deepwatch

Platform SIEM Engineer II

deepwatch$130K — $150K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2+ years of experience in SIEM administration or related field
  • Hands-on experience with major SIEM platforms like Splunk and Microsoft Sentinel
  • Understanding of log data pipelines and troubleshooting techniques
  • Proficient with Linux and Windows systems
  • Experience with cloud platforms such as AWS, Azure or GCP
  • Ability to manage competing priorities and troubleshoot issues independently
  • Clear communication skills for both technical and non-technical audiences

Responsibilities

  • Provide first line support for production impacting issues
  • Monitor and optimize performance of SIEM platforms
  • Maintain and troubleshoot log collection solutions
  • Identify and fill critical log ingest gaps
  • Communicate effectively with leadership and support roles
  • Manage ticket requests and incident statuses
  • Document network architectures and keep up with security trends

Benefits

  • Medical, dental, vision, and disability insurance
  • Flexible Time Off (FTO) and sick leave
  • 12 company holidays and 8-Weeks Paid Parental Leave
  • Annual professional development dollars for employee growth
  • Wellness contests and educational programs
  • 401(K) retirement program
Full Job Description
Platform SIEM Engineer II

Reports to Manager, Platform Advisory Services

Hybrid Tampa, FL OR Remote

While proximity to Tampa is preferred to support a hybrid schedule in our Tampa Center of Excellence, we're open to remote candidates who can support the Eastern Time Zone.

The Platform SIEM Engineer II's primary goal is to provide expert production support for the Deepwatch managed security service offerings. Platform SIEM Engineers are responsible for the configuration, operation, and optimization of all SIEM systems and resources within Deepwatch. This position is ideal for candidates with experience in SIEM administration, systems engineering, or security operations who are ready to operate more independently in a fast-paced environment. The role provides hands-on experience supporting modern, cloud-native SIEM platforms at scale, working alongside senior Platform SIEM and Detection Engineers to onboard data sources, maintain platform health, troubleshoot data pipeline issues, and ensure our customers' operational and security data is flowing, searchable, and reliable.

Candidates must display aptitude and ability to manage a multitude of technology solutions in a fast paced environment. Candidates must also offer informed solutions or recommendations based on the understanding of the issue in front of them. This position is virtual / remote working from a home office unless traveling to a corporate office or client site.

In this role, you'll get to:
  • Provide first line support of production impacting issues before engaging additional resources
  • Monitor, manage, and optimize SIEM platform performance, which includes but are not limited to:
    • Splunk
    • Google SecOps
    • Microsoft Sentinel
    • Securonix
    • CrowdStrike NG SIEM
    • Palo Alto XSIAM
  • Maintain, manage, and troubleshoot log collection solutions running on Linux and Windows systems supporting data pipelines into SIEM platforms.
  • Identify and remediate critical log ingest gaps to support continuous security monitoring
  • Communicate with leadership and support roles (internal and external)
  • Manage ticket request/incident statuses and provide timely follow up to internal and external customers
  • Participate in projects/initiatives as needed
  • Document network architectures and topologies
  • Keep up-to-date with information security news, techniques, and trends

You'll be successful in this role, if you:
  • Have 2+ years of experience in SIEM administration, security operations, or a related field.
  • Have hands-on experience with at least one SIEM platform such as Splunk, Microsoft Sentinel, Google SecOps, Securonix, CrowdStrike NG SIEM, or Palo Alto XSIAM
  • Understand log data pipelines, parsing, normalization, and troubleshooting methodologies.
  • Are comfortable administering and troubleshooting Linux and Windows systems
  • Have experience working with cloud platforms such as AWS, Azure, or GCP
  • Can independently troubleshoot operational issues and manage competing priorities
  • Communicate clearly with both technical and non-technical audiences
  • Maintain strong documentation and operational discipline in a fast-paced environment
  • Have scripting experience in Python, Bash, or PowerShell
  • Have experience with AWS, Azure, or GCP
  • Hold relevant security or cloud certifications

Statutory Pay Disclosure:

The anticipated salary range for this role is $130,00 - $150,000 + stock options + benefits. Actual compensation may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level.

ITAR Compliance

This position will have access to customer data and as such is subject to International Traffic in Arms Regulations (ITAR). Upon application, candidates will be asked to confirm that they are a U.S. Person as defined by the following:
  • A citizen of the U.S.;
  • A lawful permanent resident of the United States;
  • A person admitted to the United States as a refugee; or
  • A person that has been granted asylum by the United States government.

The intent of this requirement is not to verify employment eligibility overall, but to ensure compliance with import/export regulations. If you do not meet these requirements, we encourage you to apply for other open roles at Deepwatch. This information will be verified upon offer of employment.

What We Offer:

Deepwatch is excited to provide benefits designed to support team members and their families. Including:
  • Medical, dental, vision, and disability insurance
  • Flexible Time Off (FTO), 12 company holidays, sick leave and 8-Weeks Paid Parental Leave
  • Unique professional development benefits with Annual "development dollars" to support our people growth and development
  • Wellness contests and monthly educational programs
  • 401(K) retirement program
  • Learn more here: Deepwatch Benefits

We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates, so please don't hesitate to apply - we'd love to hear from you. Please review our DEI Statement here.

About deepwatch

deepwatch is a cybersecurity company that provides managed security services. The company was founded in 2015 and is headquartered in Denver, Colorado. deepwatch offers a range of cybersecurity services, including threat detection and response, vulnerability management, and compliance management. The company uses artificial intelligence and machine learning to provide advanced threat detection and response capabilities. deepwatch is committed to providing exceptional customer service and helping its clients improve their cybersecurity posture.
Learn more about deepwatch
Size
100 employees
Industry
Founded
2015
Revenue
$10 million

Similar Jobs

More Jobs at deepwatch

More Information Technology Jobs

Find similar Platform SIEM Engineer II jobs: