Cyber Defense Engineer - SIEM
NorthMark Strategies
Cyber Defense Engineer – SIEM
NorthMark Strategies is a leading investment firm, combining capital, innovation, and engineering to drive long-term value. From operating complex businesses to backing breakthrough technologies, our mission is to build enduring businesses. Our team combines intelligent risk-taking, operational excellence, exceptional talent, and world-class computing capacity to create shareholder value.
Our company offers a dynamic environment where individuals have the freedom to lead companies toward bold achievements by embracing innovation, leveraging technology, and fostering differentiated business strategies. Our values are Integrity, Ability, and Energy, and the company aims to hire individuals who possess those qualities.
At NorthMark Strategies, we believe the future isn't something to hope for, it's something to build. We don't just invest, we create. Bringing together strategic insight and technical horsepower to deliver outcomes that endure.
The Cyber Defense Engineer – SIEM reports to the Director of Cyber Defense and operates within the Office of the CISO. This role is responsible for architecting, developing, and implementing advanced security solutions that enhance cyber defense investigations and incident response capabilities.
This position places a strong emphasis on AI-driven security engineering, including the development of intelligent detection systems, automation pipelines, and data-driven defense mechanisms. The ideal candidate will combine deep expertise in the Microsoft security ecosystem with experience leveraging artificial intelligence and machine learning to improve SIEM/SOAR performance, detection fidelity, and operational efficiency.
You will collaborate across IT and security teams to design scalable logging, enrichment, and response architectures, while continuously advancing the organization's AI-enabled SIEM engineering maturity.
Responsibilities:
- Design, develop, and deploy AI-enhanced detections and automations within the SIEM/SOAR platform to improve signal-to-noise ratio and reduce alert fatigue.
- Engineer and optimize SIEM pipelines using AI/ML techniques for anomaly detection, behavioral analytics, and threat correlation.
- Integrate SIEM with security tools and data sources to build a context-rich, intelligence-driven monitoring ecosystem.
- Develop and implement AI-assisted threat detection models, including user/entity behavior analytics (UEBA) and predictive analytics.
- Collaborate with cyber defense operations to identify emerging threats and capability gaps, leveraging AI to proactively strengthen defenses.
- Build and maintain automated response orchestration and intelligent playbooks that adapt based on threat context.
- Design automation for alert enrichment, triage, and response using both rule-based and AI-assisted decisioning frameworks.
- Partner with IT and engineering teams to ensure comprehensive telemetry collection and high-quality data pipelines.
- Continuously improve SIEM engineering practices, including data normalization, enrichment strategies, and AI model tuning.
- Support SOC operations by enhancing detection engineering, incident response workflows, and operational metrics through AI augmentation.
Requirements:
- Bachelor's degree in computer science, Information Security, or a related field.
- 4–6+ years of experience in cybersecurity engineering, SOC engineering, or insider threat.
- Demonstrated expertise in SIEM engineering and security monitoring at scale.
- Experience integrating or developing AI/ML capabilities within security operations or detection engineering.
- Strong understanding of the Microsoft security stack (e.g., Sentinel, Defender suite)
- Proficiency with automation tooling and scripting languages (KQL, Python, Powershell)
- Proficiency in API development with the goal of integrating security tooling
- Familiarity with various log ingestion methodologies into a SIEM environment.
- Experience in multi-tenant or MSP like environments a plus
- Highly motivated self-starter who thrives on positively influencing the environment.
It is impossible to list every requirement for, or responsibility of, any position. Similarly, we cannot identify all the skills a position may require since job responsibilities and the Company's needs may change over time. Therefore, the above job description is not comprehensive or exhaustive. The Company reserves the right to adjust, add to or eliminate any aspect of the above description. The Company also retains the right to require all employees to undertake additional or different job responsibilities when necessary to meet business needs.
Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Benefits & Perks:
- Company-Paid Lunch Stipend: Lunch is provided via GrubHub
- Company-Paid Benefits: 100% Employer-Paid Medical in our High Deductible Health Plan, Dental and Vision benefits for employees and their families, 16 weeks of Paid Parental Leave, Employee Assistance Program, Life insurance, Short-Term Disability and Long-Term Disability
- 401(k): Company will match 100% of your contributions up to 6%
- Optional Employee-Paid Benefits: Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.
- Time Off: 25 days of Paid Time Off plus 12 company holidays
EQUAL OPPORTUNITY EMPLOYER
NORTHMARK STRATEGIES LLC IS AN EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER. THE COMPANY'S POLICY IS NOT TO DISCRIMINATE AGAINST ANY APPLICANT OR EMPLOYEE BASED ON RACE, COLOR, RELIGION, NATIONAL ORIGIN, GENDER, AGE, SEXUAL ORIENTATION, GENDER IDENTITY OR EXPRESSION, MARITAL STATUS, MENTAL OR PHYSICAL DISABILITY, AND GENETIC INFORMATION, OR ANY OTHER BASIS PROTECTED BY APPLICABLE LAW. THE FIRM ALSO PROHIBITS HARASSMENT OF APPLICANTS OR EMPLOYEES BASED ON ANY OF THESE PROTECTED CATEGORIES.
$99k - $232k
...cybersecurity focus on protecting organizations from cyber threats through advanced technologies and... ...in network security, cybersecurity engineering, or security consulting, including... ...technologies such as firewalls, IDS/IPS, SIEM, endpoint security, and cloud security solutions...SuggestedFull timeH1b$168k - $195k
...About The Role We are seeking a highly skilled Senior Cyber Security Engineer - SIEM and Automation to lead and enhance our detection... ...Continuous learning mindset with a focus on threat-driven defense Compensation : The anticipated salary range for...SuggestedWork at officeLocal areaImmediate startRemote workRelocation$77k - $202k
...people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work... ...Sets You Apart Master's Degree in Computer Science, Electrical Engineering, Industrial Engineering, Industrial and Operations Engineering...SuggestedFull timeH1b$99k - $232k
...people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work... ...Sets You Apart Master's Degree in Computer Science, Electrical Engineering, Industrial Engineering, or Industrial and Operations...SuggestedFull timeH1b- ...cybersecurity software company is looking for a Senior Detection Engineer to enhance detection engineering and operations in a fully... ...5–8 years of relevant experience, including hands-on work with SIEM and security analytics tools. A solid understanding of cloud environments...SuggestedRemote work
$50 per hour
...Our client is seeking a skilled Security Engineer with strong hands-on experience in SIEM platforms and a solid IT/Security background. This role will focus on designing, implementing, and maintaining security monitoring and response solutions, with a particular emphasis...- ...GuidePoint Security, LLC offers a cybersecurity role requiring 3-5 years in SIEM/SOAR solutions. Candidates should have expertise in deploying security content for various SIEM platforms, including Splunk and Palo Alto. The position is primarily remote, focusing on minimizing...Remote workFlexible hours
- A travel and technology company seeks a Senior Security Operations Engineer to enhance security operations and incident response processes. This role requires deep expertise in AWS, GCP, and SIEM tools, along with a proactive mindset for continuous improvement. The candidate...Flexible hours
- ...Senior Detection Engineer (SIEM / Security Observability) Remote, US Description Keeper Security is seeking a Senior Detection Engineer to... ...platform that protects users, devices, and infrastructure from cyber attacks. About the Job As a Senior Detection Engineer, you will...Remote work
$124k - $280k
...people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work... ...What Sets You Apart - Bachelor's/Master's Degree in Computer Engineering, Computer Applications, Computer Programming, Computer Science,...Full timeH1b$106k - $170k
...global investment firm in New York is seeking an Associate Security Engineer. The role involves providing security platform engineering... ...information security, cloud technologies, and hands-on experience with SIEM tools like Splunk. The position offers a competitive salary...- ...A leading cybersecurity firm seeks a Sales Engineer in Kentucky who will manage technical relationships with prospective clients throughout... ...role requires at least 2 years of experience in log management, SIEM, and XDR, along with strong communication skills. Candidates...Flexible hours
- ...for a cybersecurity role focusing on end-to-end security investigations and incident analysis. The position demands proficiency in SIEM platforms and experience in a SOC environment. Ideal candidates will possess practical knowledge of Splunk, Mimecast, and various security...
$40 - $60 per hour
...CeDent is seeking an experienced Cybersecurity Engineer to strengthen its team. The ideal candidate will have extensive knowledge in network... ...host-based security, privileged access management, and various SIEM tools. This position requires hands-on experience with...Hourly payContract work- ...internal and external learning platforms, cyber conferences, industry events, and... ...What will you be doing as a Cyber Range Engineer at SimSpace? Design and architect complex... ...strong understanding of cyber security tools (SIEM, Proxy, AV, EDR, DLP, HID/NID, HIP/NIP, Forensics...Contract workTemporary workFor subcontractorInternshipWork at officeLocal areaRemote work
$120k - $253k
...SVP – Cyber Technology Engineer At BNY, our culture allows us to run our company better and enables employees' growth and success. As a leading... ...log data Experience integrating security technologies (SIEM, EDR, vulnerability platforms, etc.) Exposure to AI / ML...Temporary workWork experience placementWorldwideFlexible hours- ...Rapid Strategy, a leading cybersecurity provider, is seeking a mid-level resource to support Cyber Operations with a non-profit client. This role demands expertise in incident response and vulnerability management using tools like CrowdStrike and Microsoft Security suite...
- ...automated response (SOAR) workflows - connecting alerts from Panther SIEM, SentinelOne EDR, and Wiz CSPM into automated investigation and... ...daily - not just proof-of-concept scripts ~ Strong software engineering skills in Python, TypeScript, or Go - you write production-...Work at officeImmediate startRemote workRelocation package
- A leading European technology company is seeking a Cyber Security Engineer specializing in advanced security tools to join their Information Security team. The role involves managing penetration testing, SIEM, and incident response technologies. Candidates should have a...
$104k - $156k
...Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will design... ...investigations in partnership with Cyber teams ~ Continuously improve endpoint... ...Security Information and Event Management (SIEM), Security Operations, Threat Modeling, Vulnerability...Remote work- ...Senior Security Engineer, Security Incident Response Team (SIRT) Remote... ...continuous improvements in defense, detection and response capabilities... ...capabilities, including SIEM use cases, alerting strategies... ...response resolution, through to cyber threat analysis and detection...Remote work
$195k - $240k
...massive cloud-native environment, and we expect our offensive engineers to build the tooling that makes that possible. We're... ...capabilities tailored to Datadog's environment and modern defensive controls (EDR, SIEM, network monitoring) Improve the efficiency of...Work at office$100k - $140k
...reading - this may be your next great opportunity. As a Security Engineer, you will be part of BlackCloak’s internal technology team... ...new Security Tools - support administration across tools such as SIEM, EDR, CNAAP, Email Security, and others. Support security and risk...Full timeTemporary workRemote workHome officeFlexible hoursShift work- ...are seeking a skilled Security Operations Engineer to enhance our security monitoring and... ...CrowdStrike, GitHub Experience: 3+ years of cyber security operations, 2+ years of incident... ...blockchain technology at ZetaChain. 2. SIEM Specialist A professional skilled in SIEM...Remote workHome officeShift work
- ...company. We are currently looking for a Senior Security Operations Engineer in the United States. This is a unique opportunity to join a... ...remediation activities. Design, build, and optimize security detections, SIEM rules, SOAR automations, and detection‑as‑code initiatives to...Remote work
- ...drive execution across the SOC function. Key Responsibilities: SIEM/SOAR Operations (Google SecOps) Own the log ingestion pipeline... .../MTTR, and coverage status Manage Google SecOps RBAC Detection Engineering Build and deploy production detection rules mapped to MITRE ATT...Permanent employmentRemote workFlexible hours
$165k - $200k
...around the world. The Security Operations team owns incident response, threat detection, SIEM engineering, log management, and third-party security risk forming the frontline defense for StubHub's global operations. As a Security Operations Engineer you will bring deep...Work at officeRemote workWorldwideFlexible hours$90k - $150k
...Team8- Cyber Startup -Customer Operations Engineer Description Salary range: 90,000 to 150,000 USD annually, depending on experience and qualifications. We are a cybersecurity startup building next generation technology for global customers. We are looking for a hands...Remote workMonday to Friday$192k - $240k
...Security Operations Engineer Brex is the intelligent finance platform that enables companies to spend smarter and move faster in more... ...some of the security services and tools owned by the team (e.g. - SIEM, data pipelines, SOAR, domain monitoring, endpoint tooling,...Work experience placementWork at officeRemote workWork from home$109k - $160k
...Security Operations Engineer Livingston, NJ CoreWeave is The Essential... .... Utilize and query SIEM, EDR, and other security tooling... ...recommendations for improving security defenses across engineering, operations... ..., Computer Engineering, Cyber Security, Information...Permanent employmentTemporary workCasual workWork at officeRemote workFlexible hoursNight shiftWeekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Defense Engineer - SIEM. Be the first to apply!
- sr information security engineer New York, NY
- senior application security engineer New York, NY
- associate security engineer New York, NY
- azure security engineer New York, NY
- principal security engineer New York, NY
- security engineering manager New York, NY
- aws cloud security engineer New York, NY
- dlp security engineer New York, NY
- entry level security engineer New York, NY
- lead security engineer New York, NY

