Principal SIEM Engineer - Remote
Budget / Salary$128,600–225,000
TypeFull-time job
LocationUnited States
Posted1 hour ago
The Principal SIEM Engineer is part of the Operations, Intelligence and Services (OIS) department, which resides on the Engineering team and reports to the Senior Director, Operations, Intelligence and Services. This is a senior, hands-on individual contributor role on the SIEM and SOAR Engineering team. As our Principal SIEM Engineer, you will build and run the platform CIS’s Security Operations Center (SOC) works in: SIEM configuration and log source onboarding, SOAR case management and playbook automation, detection content, and troubleshooting of the ingestion and case creation pipeline from the collector through to the case an analyst opens. This role requires hands-on engineering in our SIEM and SOAR platform day to day. This role is also the terminal technical escalation point for the platform, which means owning a problem through to resolution rather than routing it onward, including holding the vendor accountable when the defect originates on their side.
CIS provides support to U.S. State, Local, Tribal, and Territorial (SLTT) organizations through a set of cybersecurity solutions (IDS, PDNS, endpoint, and Managed Detection and Response) that feed data to CIS’s SOC, including support for organizations we define as underserved, those with very limited resources that are not well served by current commercial providers. Those services keep growing in both volume and variety. Every managed service customer arrives with log sources that must be collected, parsed, tagged, validated, alerted on, and automated before the SOC can work them, and much of that is built per log source rather than once per customer. The person in this role must be able to carry a problem across the whole pipeline rather than hand it to a specialist.
What You'll Do:
Develop and maintain SOAR content in our platform, including case management configuration, escalation playbooks, and automations. Author and version playbook templates, including bulk escalation templates spanning multiple source types such as CrowdStrike and Albert, and coordinate changes with SOC leadership before deploying them
Configure and maintain the SIEM, including relay build and join to the SIEM, log source tagging, regular expressions, parsing validation, and alert definitions
Build and tune detection content across the sources CIS monitors, including Suricata, CrowdStrike, and Albert, along with third party endpoint, firewall, and network telemetry
Troubleshoot the ingestion and case creation pipeline end to end and serve as the tier 2 escalation point for the platform; covering every ingestion failure, playbook logic errors, data variance between third party portals and SOAR case data, and any undocumented error type, owned through to resolution
Participate in incident response for the platform, including the tier 2 after-hours on call rotation, and maintain the alerting and routing behind it
Manage technical escalation with the SIEM and SOAR vendor as the CIS contact on severity cases. Diagnose vendor side defects and regressions, judge whether a vendor supplied fix is safe to accept, and design the remediation when it is not
Deliver the engineering steps of CIS Managed Detection and Response (MDR) and SOC as a service customer onboarding, including use case verification, onboarding guide development, relay build and join to the SIEM, log collection verification, tag and regular expression configuration, parsing validation with the vendor, alert definitions, SOAR case automation, user acceptance testing with the SOC, and health monitoring
Build connector and log source integrations and automate buildout where it is repeatable. Sources span Windows and Unix host logs, network devices and firewalls, VPN and remote access, identity and authentication systems, and email security, along with managed service provider collectors
Manage, develop, and tune the queries, alerts, inputs, and scripts that integrate across the suite of cyber defense offerings and the supporting operations infrastructure
Build reporting and dashboards on SIEM and SOAR data, including operational and customer facing dashboards drawing live case data from SOAR tables
Audit ingest volume and manage it against contractual limits, including re-engineering source volume and filtering to keep daily ingest inside the contracted cap
Maintain platform documentation, including the tiered escalation runbooks, onboarding guides, and log source documentation
Provide technical input to the Product team and leadership decisions about the SIEM and SOAR platform, including vendor renewal discussions covering ingest ceilings, licensing models, and platform capability
Other tasks and responsibilities as assigned
What You'll Need:
Bachelor’s degree in Information Technology, Cybersecurity, or a related field*
7+ years’ experience deploying, engineering, and operating enterprise security monitoring and logging platforms, including log source onboarding, parsing, and detection content development
7+ years’ experience in security operations or security engineering in direct support of a security operations center
5+ years’ experience building SOAR automation in a production environment, including case management content, escalation playbooks, and integration with ticketing systems and third-party APIs
Demonstrated experience troubleshooting a log pipeline end to end, from collector or relay through parsing and enrichment to the alert or case an analyst works, and resolving the fault rather than escalating it
Experience serving as a technical escalation point and running escalations with a platform vendor, including assessing whether a vendor supplied fix is safe to deploy
Experience using or producing Cyber Threat Intelligence designed for network defense
Willingness to participate in an after-hours on call rotation for the platform
Experience interacting with and performing analysis of data collected by security tools such as firewall, intrusion detection and prevention systems, data loss prevention, endpoint security tools, host-based logs, network logs, syslog, and other data sources
Proficiency in security log data enrichment, both processes and sources, to include significant operational experience with regular expressions (RegEx), SQL, Python, and analytic techniques
Experience with network forensics and toolsets such as Wireshark, PCAP, tcpdump, and MITRE ATT&CK framework
Experience with cloud technologies and providers such as Amazon, Azure, and Google
Solid client-facing and internal communication skills
Solid organizational skills including attention to detail and multi-tasking skills
Must be authorized to work in the United States
It's a Plus if You Have:
Advanced degree in Computer Science, Business, or related field
Hands-on experience with SIEM and SOAR platforms
Experience onboarding customers onto a managed detection and response or SOC as a service offering, log source by log source
Experience building relays or log collectors and joining them to a SIEM, including TLS termination and client-side collection configuration
Experience developing detection content for network intrusion detection, endpoint detection and response, or firewall telemetry
Experience managing ingest volume against a contracted licensing or volume ceiling
Experience mentoring engineers and cross-training peers on a SIEM or SOAR platform
Strong presentation capabilities
Relevant industry certifications such as CISSP, GCIH, GCIA, GMON
Experience in incident response, vulnerability management, and security operations
Experience in vendor management and relationships
Familiarity with Agile DevOps and project management
Strong knowledge of scripting languages such as Python and PowerShell
*Additional years of relevant experience or a combination of an Associate’s degree or equivalent and relevant experience may be substituted for the Bachelor’s degree.
At CIS, we are committed to providing an inclusive environment in which the diverse backgrounds, experiences, and views of our employees, members, and customers are valued and respected. It is through this commitment that we are able to work together towards our common mission: to make the connected world a safer place.
Compensation Range:
USD$128,600.00 - $225,000.00Originally posted on Himalayas
CIS provides support to U.S. State, Local, Tribal, and Territorial (SLTT) organizations through a set of cybersecurity solutions (IDS, PDNS, endpoint, and Managed Detection and Response) that feed data to CIS’s SOC, including support for organizations we define as underserved, those with very limited resources that are not well served by current commercial providers. Those services keep growing in both volume and variety. Every managed service customer arrives with log sources that must be collected, parsed, tagged, validated, alerted on, and automated before the SOC can work them, and much of that is built per log source rather than once per customer. The person in this role must be able to carry a problem across the whole pipeline rather than hand it to a specialist.
What You'll Do:
Develop and maintain SOAR content in our platform, including case management configuration, escalation playbooks, and automations. Author and version playbook templates, including bulk escalation templates spanning multiple source types such as CrowdStrike and Albert, and coordinate changes with SOC leadership before deploying them
Configure and maintain the SIEM, including relay build and join to the SIEM, log source tagging, regular expressions, parsing validation, and alert definitions
Build and tune detection content across the sources CIS monitors, including Suricata, CrowdStrike, and Albert, along with third party endpoint, firewall, and network telemetry
Troubleshoot the ingestion and case creation pipeline end to end and serve as the tier 2 escalation point for the platform; covering every ingestion failure, playbook logic errors, data variance between third party portals and SOAR case data, and any undocumented error type, owned through to resolution
Participate in incident response for the platform, including the tier 2 after-hours on call rotation, and maintain the alerting and routing behind it
Manage technical escalation with the SIEM and SOAR vendor as the CIS contact on severity cases. Diagnose vendor side defects and regressions, judge whether a vendor supplied fix is safe to accept, and design the remediation when it is not
Deliver the engineering steps of CIS Managed Detection and Response (MDR) and SOC as a service customer onboarding, including use case verification, onboarding guide development, relay build and join to the SIEM, log collection verification, tag and regular expression configuration, parsing validation with the vendor, alert definitions, SOAR case automation, user acceptance testing with the SOC, and health monitoring
Build connector and log source integrations and automate buildout where it is repeatable. Sources span Windows and Unix host logs, network devices and firewalls, VPN and remote access, identity and authentication systems, and email security, along with managed service provider collectors
Manage, develop, and tune the queries, alerts, inputs, and scripts that integrate across the suite of cyber defense offerings and the supporting operations infrastructure
Build reporting and dashboards on SIEM and SOAR data, including operational and customer facing dashboards drawing live case data from SOAR tables
Audit ingest volume and manage it against contractual limits, including re-engineering source volume and filtering to keep daily ingest inside the contracted cap
Maintain platform documentation, including the tiered escalation runbooks, onboarding guides, and log source documentation
Provide technical input to the Product team and leadership decisions about the SIEM and SOAR platform, including vendor renewal discussions covering ingest ceilings, licensing models, and platform capability
Other tasks and responsibilities as assigned
What You'll Need:
Bachelor’s degree in Information Technology, Cybersecurity, or a related field*
7+ years’ experience deploying, engineering, and operating enterprise security monitoring and logging platforms, including log source onboarding, parsing, and detection content development
7+ years’ experience in security operations or security engineering in direct support of a security operations center
5+ years’ experience building SOAR automation in a production environment, including case management content, escalation playbooks, and integration with ticketing systems and third-party APIs
Demonstrated experience troubleshooting a log pipeline end to end, from collector or relay through parsing and enrichment to the alert or case an analyst works, and resolving the fault rather than escalating it
Experience serving as a technical escalation point and running escalations with a platform vendor, including assessing whether a vendor supplied fix is safe to deploy
Experience using or producing Cyber Threat Intelligence designed for network defense
Willingness to participate in an after-hours on call rotation for the platform
Experience interacting with and performing analysis of data collected by security tools such as firewall, intrusion detection and prevention systems, data loss prevention, endpoint security tools, host-based logs, network logs, syslog, and other data sources
Proficiency in security log data enrichment, both processes and sources, to include significant operational experience with regular expressions (RegEx), SQL, Python, and analytic techniques
Experience with network forensics and toolsets such as Wireshark, PCAP, tcpdump, and MITRE ATT&CK framework
Experience with cloud technologies and providers such as Amazon, Azure, and Google
Solid client-facing and internal communication skills
Solid organizational skills including attention to detail and multi-tasking skills
Must be authorized to work in the United States
It's a Plus if You Have:
Advanced degree in Computer Science, Business, or related field
Hands-on experience with SIEM and SOAR platforms
Experience onboarding customers onto a managed detection and response or SOC as a service offering, log source by log source
Experience building relays or log collectors and joining them to a SIEM, including TLS termination and client-side collection configuration
Experience developing detection content for network intrusion detection, endpoint detection and response, or firewall telemetry
Experience managing ingest volume against a contracted licensing or volume ceiling
Experience mentoring engineers and cross-training peers on a SIEM or SOAR platform
Strong presentation capabilities
Relevant industry certifications such as CISSP, GCIH, GCIA, GMON
Experience in incident response, vulnerability management, and security operations
Experience in vendor management and relationships
Familiarity with Agile DevOps and project management
Strong knowledge of scripting languages such as Python and PowerShell
*Additional years of relevant experience or a combination of an Associate’s degree or equivalent and relevant experience may be substituted for the Bachelor’s degree.
At CIS, we are committed to providing an inclusive environment in which the diverse backgrounds, experiences, and views of our employees, members, and customers are valued and respected. It is through this commitment that we are able to work together towards our common mission: to make the connected world a safer place.
Compensation Range:
USD$128,600.00 - $225,000.00Originally posted on Himalayas
Apply on Himalayas →
Job sourced from Himalayas. Applications happen directly on the original platform — we never collect your data.