SIEM Engineer

TalentBridgeX

  • Fort Belvoir, Virginia
  • 3 days ago

    Highlights

    The ideal candidate will bring deep technical expertise in cybersecurity operations and SIEM engineering, with the ability to assess security posture, identify vulnerabilities, develop advanced detection rules and use cases, and strengthen the organization's ability to identify and respond to cyber threats. This senior-level role requires hands-on expertise in Security Information and Event Management (SIEM), security monitoring, threat detection, log analysis, and the development and optimization of enterprise detection capabilities.

    Numbers & Facts

    LocationFort Belvoir, Virginia

    Description

    About the Opportunity

    Our client is seeking an experienced SIEM Engineer / Cybersecurity Specialist Subject Matter Expert (L4) to support a mission-critical cybersecurity environment at Fort Belvoir, Virginia. This senior-level role requires hands-on expertise in Security Information and Event Management (SIEM), security monitoring, threat detection, log analysis, and the development and optimization of enterprise detection capabilities.

    The ideal candidate will bring deep technical expertise in cybersecurity operations and SIEM engineering, with the ability to assess security posture, identify vulnerabilities, develop advanced detection rules and use cases, and strengthen the organization's ability to identify and respond to cyber threats. Candidates must possess an active TS/SCI clearance.

    Key Responsibilities

    • Engineer, administer, optimize, and support enterprise SIEM platforms, including Splunk Enterprise Security (ES) and IBM QRadar.
    • Develop, implement, and maintain SIEM correlation rules, alerts, dashboards, reports, and detection use cases.
    • Perform log ingestion, normalization, management, correlation, and analysis across enterprise security environments.
    • Tune alerts and detection logic to improve fidelity, reduce false positives, and enhance threat-detection capabilities.
    • Analyze security telemetry from Windows, Linux, firewalls, IDS/IPS, cloud platforms, applications, and network infrastructure.
    • Develop SIEM use cases and detection rules aligned with organizational threats, risk profiles, and mission requirements.
    • Assess current cybersecurity posture, define acceptable levels of risk, and support formal security maintenance procedures.
    • Identify potential cybersecurity and information-security vulnerabilities through security assessments, penetration- testing activities, and red-team findings.
    • Support cloud security monitoring and integrate cloud-generated security telemetry into enterprise monitoring platforms.
    • Integrate SIEM capabilities with Security Orchestration, Automation, and Response (SOAR) technologies to improve security operations and incident-response efficiency.
    • Develop scripts and automation using Python, Bash, and/or PowerShell.
    • Apply NIST and MITRE ATT&CK frameworks to threat detection, monitoring, and security operations.
    • Support privacy impact assessments, PII data security and monitoring, migration strategies, and System Privacy Plans.
    • Provide subject matter expertise, cybersecurity guidance, documentation, and operational best practices to mission stakeholders.

    Required Qualifications

    • Active TS/SCI security clearance.
    • Senior-level experience in cybersecurity engineering, security operations, SIEM engineering, or a closely related discipline.
    • Demonstrated hands-on experience with enterprise SIEM platforms, preferably Splunk Enterprise Security and/or IBM QRadar.
    • Strong experience with log management, event correlation, alert development and tuning, SIEM use-case development, detection engineering, and cyber threat analysis.
    • Strong understanding of security logs generated by Windows, Linux, firewalls, IDS/IPS technologies, cloud environments, and enterprise applications and infrastructure.
    • Working knowledge of scripting and automation using Python, Bash, and/or PowerShell.
    • Strong understanding of networking fundamentals and protocols, including TCP/IP, DNS, HTTP, and HTTPS.
    • Working knowledge of cybersecurity frameworks and methodologies, including NIST and MITRE ATT&CK.

    Preferred Qualifications

    • Experience with cloud security monitoring and cloud-native security telemetry.
    • Experience with SOAR platforms, security automation, and automated incident-response workflows.
    • Experience supporting cybersecurity operations within the Federal Government, Department of Defense, or Intelligence Community.
    • Experience with threat hunting, penetration testing, vulnerability assessment, or red-team activities.
    • Experience developing advanced detection content mapped to the MITRE ATT&CK framework.

    Preferred Certifications

    • Splunk Enterprise Security certifications
    • CompTIA Security+
    • CompTIA CySA+
    • CISSP
    • Other relevant cybersecurity, SIEM, cloud security, or information-assurance certifications

    Similar Jobs

    See more jobs