Principal SIEM Engineer @Center for Internet Security
Engineering
Salary usd 128,600 - 2..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted YDay

[Hiring] Principal SIEM Engineer @Center for Internet Security

YDay - Center for Internet Security is hiring a remote Principal SIEM Engineer. 💸 Salary: usd 128,600 - 225,000 per year 📍Location: USA

Role Description

The Principal SIEM Engineer is part of the Operations, Intelligence and Services (OIS) department, which resides on the Engineering team and reports to the Senior Director, Operations, Intelligence and Services. This is a senior, hands-on individual contributor role on the SIEM and SOAR Engineering team. As our Principal SIEM Engineer, you will build and run the platform CIS’s Security Operations Center (SOC) works in:

  • SIEM configuration and log source onboarding
  • SOAR case management and playbook automation
  • Detection content
  • Troubleshooting of the ingestion and case creation pipeline from the collector through to the case an analyst opens

This role requires hands-on engineering in our SIEM and SOAR platform day to day. This role is also the terminal technical escalation point for the platform, which means owning a problem through to resolution rather than routing it onward, including holding the vendor accountable when the defect originates on their side.

CIS provides support to U.S. State, Local, Tribal, and Territorial (SLTT) organizations through a set of cybersecurity solutions (IDS, PDNS, endpoint, and Managed Detection and Response) that feed data to CIS’s SOC, including support for organizations we define as underserved, those with very limited resources that are not well served by current commercial providers. Those services keep growing in both volume and variety.

Every managed service customer arrives with log sources that must be collected, parsed, tagged, validated, alerted on, and automated before the SOC can work them, and much of that is built per log source rather than once per customer. The person in this role must be able to carry a problem across the whole pipeline rather than hand it to a specialist.

Qualifications

  • Bachelor’s degree in Information Technology, Cybersecurity, or a related field*
  • 7+ years’ experience deploying, engineering, and operating enterprise security monitoring and logging platforms
  • 7+ years’ experience in security operations or security engineering in direct support of a security operations center
  • 5+ years’ experience building SOAR automation in a production environment
  • Demonstrated experience troubleshooting a log pipeline end to end
  • Experience serving as a technical escalation point and running escalations with a platform vendor
  • Experience using or producing Cyber Threat Intelligence designed for network defense
  • Willingness to participate in an after-hours on call rotation for the platform
  • Experience interacting with and performing analysis of data collected by security tools
  • Proficiency in security log data enrichment
  • Experience with network forensics and toolsets
  • Experience with cloud technologies and providers
  • Solid client-facing and internal communication skills
  • Solid organizational skills including attention to detail and multi-tasking skills
  • Must be authorized to work in the United States

Requirements

  • Build and maintain SOAR content in our platform
  • Configure and maintain the SIEM
  • Build and tune detection content across the sources CIS monitors
  • Troubleshoot the ingestion and case creation pipeline end to end
  • Participate in incident response for the platform
  • Manage technical escalation with the SIEM and SOAR vendor
  • Deliver the engineering steps of CIS Managed Detection and Response (MDR)
  • Build connector and log source integrations
  • Manage, develop, and tune the queries, alerts, inputs, and scripts
  • Build reporting and dashboards on SIEM and SOAR data
  • Audit ingest volume and manage it against contractual limits
  • Maintain platform documentation
  • Provide technical input to the Product team and leadership decisions
  • Other tasks and responsibilities as assigned

Benefits

  • Compensation Range: USD$128,600.00 - $225,000.00

Company Description

At CIS, we are committed to providing an inclusive environment in which the diverse backgrounds, experiences, and views of our employees, members, and customers are valued and respected. It is through this commitment that we are able to work together towards our common mission: to make the connected world a safer place.

Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Principal SIEM Engineer @Center for Internet Security
Engineering
Salary usd 128,600 - 2..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted YDay
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 127,947+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later