transformation.
3+ YOE3+ years in security engineering or SIEM administration; hands-on with Splunk, Microsoft Sentinel or Google SecOps (Chronicle); experience with syslog, WEF, HEC, Regex, and scripting (Python, PowerShell, Bash).
Splunk Enterprise/Cloud, Microsoft Sentinel, Google SecOps (Chronicle), Syslog-ng, Rsyslog, Windows Event Forwarding (WEF), HTTP Event Collector (HEC), REST API, Regex, Python, PowerShell, Bash, AWS CloudTrail, Azure Activity, GCP Audit, Splunk CIM, Sentinel ASIM, Google SecOps UDM
1w
Save
Mark Applied
Hide
SIEM and Data Management Engineer – Managed Security
United States
$120k-$160k/yr RemoteFull Time
AHEAD
AHEAD: Builds platforms and solutions for digital business.
2+ YOERequires 2–4 years in information security or related work, Cortex XSIAM/SIEM administration, security data pipelines, parser tuning, storage management, Python, and strong communication skills. Bachelor's degree or equivalent experience preferred.
Palo Alto Cortex XSIAM, Elastic Security, SIEM, Security Operations Center (SOC), API, syslog, Python, SOAR, IAM, IDS, EDR, regular expressions
4d
Save
Mark Applied
Hide
Cribl Data Engineer, Cybersecurity and SIEM
Charlotte or New York City or Los Angeles or California
$150k-$210k/yr HybridFull Time
TSG Risk Management
TSG Risk Management: Security and IT provider serving businesses with staffing, cybersecurity, investigations, and consulting.
4+ YOERequires 4–5 years of data, security, or SIEM engineering; production Cribl experience; cybersecurity data pipeline expertise; Python or Bash; cloud platform experience; and strong troubleshooting and communication skills.
Cribl, Databricks, Snowflake, Python, Bash, AWS, Azure, Google Cloud, Cribl Stream, Cribl Edge, OCSF, NIST, MITRE ATT&CK, CIM Object Model, Windows, macOS, Linux, Unix, SIEM, SOAR
1mo
Save
Mark Applied
Hide
Principal Software Engineer, AI SIEM
United States
$216k-$297k/yr RemoteFull Time
SentinelOne
SentinelOneNYSE: S: AI-native cybersecurity platform for autonomous threat protection.
15+ YOE15+ years building large-scale distributed backend systems, strong architecture reasoning, API and service-contract design, cloud and data systems experience, SIEM/SOAR familiarity, mentoring and cross-team influence.
4w
Save
Mark Applied
Hide
SIEM Engineering & Operations Lead - Vice President
Jacksonville, Florida, United States
$100k-$157k/yr HybridFull Time
Deutsche Bank
Deutsche BankXETRA: DBK: Global banking and financial services organization.
Proven leadership of SIEM engineering and operations, strong experience with Splunk or Microsoft Sentinel, regulatory/audit risk management, vendor and budget oversight, and stakeholder communication.
Splunk, Microsoft Sentinel
1w
Save
Mark Applied
Hide
Security Engineer (SIEM / EL3 Logging)
United States or Virginia or Huntsville
$93k-$128k/yr RemoteFull Time
PingWind
PingWind: Service-disabled veteran-owned IT and management consulting serving federal agencies with cybersecurity, software, supply-chain, and digital-transformation services.
8+ YOEBachelor's degree, Public Trust clearance, and 8 years of experience required. Requires SIEM, EL3 logging, federal cybersecurity compliance, remediation, vulnerability tracking, encryption, and documentation expertise.
SIEM, Security Event and Incident Management (SIEM), AES-256, SHA-256, TLS, FISMA, Ongoing Security Assessments (OSA), Plan of Action and Milestones (POA&M), CSAM, Continuous Diagnostics and Monitoring (CDM), Common Vulnerabilities and Exposures (CVE), Cybersecurity Framework (CSF), Microsoft Office
2w
Save
Mark Applied
Hide
Cybersecurity Engineer II | SIEM and EDR (Remote)
Atlanta, Georgia, United States
$90k-$130k/yr RemoteFull Time
The Home Depot
The Home DepotNYSE: HD: World's largest home improvement specialty retailer.
2+ YOERequires 2+ years of cybersecurity experience, 1+ year with SIEM or EDR, networking knowledge, detection engineering skills, communication ability, and a bachelor's degree or equivalent.
Cortex XSIAM, Splunk, CrowdStrike, Azure, GCP, Linux, Unix, RegEx, SIEM, EDR
3mo
Save
Mark Applied
Hide
Security Solution Engineer — SIEM/SOAR
Kansas City or Sarasota or Scottsdale or Overland Park
HybridFull Time
TENEX.AI
TENEX.AI: AI is a private AI-native managed detection and response provider protecting organizations with human-led security operations.
3+ YOE3+ years in detection engineering or security operations; SIEM/SOAR expertise; Python, log parsers, dashboards; knowledge of MITRE ATT&CK.
YARA-L, KQL, SOAR, Python, REST API, Google SecOps, Microsoft Sentinel, APIs, Log parsers
2mo
Save
Mark Applied
Hide
Content Developer (SIEM Cyber Security)
San Antonio or Lackland Air Force Base
OnsiteFull Time
STS Systems Defense
STS Systems Defense: Alaska Native government-services contractor providing cybersecurity, information management, mission operations, and technical services to federal agencies.
5+ YOEActive TS/SCI clearance, DoD 8570 IAT Level III CND, GMLE or degree in computer science, 5+ years SIEM experience (ArcSight/Splunk/ELK), 3+ years network traffic analysis, SOAR and scripting (Python, PowerShell) experience preferred.
SIEM, ArcSight, Splunk, ELK, Phantom, Demisto, SOAR, Python, PowerShell, IDS/IPS, MITRE ATT&CK