Senior Information Security Engineer - SIEM and Detection

Faegre Drinker Biddle & Reath LLP

$160K — $183K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in cybersecurity, information systems, or related field, or equivalent experience
  • 8+ years of relevant information security experience emphasizing security operations and incident response
  • Hands-on experience with SIEM platform engineering, including log source onboarding and migrations
  • Proficient in developing and tuning detections using MITRE ATT&CK framework and query languages like KQL
  • Experience configuring enterprise EDR platforms, with CrowdStrike Falcon as a strong preference
  • Demonstrated leadership in incident response, including plan maintenance and tabletop exercises
  • Experience managing relationships with managed detection and response/security service providers
  • Familiarity with Microsoft security tools and knowledge of network and email security controls.

Responsibilities

  • Own architecture, configuration, and performance of the firm's SIEM platform in partnership with CrowdStrike
  • Onboard and maintain various log sources using Microsoft and other key technologies
  • Design, build, test, and tune detection rules and analytics aligned with MITRE ATT&CK framework
  • Serve as senior technical lead for the Security Incident Response Team, guiding investigations
  • Maintain the firm's Incident Response Plan and playbooks as environments and threats evolve
  • Configure CrowdStrike Falcon and its modules across firm endpoints and identities
  • Develop security automation and orchestration workflows integrating SIEM, CrowdStrike, and ServiceNow

Benefits

  • Flexible working environment for better work-life balance
  • Opportunity to engage in firm-sponsored volunteer activities
  • Wellness programming tailored to individual needs
  • Professional atmosphere with access to top experts in the field
  • Diverse health plan options including dental, vision, and 401(k) plans
  • Generous paid time off policy
Full Job Description
Job Description Summary:
Faegre Drinker has an opportunity for a Senior Information Security Engineer - SIEM and Detection to work with our Technology & Innovation team in our Philadelphia, New York City, or Washington, D.C. offices. You will be part of a dynamic team responsible for owning the firm's security monitoring platform and the detection capability built on it. This position will work with other talented individuals who share a passion for doing great work in the best interest of our clients.

Job Description:

What you would do:
  • Owns the architecture, configuration, health, and performance of the firm's SIEM platform, including data ingestion, parsing, normalization, retention, and cost management, in partnership with CrowdStrike as the managed security service provider
  • Onboards and maintains log sources across Microsoft Defender, Microsoft Entra ID, Microsoft 365, Microsoft Purview, Azure, CrowdStrike, network and firewall infrastructure, and key business applications, using Event Hub, Graph API, and native connectors as appropriate
  • Designs, builds, tests, and tunes detection rules and analytics mapped to the MITRE ATT&CK framework, prioritizing coverage based on the firm's threat profile and risk
  • Serves as senior technical lead for the Security Incident Response Team, guiding investigations from analysis and containment through recovery and reporting, and advising the Director and leadership on response decisions
  • Owns the firm's Incident Response Plan and playbooks, maintaining them as the firm's environment, threats, and regulatory obligations evolve
  • Owns the configuration of the CrowdStrike Falcon platform and its related modules across all firm endpoints and identities, including EDR, Identity Protection, Data Protection, prevention and update policies, integrations, and day-to-day tuning, along with adjacent security technologies that feed or act on Falcon data
  • Builds security automation and orchestration workflows for common response actions, enrichment, and case management, integrating the SIEM, CrowdStrike, and ServiceNow
  • Special projects and other duties as assigned


What is expected:
  • Ability to problem-solve
  • Excellent interpersonal, verbal and written communication skills, including the ability to communicate effectively in a virtual environment (e.g., via phone, web/videoconference)
  • Ability to concentrate on tasks, make decisions and work calmly and effectively in a high-pressure, deadline-orientated environment
  • Demonstrated ability to use good judgment in taking initiative while asking for direction or clarification and consulting others, as appropriate
  • Willingness to be flexible with time and adjust to a changing work environment
  • Ability to build and maintain positive relationships, both internally and externally, while maintaining a client service orientation
  • Ability to use sound judgment and discretion in dealing with highly confidential information
  • Ability to take direction and accept supervision
  • Demonstrated ability to work independently, organize and accurately prioritize work, be detail-oriented, understand when urgency is required and use good judgment in varied situations
  • Ability to work effectively with co-workers in a team oriented collaborative environment


What we offer:
  • Flexible working environment for work-life success
  • Opportunity to participate in firm-sponsored volunteer events
  • Wellness programming with personalized content and activities
  • Professional environment and the opportunity to work with experts at the top of their fields
  • Variety of health plan options, as well as dental, vision and 401(k) plans
  • Generous paid time off


The anticipated initial salary for someone who is hired into this position is $160,200 - $183,100.

Actual initial salary may be above or below the above-identified range and will be based on the relevant skills, training, experience, and other job-related factors, including the location where the position is filled, in all cases consistent with applicable law. This is an exempt role and the initial salary range listed above is just one component of Faegre Drinker's total compensation and benefits package for professional staff, which includes, but is not limited to, a discretionary bonus; life, health, accident, and disability insurance; and a 401(k) plan.

What is required:
  • Bachelor's degree in cybersecurity, information systems, or a related field, or equivalent years of experience
  • Eight years or more of relevant information security experience, including security operations and incident response in an enterprise environment
  • Hands-on experience engineering a SIEM platform, including log source onboarding, forwarding infrastructure, parsing and normalization, and at least one major deployment or migration
  • Experience developing and tuning detections, with working knowledge of the MITRE ATT&CK framework and query languages such as KQL or equivalent
  • Experience owning the configuration of an enterprise EDR platform, including policy management, tuning, integrations, and containment actions. CrowdStrike Falcon experience strongly preferred
  • Demonstrated experience leading incident response, including building or maintaining incident response plans and playbooks and running tabletop exercises
  • Experience managing a managed detection and response or managed security service provider relationship as the primary technical counterpart, including tuning, escalation, and service reviews
  • Working knowledge of Microsoft security tooling, including Microsoft Defender, Microsoft Entra ID, Microsoft 365, and Microsoft Purview
  • Working knowledge of network security, firewalls, and email security controls.
  • Thorough understanding of current security principles, techniques, and protocols.
  • Ability to effectively communicate information security issues, risks, and recommendations to both technical and non-technical peers and management, including through well-written reports


Apply now if you are ready to join the Faegre Drinker team!

Similar Jobs

More Jobs at Faegre Drinker Biddle & Reath LLP

More Information Technology Jobs

Find similar Senior Information Security Engineer - SIEM and Detection jobs: