Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced
SIEM/UEBA Engineer (Mid) to support enterprise cybersecurity operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.
This role serves as a critical technical function responsible for the administration, engineering, and continuous improvement of enterprise Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA) platforms across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, and enterprise applications.
The ideal candidate is a technically proficient and analytically driven cybersecurity professional with demonstrated hands-on experience engineering, administering, and tuning enterprise SIEM and UEBA platforms, developing high-fidelity detection content, and supporting threat detection and incident response operations within a federal government IT environment. This individual must possess the technical depth, analytical rigor, and operational discipline required to build and sustain robust, detection-rich security monitoring capabilities that provide the Government with accurate, timely, and actionable visibility into threats and anomalous activity across the enterprise.
The SIEM/UEBA Engineer (Mid) will serve as a key technical contributor responsible for the engineering, administration, and continuous improvement of the program's enterprise SIEM and UEBA platforms, detection content library, log ingestion architecture, and security analytics capabilities. This individual works closely with security engineers, SOC analysts, incident responders, infrastructure engineers, cloud operations teams, and Government stakeholders to ensure the SIEM and UEBA platforms provide comprehensive, high-fidelity, and continuously improving threat detection and behavioral analytics coverage across the full enterprise environment-supporting the Government's ability to detect, investigate, and respond to cybersecurity threats rapidly and effectively.
Principal responsibilities will include but are not limited to:
SIEM Platform Engineering & Administration- Administer, engineer, and maintain the enterprise SIEM platform, ensuring the platform is properly configured, optimized, and continuously improved to support comprehensive security monitoring, threat detection, and incident investigation across the full enterprise environment.
- Design, implement, and maintain log ingestion architectures, ensuring all required log sources-including endpoints, servers, network devices, cloud platforms, enterprise applications, identity platforms, and security tools-are onboarded, reliably ingesting, and properly parsed into the SIEM.
- Develop and maintain log source onboarding documentation, data ingestion runbooks, and parser configurations, ensuring all log sources are accurately documented and ingestion pipelines are well-understood and maintainable.
- Monitor SIEM platform health, performance, and data ingestion reliability, proactively identifying and resolving ingestion failures, data gaps, parsing errors, and platform performance issues before they impact detection capability or investigation support.
- Manage SIEM platform capacity, licensing, and storage, ensuring the platform operates within defined performance parameters and that capacity planning activities are conducted proactively to address growth in log volume and data retention requirements.
- Implement and maintain SIEM platform access controls, ensuring role-based access is properly configured and that analyst, engineer, and administrative access privileges are aligned with least-privilege principles and applicable Federal security requirements.
- Support SIEM platform upgrades, patches, and configuration changes, coordinating with the change management process and ensuring all changes are properly tested and documented prior to production implementation.
- Develop and maintain SIEM platform architecture documentation, including data flow diagrams, log source inventories, ingestion pipeline configurations, and platform configuration baselines.
UEBA Platform Engineering & Administration- Administer, engineer, and maintain the enterprise UEBA platform, ensuring the platform is properly integrated with relevant data sources, accurately modeling user and entity behavior baselines, and generating high-fidelity risk scores and anomaly detections.
- Design and implement UEBA data source integrations, ensuring the platform ingests relevant identity, authentication, endpoint, application, cloud, and network data necessary to build accurate and comprehensive behavioral baselines.
- Configure and tune UEBA behavioral models, risk scoring algorithms, and anomaly detection rules, balancing detection sensitivity with alert fidelity to maximize actionable insight while minimizing false positive rates.
- Develop and maintain UEBA use cases targeting insider threat scenarios, compromised credential activity, privilege escalation, lateral movement, data exfiltration, and other high-priority behavioral risk indicators relevant to the enterprise environment.
- Monitor UEBA platform health, performance, and detection output quality, proactively identifying and resolving platform issues, model degradation, and detection coverage gaps.
- Develop and maintain UEBA platform documentation, including use case specifications, risk scoring configurations, behavioral model descriptions, and integration architecture documentation.
Detection Engineering & Content Development- Design, develop, implement, and continuously improve a comprehensive library of SIEM detection rules, correlation queries, behavioral analytics models, and alerting configurations aligned with the MITRE ATT&CK framework, covering the full spectrum of relevant adversary tactics, techniques, and procedures (TTPs) targeting the enterprise environment.
- Conduct regular detection coverage assessments, mapping existing detection content against the MITRE ATT&CK framework to identify coverage gaps, prioritize new detection development, and ensure detection capabilities keep pace with the evolving threat landscape.
- Develop and maintain detection content for high-priority threat scenarios, including insider threats, credential theft and abuse, privilege escalation, lateral movement, command-and-control communications, data exfiltration, ransomware activity, and cloud-based attack techniques.
- Implement and maintain detection tuning processes, regularly reviewing alert volumes, false positive rates, and detection fidelity metrics to identify and implement tuning improvements that increase alert quality and reduce analyst burden.
- Develop and maintain threat-informed detection content based on current threat intelligence, Government-issued advisories, and observed threat actor TTPs, ensuring detection capabilities are continuously updated to address emerging threats.
- Develop and maintain detection content documentation, including detection rule specifications, use case descriptions, alert triage guides, and expected false positive patterns, ensuring detection content is well-documented and maintainable.
- Support purple team and detection validation activities, coordinating with threat emulation and penetration testing efforts to validate detection coverage and identify gaps requiring additional detection development.
Log Source Management & Data Normalization- Manage the enterprise log source inventory, maintaining an accurate and current record of all log sources onboarded to the SIEM, including source type, ingestion method, data volume, parsing status, and detection relevance.
- Develop and maintain custom log parsers, field extraction configurations, and data normalization mappings for non-standard or custom log sources, ensuring all ingested data is accurately parsed and available for detection and investigation use.
- Conduct regular log source quality assessments, identifying and resolving data quality issues, parsing errors, field mapping inconsistencies, and ingestion reliability problems that may impact detection fidelity or investigation capability.
- Support the onboarding of new log sources as the enterprise environment evolves, working with infrastructure engineers, cloud operations teams, and application owners to identify, onboard, and validate new data sources relevant to security monitoring objectives.
- Develop and maintain log ingestion and data normalization documentation, ensuring all custom parsers, field mappings, and ingestion configurations are accurately documented and version-controlled.
Security Analytics & Threat Intelligence Integration- Develop and maintain advanced security analytics capabilities within the SIEM and UEBA platforms, including threat hunting queries, statistical analysis models, and automated enrichment workflows that enhance detection and investigation capabilities.
- Integrate threat intelligence feeds into the SIEM platform, developing automated indicator of compromise (IOC) matching, threat intelligence enrichment, and threat intelligence-driven alerting capabilities.
- Develop and maintain automated alert enrichment workflows, ensuring SIEM alerts are automatically enriched with relevant contextual data-including asset information, user identity data, threat intelligence, and vulnerability context-to accelerate analyst triage and investigation.
- Support threat hunting activities, developing and executing hypothesis-driven hunting queries across SIEM data to proactively identify indicators of compromise, anomalous activity, and undetected threats within the enterprise environment.
- Analyze threat hunting findings and SIEM detection performance data to identify opportunities for new detection content development, platform tuning improvements, and security control enhancements.
Incident Investigation Support- Provide expert SIEM and UEBA platform support to security incident investigations, developing targeted queries, timeline reconstructions, and behavioral analysis outputs that help analysts and incident responders rapidly characterize the scope, nature, and impact of security incidents.
- Support the development and maintenance of investigation playbooks and query libraries that guide analysts through structured, repeatable investigation workflows for common incident types.
- Develop and maintain SIEM dashboards and investigation views optimized for analyst use, ensuring analysts have rapid access to the data, visualizations, and contextual information needed to efficiently triage and investigate security alerts.
- Contribute to post-incident review activities, providing SIEM and UEBA platform perspective on detection effectiveness, investigation data availability, and opportunities to improve detection and response capabilities based on incident findings.
Reporting, Metrics & Documentation- Develop and maintain SIEM and UEBA performance metrics, including log ingestion volume and reliability, detection rule coverage, alert volume and fidelity, false positive rates, mean time to detect (MTTD), and analyst workload metrics.
- Prepare and present SIEM and UEBA performance reports and briefings for program leadership and Government stakeholders, communicating platform health, detection coverage, and improvement initiative status clearly and accurately.
- Develop and maintain comprehensive SIEM and UEBA engineering documentation, including platform architecture diagrams, log source inventories, detection content libraries, tuning records, and standard operating procedures.
- Support the development and maintenance of the program's security metrics dashboard, ensuring SIEM and UEBA performance data is accurately reflected in program reporting deliverables.
Compliance & ATO Support- Ensure the SIEM and UEBA platforms are configured and maintained in compliance with applicable Federal cybersecurity frameworks and requirements, including NIST SP 800-53, FISMA, FedRAMP, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, applicable DISA STIGs, and client-specific cybersecurity policies.
- Support ATO activities for the SIEM and UEBA platforms, including security control implementation documentation, system security plan (SSP) contribution, continuous monitoring reporting, and audit evidence collection.
- Support continuous monitoring activities, ensuring SIEM and UEBA platform configurations are regularly assessed for compliance and that any identified deviations are promptly remediated and documented.
Education and Experience:Required:- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience may be considered.
- Minimum of 3-5 years of hands-on experience in SIEM engineering, security operations, or a closely related cybersecurity discipline within a federal government IT contracting or enterprise security environment.
- Demonstrated hands-on experience administering and engineering enterprise SIEM platforms, including log source onboarding, parser development, detection rule creation, alert tuning, and platform administration.
- Experience developing detection content aligned with the MITRE ATT&CK framework, including correlation rules, behavioral analytics, and threshold-based alerting.
- Experience with log ingestion architecture design, including the onboarding and normalization of diverse log source types across endpoint, network, application, cloud, and identity platforms.
- Active security clearance or the ability to obtain and maintain