SIEM Engineer

IDBNY

$140K — $160K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of cybersecurity experience
  • 3+ years managing and engineering SIEM platforms
  • Experience supporting SOC operations and incident response
  • Preferred experience in financial services or regulated industries
  • Technical expertise in various SIEM platforms and data ingestion processes

Responsibilities

  • Manage and maintain enterprise SIEM platforms
  • Develop and maintain correlation rules and detection content
  • Support SOC operations through advanced threat detection
  • Integrate threat intelligence feeds into the SIEM platform
  • Automate SIEM administration and monitoring tasks
  • Ensure compliance with regulatory and audit requirements
  • Produce security metrics and executive reports

Benefits

  • Annual bonus eligibility
  • Comprehensive medical, pharmacy, dental, and vision plans
  • Life and disability insurance
  • Employee wellness program
  • Retirement and savings plans with employer contributions
  • Generous holiday and paid time off schedules
  • Parental leave
  • Tuition reimbursement
Full Job Description
SIEM Engineer - Job Description

Role Overview

The SIEM Engineer is responsible for designing, implementing, maintaining, and optimizing the organization's Security Information and Event Management (SIEM) platform. This role supports Security Operations by developing detection use cases, integrating log sources, improving threat visibility, and enhancing incident response capabilities across on-premises, cloud, and hybrid environments. The SIEM Engineer works closely with SOC analysts, incident responders, threat intelligence teams, infrastructure teams, and security leadership to strengthen the organization's cyber defense posture.

Key Responsibilities
  1. SIEM Administration & Engineering
  • Manage and maintain enterprise SIEM platforms.
  • Configure and optimize log ingestion, normalization, parsing, and retention.
  • Integrate security data sources including:
    • Firewalls
    • IDS/IPS
    • EDR/XDR
    • Active Directory / Entra ID
    • Cloud platforms (Azure, AWS, GCP)
    • Network and endpoint security solutions
  • Ensure availability, scalability, and performance of SIEM infrastructure.
  1. Detection Engineering & Use Case Development
  • Develop and maintain correlation rules, analytics, and detection content.
  • Create use cases aligned with MITRE ATT&CK techniques.
  • Tune detection rules to reduce false positives and improve alert fidelity.
  • Work with Purple Team, Red Team, and Threat Intelligence teams to improve detection coverage.
  • Implement new monitoring capabilities for emerging threats.
  1. Security Monitoring & Incident Support
  • Support SOC operations through advanced threat detection and alert analysis.
  • Assist incident responders during investigations.
  • Correlate events across multiple technologies to identify malicious activity.
  • Perform root cause analysis and recommend containment improvements.
  • Develop dashboards and reporting for operational visibility.
  1. Threat Hunting & Threat Intelligence Integration
  • Develop hunting queries to identify malicious behavior not detected by automated alerts.
  • Integrate threat intelligence feeds into the SIEM platform.
  • Create indicators of compromise (IOC) monitoring and enrichment processes.
  • Identify suspicious trends and emerging attack patterns.
  1. Automation & Optimization
  • Automate SIEM administration and monitoring tasks using scripting.
  • Integrate SIEM with SOAR platforms and ticketing systems.
  • Develop workflows for alert enrichment, escalation, and incident response.
  • Improve operational efficiency through automation and orchestration.
  1. Governance, Compliance & Reporting
  • Support regulatory and audit requirements.
  • Maintain SIEM documentation, runbooks, and standards.
  • Produce security metrics and executive reporting.
  • Ensure log retention and monitoring practices meet compliance requirements.

Required Qualifications

Experience
  • 5+ years of cybersecurity experience.
  • 3+ years managing and engineering SIEM platforms.
  • Experience supporting SOC operations and incident response.
  • Experience in financial services or regulated industries preferred.

Technical Skills
  • Expertise in platforms such as:
    • Microsoft Sentinel
    • Splunk
    • QRadar
    • LogRhythm
    • Elastic Security
    • CrowdStrike NG-SIEM
    • Cribl
  • Strong knowledge of:
    • Windows and Linux security logs
    • Network security monitoring
    • EDR/XDR technologies
    • Threat hunting methodologies
    • MITRE ATT&CK framework
    • Data ingestion pipelines
  • Scripting experience:
    • KQL
    • PowerShell
    • Python
    • SQL

Security Knowledge
  • Log management and event correlation.
  • Detection engineering.
  • Threat intelligence.
  • Incident response processes.
  • Vulnerability management concepts.
  • Zero Trust security principles.


Preferred Certifications
  • Microsoft Certified: Security Operations Analyst (SC-200)
  • Microsoft Sentinel Specialty
  • Splunk Enterprise Security Certified Admin
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • CISSP

CompensationThe expected annual salary for this position is between $140,000 and $160,000 at the start of employment. A salary offer is determined on an individualized basis, taking into consideration factors such as an individual's skills and experience. In addition to base salary, our total rewards package also includes eligibility for an annual bonus, medical, pharmacy, dental, and vision plans, life and disability insurance, employee wellness program, retirement and savings plans with employer contributions, generous holiday and paid time off schedules, parental leave, and tuition reimbursement.
Additional Information

DisclaimerThe above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities from time to time, as needed.
All your information will be kept confidential according to EEO guidelines.
We are operating on a Hybrid schedule.NO AGENCIES PLEASE.

Similar Jobs

More Jobs at IDBNY

More Information Technology Jobs

Find similar SIEM Engineer jobs: