SIEM Engineer
| Verified Pay check_circle | Provided by the employer$133000 - $166000 per year |
|---|---|
| Hours | Full-time |
| Location | Austin, TX Austin, Texas open_in_new |
About this job
Job Description
SIEM Engineer II – Direct Hire
Location: Austin, TX – Onsite
Employment Type: Full-Time, Direct Hire
Work Authorization: U.S. Citizen or Green Card Holder Required
Urgency: Immediate Hiring Need
Our client is looking for an experienced SIEM Engineer II to join its cybersecurity team in Austin. This is an urgent, direct-hire opportunity for a hands-on security engineer with strong experience in Splunk Enterprise Security, SIEM engineering, security telemetry, detection engineering, and log management.
This is not simply a SOC monitoring position. We are looking for someone who has worked behind the scenes of a SIEM environment—onboarding and improving data sources, engineering detections, troubleshooting log quality, optimizing telemetry, and helping security teams turn large volumes of data into actionable threat intelligence.
The ideal candidate will bring strong Splunk expertise along with practical experience supporting cloud, endpoint, identity, network, and application security telemetry.
What You'll Do
- Engineer, administer, optimize, and support enterprise SIEM environments, with a strong emphasis on Splunk Enterprise and Splunk Enterprise Security (ES).
- Onboard new security and technology log sources into the SIEM platform.
- Perform log parsing, normalization, enrichment, filtering, and data-quality remediation.
- Develop and tune SPL searches, correlation rules, alerts, and security detections.
- Build detections for threats involving compromised identities, malware, lateral movement, privilege escalation, suspicious network activity, cloud threats, and other attack patterns.
- Map detections and security use cases to frameworks such as MITRE ATT&CK.
- Integrate telemetry from cloud platforms, endpoints, firewalls, identity platforms, network security tools, vulnerability-management platforms, and business applications.
- Partner with SOC and incident-response teams to improve detection coverage, investigation capabilities, and response workflows.
- Troubleshoot ingestion, indexing, parsing, data-quality, and performance issues.
- Develop dashboards, reports, and analytics that improve security visibility and operational decision-making.
- Support large-scale security data ingestion and help improve the performance, reliability, and scalability of SIEM infrastructure.
- Collaborate with infrastructure, cloud, application, IAM, network, and cybersecurity teams to identify logging requirements and close visibility gaps.
- Assist with automation and orchestration of security processes and response workflows.
- Document log sources, detections, configurations, troubleshooting procedures, and operational processes.
What We're Looking For
- Several years of hands-on experience in SIEM engineering, security engineering, detection engineering, SOC engineering, or a closely related cybersecurity discipline.
- Strong hands-on experience with Splunk Enterprise and/or Splunk Enterprise Security.
- Demonstrated ability to write and troubleshoot SPL.
- Experience onboarding and integrating security telemetry and enterprise log sources.
- Strong understanding of log ingestion, parsing, normalization, enrichment, data models, and data quality.
- Experience developing, tuning, and maintaining security detections and correlation searches.
- Understanding of common attacker techniques and the ability to translate threats into effective SIEM detections.
- Experience working with security telemetry from areas such as cloud, endpoint, IAM, firewalls, network security, vulnerability management, and applications.
- Knowledge of MITRE ATT&CK and modern detection-engineering practices.
- Understanding of incident response, threat detection, and SOC operations.
- Strong troubleshooting skills and the ability to work with technical teams to resolve complex logging and integration issues.
Highly Valued Experience
Candidates do not need every item below, but experience in several of these areas will be particularly attractive:
- Splunk Enterprise Security
- Splunk administration and large-scale data ingestion
- Cribl or similar telemetry-routing/log-pipeline technologies
- Splunk SOAR/Phantom or other security automation platforms
- AWS security telemetry such as CloudTrail, GuardDuty, and VPC Flow Logs
- Azure or GCP security logging
- Endpoint platforms such as CrowdStrike or SentinelOne
- Palo Alto, Fortinet, Cisco, or similar network-security technologies
- IAM telemetry and identity-threat detection
- Vulnerability-management platforms such as Tenable or Qualys
- Infrastructure automation using tools such as Terraform, Ansible, Docker, Kubernetes, or CI/CD pipelines
- Additional SIEM technologies such as QRadar, ELK, or LogRhythm
- Security frameworks including NIST, CIS Controls, or ISO 27001
Education & Certifications
A bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline is preferred. Equivalent professional experience will also be considered.
Relevant certifications such as Splunk Enterprise Certified Admin, Splunk Enterprise Security certifications, Splunk Cybersecurity Defense Analyst, CISSP, Security+, or AWS certifications are highly valued.
Important Requirements
This is a full-time, direct-hire position located in Austin and requires onsite work.
Candidates must be able and willing to work onsite as required.
Applicants must be U.S. Citizens or U.S. Permanent Residents (Green Card holders). Sponsorship is not available for this position.
Our client is moving quickly and is looking to identify qualified candidates immediately.
If you are a hands-on SIEM engineer who enjoys building and improving security capabilities—not simply monitoring alerts—we would like to hear from you.
We Place People is a premiere Executive Search Firm working with leading companies nationwide. We have a direct relationship with our clients and a 95% hire rate! We differentiate ourselves from other firms & work closely with our candidates throughout the interview process. WE PLACE PEOPLE is what we do best!