SIEM Engineer
6 мес. назад
USASeniorOnsite
siemidsnacedrfirewallssecurity appliancescloud environments
Responsible for design, deployment, configuration, and maintenance of SIEM systems to support cyber security operations and compliance.
О компании
- Be Challenged and Make a Difference In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At , we provide unmatched value to our customers and employees through innovative solutions and an engaging culture. Description of Task to be Performed: is seeking an experienced SIEM (Security Information and Event Management) Engineer to provide support to a mission critical customer. The selected candidate will be responsible for the design, deployment, configuration, and maintenance of SIEM systems across multiple classification enclaves. Key Responsibilities · Support the architecture, engineering, optimization, and sustainment of Security Information and Event Management (SIEM) platfor
Требования
- 6+ years of cybersecurity experience, with at least 5 years focused on SIEM engineering in enterprise environments.
- Experience supporting federal government systems at multiple security levels, strong knowledge of federal cybersecurity frameworks, and the ability to provide technical support within a secure environment.
- Hands-on experience with one or more enterprise SIEM platforms.
- Experience engineering and sustaining SIEM solutions in classified or air-gapped environments.
- Familiarity with cross-domain solutions and secure data transfer controls.
- Strong expertise in:
- Log normalization and parsing
- Advanced correlation rule development
- Threat detection engineering
- Network protocols and traffic analysis
- Windows and Linux security logging
- Active TS clearance with the ability to obtain SCI accesses.
Будет плюсом
- Bachelor’s degree in Information Technology, Computer Science, Information Systems or related field
- Proficiency in scripting/automation (Python, PowerShell, Bash).
- Deep understanding of MITRE ATT&CK and threat detection methodologies.
- Demonstrated ability to work independently and lead technical initiatives in highly regulated environments.
- Knowledge of Zero Trust architecture principles.
- Relevant certifications such as GIAC (GCIA, GCIH, GCED) or CISSP a plus, but not required.