Senior SIEM Engineer
Valiant Solutions
Position Description Valiant Solutions is seeking a Senior SIEM Engineer to join our rapidly growing and innovative cybersecurity team! The Senior SIEM Engineer serves as the technical lead for the design, deployment, tuning, and sustainment of the enterprise Security Information and Event Management (SIEM) platform that supports the client's Security Operations Center (SOC). This role owns the health and performance of the SIEM environment that ingests logs and telemetry across endpoint, network, cloud, operating system, and application layers, and feeds the 24x7x365 monitoring mission. Working alongside SOC analysts, threat hunters, engineering teams, and the client's stakeholders, the Senior SIEM Engineer translates detection requirements into production-ready content, integrates the SIEm with SOAR, EDR, CDM, and identity platforms, and builds the dashboards, correlation searches, and data models that allow Tier 1 through Tier 3 analysts to triage, investigate, and respond to threats within the client's's contractual timeframes. The position requires deep, hands-on SIEM expertise, strong cloud and federal cybersecurity context, and the judgment to balance ingest costs, data quality, detection coverage, and compliance with OMB M-26-14, NIST SP 800-53, NIST SP 800-61, and NIST SP 800-137. Named one of the Best Places to Work in the Washington DC area for 12 consecutive years , Valiant is proud of our employee-centric culture and commitment to excellence. If you are interested in learning more about Valiant and this opportunity, we invite you to apply now! Location: Remote, ideally in the Washington, DC Metro Area. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.
Eligibility Requirements: U.S. Citizenship is required due to federal contract obligations, and applicants must be able to successfully pass a federal background investigation Required Experience:
Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees
Valiant contributes 25% towards Health Coverage for Family and Dependents
100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees
100% Paid Certifications
401K Matching up to 4%
Paid Time Off
Paid Federal Holidays
Wellness & Fitness Program
Valiant University - Online Education and Training Portal
FSA programs for: Medical Costs, Dependent Care, Transit, and Parking
Referral Bonuses Remote Work Policy
Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General's effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients. Equal Employment Opportunity Valiant Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, marital status, or veteran status, in accordance with applicable law. Physical Demands Sitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job. Authorization to Share Resume and Personal Information By submitting your resume for this position, you authorize Valiant Solutions to share your resume, as well as, personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should Valiant Solutions or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents. #LI-KW1
Eligibility Requirements: U.S. Citizenship is required due to federal contract obligations, and applicants must be able to successfully pass a federal background investigation Required Experience:
- Eight or more years of cybersecurity engineering experience, with at least five years dedicated to SIEM architecture, administration, and content development.
- Hands-on experience designing and operating distributed SIEM deployments at enterprise scale, including indexer clusters, search head clusters, heavy and universal forwarders, deployment servers, and license management.
- Demonstrated experience writing, tuning, and optimizing queries, correlation searches, data models, accelerated summaries, lookups, and macros.
- Working knowledge of security focused SIEM components, including notable event framework, risk-based alerting, asset and identity frameworks, and adaptive response actions.
- Experience in onboarding diverse data sources at scale, including operating system logs, network flow and packet data, cloud platform logs (AWS CloudTrail, GuardDuty, VPC Flow, Config), endpoint telemetry, application logs, and identity provider logs.
- Experience integrating SIEM with SOAR platforms, Endpoint Detection and Response tools, Continuous Diagnostics and Mitigation (CDM) data feeds, vulnerability management platforms, and ticketing systems such as ServiceNow.
- Working knowledge of AWS GovCloud services and the design patterns used to forward, normalize, and secure log data from cloud-native sources.
- Familiarity with the MITRE ATT&CK framework and experience translating adversary techniques into SIEM detection content.
- Working knowledge of NIST SP 800-53, NIST SP 800-61, and NIST SP 800-137, and the ability to map SIEM controls and continuous monitoring practices to those frameworks.
- Experience supporting incident response activities, including building investigation dashboards, preserving log evidence, and producing artifacts for post-incident reporting.
- Strong scripting and automation skills in at least one of Python, Bash, or PowerShell, and comfort with version control using Git.
- Beneficial Splunk certifications: Splunk Core Certified Power User and Splunk Enterprise Certified Admin. Splunk Certified Architect, Splunk Enterprise Security Certified Admin, or Splunk Core Certified Consultant is strongly preferred.
- Required to obtain and maintain a Non-Sensitive / High Risk (Public Trust) security clearance at the Tier 4/6c level.
- Strong written and verbal communication skills, with the ability to brief technical findings to SOC leadership, ISSOs, and senior Government officials.
- Lead the architecture, deployment, upgrade, and sustainment of the SIEM environment supporting the client's SOC, including indexer and search head clusters, forwarders, and supporting infrastructure.
- Monitor SIEM platform health, license usage, indexing latency, search performance, and ingest rates, and proactively address capacity, performance, and availability issues.
- Onboard new data sources by defining requirements, configuring inputs and forwarders, building parsing and field extractions, and validating Common Information Model (CIM) compliance.
- Develop, tune, and maintain correlation searches, notable events, dashboards, reports, and data models that support Tier 1 triage within fifteen minutes of detection and Tier 2 analysis within four hours of escalation.
- Build and maintain SOC dashboards that provide real-time visibility into the client's security posture, supporting both day-to-day operations and executive reporting.
- Translate detection requirements from threat hunters, CTI analysts, and engineering teams into production SIEM content mapped to the MITRE ATT&CK framework.
- Integrate SIEM with SOAR, EDR, NDR, DLP, CDM, vulnerability management, and identity platforms to support automated triage, enrichment, and response.
- Reduce false positive rates and alert fatigue by tuning correlation rules, refining thresholds, and applying risk-based alerting techniques.
- Support incident response by building investigation queries, producing timeline reconstructions, preserving evidence, and contributing artifacts to initial incident reports within one hour of confirmation and final reports within seventy-two hours.
- Author and maintain Engineering Design Documents, Standard Operating Procedures, runbooks, and configuration guides for the SIEM environment, and review them on the cadence required by the SOC CONOPS.
- Partner with the Security Architect and engineering leads to align SIEM design with Zero Trust principles, the client's Technology Standards, and the agency's broader cybersecurity reference architecture.
- Manage SIEM-related changes through the client's change control process, including impact assessments, back-out plans, and presentations to the Engineering Review Board and Change Control Board.
- Provide knowledge transfer and informal training to SOC analysts, engineers, and system owners on SIEM usage, search development, and dashboard interpretation.
- Apply secure configuration baselines, role-based access controls, and audit logging to the SIEM environment to meet federal compliance requirements.
- Track and report on SIEM-related metrics, including ingest volume by source, detection coverage by MITRE technique, mean time to detect, and platform availability.
- Stay current on SIEM product roadmap items, new applications and add-ons, and emerging detection techniques, and recommend improvements to the client's SIEM strategy.
Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees
Valiant contributes 25% towards Health Coverage for Family and Dependents
100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees
100% Paid Certifications
401K Matching up to 4%
Paid Time Off
Paid Federal Holidays
Wellness & Fitness Program
Valiant University - Online Education and Training Portal
FSA programs for: Medical Costs, Dependent Care, Transit, and Parking
Referral Bonuses Remote Work Policy
Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General's effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients. Equal Employment Opportunity Valiant Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, marital status, or veteran status, in accordance with applicable law. Physical Demands Sitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job. Authorization to Share Resume and Personal Information By submitting your resume for this position, you authorize Valiant Solutions to share your resume, as well as, personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should Valiant Solutions or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents. #LI-KW1
Vacancy posted 3 hours ago
Similar jobs that could be interesting for youBased on the Senior SIEM Engineer in United States vacancy
$130k - $145k
...Senior Siem Engineer Everforth ECS is seeking a senior siem engineer to work in our washington, dc office. please note: this position is contingent upon contract award. we are seeking a cleared senior siem engineer to support security monitoring, detection engineering...SeniorContract workWork at office$123k - $180k
...Acronis International GmbH is seeking a Senior Security Engineer to lead the Elastic SIEM and Detection Engineering program. The role involves optimizing the Elastic Security platform, enhancing detection strategies, and automating workflows. Candidates should have over...Senior- ...Koitecc Solutions is seeking an experienced IT Security professional based in Plano, Texas, with over 5 years of SIEM/SOAR expertise. The role involves managing and optimizing Splunk for advanced threat detection and incident response, while collaborating with IT teams...Senior
- ...Koitecc Solutions is seeking an experienced IT Security professional in Charlotte, NC, with at least 5 years of expertise in SIEM/SOAR. The role focuses on managing and optimizing Splunk for threat detection and incident response. Ideal candidates will collaborate to...Senior
- ...Norton Healthcare, Inc. is looking for a Senior SIEM Engineer to enhance security monitoring and detection capabilities. This role involves the design and optimization of SIEM ingestion pipelines, mentoring junior staff, and ensuring high-quality telemetry from log sources...SeniorRemote work
- A global professional services firm is seeking a CyberSecurity SIEM Engineer to lead the deployment of security solutions for clients. You will monitor cybersecurity threats and enhance security operations while supporting professional growth through training. Candidates...Senior
- 6AM City, LLC is looking for a Security Engineer Contractor to join their remote team. This role focuses on developing and monitoring SIEM infrastructure and translating threat intelligence into actionable security measures. Ideal for candidates with strong knowledge in...SeniorContract workFor contractorsRemote work
- ...Join a forward-thinking company as a SIEM Platform Specialist, where you will design and deploy cutting-edge security solutions. This role involves working closely with business units to create network hierarchies, troubleshoot SIEM issues, and develop custom API connectors...Senior
- ...Koitecc Solutions is looking for an experienced IT Security professional located in Chandler, Arizona. You will manage and optimize SIEM/SOAR systems such as Splunk for advanced threat detection and incident response in a FinTech environment. The ideal candidate possesses...Senior
- ...CORE & MAIN LP, based in St. Louis, is looking for a Senior Information Security Engineer to enhance security monitoring and cloud IAM controls. The role... ...years of information security experience, expertise with SIEM platforms, and a solid understanding of cloud security...Senior
- A leading global consulting firm is seeking a CyberSecurity SIEM Engineer. This role involves ensuring the security of client operations and requires a strong background in information security systems, including SIEM technologies, and a technical degree. You'll engage...Senior
- ...Koitecc Solutions in Chicago is seeking an experienced IT Security professional to manage SIEM/SOAR platforms, especially Splunk, to enhance threat detection and incident response. Candidates should have over 5 years of experience in security operations and production...Senior3 days per week
- ...Nevada Corporation is looking for a Principal Systems Security Engineer in Lone Tree, CO. This role involves overseeing the cybersecurity... ...vulnerability management, NIST standards, and hands-on experience with SIEM tools. A current Top Secret U.S. Security Clearance is mandatory...Senior
$168k - $195k
...American General Life Insurance Company is looking for a Senior Cyber Security Engineer specializing in SIEM and Automation. The role involves enhancing detection engineering capabilities, developing use cases, and optimizing logging strategies to improve security insights...Senior$77.5k - $140.9k
...take your career wherever you want it to go. Join EY and help to build a better working world. Job Title: CyberSecurity SIEM Engineer (Senior SDC) About the job At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support...SeniorWork experience placementSummer holidayFlexible hours- 060 SAKS & CO LLC is seeking a Detection Engineer in New York. The role involves designing and improving security detections across cloud... ...experience in Security Operations. Skills in AWS, Azure, Python, and SIEM platforms are essential. The position offers a dynamic...Senior
$113k - $188k
...Active Top Secret SCI (TS/SCI) As a Senior Consultant in Guidehouse's cyber practice... ...implementation, and continuous improvement of SIEM capabilities for a federal law... ...environment. You'll combine hands on SIEM engineering with client facing consulting: translating...SeniorTemporary workFlexible hours$125k - $162k
...A defense technology company is seeking a Senior Cybersecurity Engineer to enhance security infrastructure at their Boulder, Colorado office. Candidates should have 4+ years in system administration and cybersecurity, including experience with securing development environments...SeniorWork at officeFlexible hours$168k - $195k
...About The Role We are seeking a highly skilled Senior Cyber Security Engineer – SIEM and Automation to lead and enhance our detection engineering capabilities. This role is responsible for developing high‑fidelity use cases, optimizing logging strategies, integrating security...Senior16 hours- NOVA Corporation is seeking an experienced cybersecurity professional in Dayton, Ohio. This role requires applying expertise in the Risk Management Framework to manage vulnerabilities, ensure compliance, and support security authorizations. The ideal candidate will hold...Senior
- ...A leading Cyber Security company is seeking a highly skilled Senior Security Engineer to join their Managed Security Services team. In this role, you will be responsible for deploying and continuously supporting security solutions, coaching other engineers, and working...SeniorRemote workFlexible hours
$120k - $170k
...Nerdleveltech is seeking a Senior Elastic Engineer to work remotely. This role involves designing, building, and securing multiple Elastic Stack solutions globally in a Federal DoD environment. Successful candidates should have a minimum of Top-Secret clearance, with a...SeniorRemote workFlexible hours$130k - $150k
...A leading technology company is seeking a Senior Security Integration Engineer to join its Huntsville team. In this customer-facing role, you will lead integrations into the Elastic Security Platform and work with clients to optimize security data sources. Candidates...Senior- ...A healthcare data company dedicated to transforming how patients receive care is seeking a Sr. Cyber Threat & Response Engineer. In this role, you will identify, analyze, and mitigate cyber threats, collaborate with a security team, and respond to critical alerts post...SeniorRemote workFlexible hours
- ...GeoControl Systems, Inc is seeking a Senior Security Integration Engineer to work at Schriever Space Force Base or Redstone Arsenal. The ideal candidate will have a strong background in Elastic Stack and enterprise networks, focusing on security telemetry and integration...SeniorFlexible hours
- ...A leading internet intelligence provider is looking for a Senior Integrations Software Engineer to build and maintain robust integrations between its platform and third-party systems. Candidates should have at least 7 years of software engineering experience with strong...SeniorRemote work
- ...Senior Engineer II NG-SIEM EPICS Team Our mission is to make all of our customers' security-relevant data continuously available for automated detection and response, threat hunting, and other Falcon platform use cases. To enable this, the systems behind NG-SIEM (next...SeniorHourly payPermanent employmentTemporary workWork at office
$130k - $150k
...A leading technology firm is seeking a Senior Elastic Stack Data Integration Engineer to support the Missile Defense Agency. The successful candidate will design and maintain ingestion pipelines, ensuring high-quality data delivery and optimizing performance. Experience...Senior- ...A leading benefits organization is seeking a Sr Information Security Operations Engineer to support various information security projects in Salt Lake City, Utah. This role involves defining observability functions, leading incident response efforts, and collaborating...Senior
$55 - $70 per hour
...Description Senior SIEM & Detection Engineer (Contract) Mandatory Shift: 3:00 PM – 11:00 PM EDT Contract Length: 6 months (extension possible) Work Model: Remote Start: ASAP The goal is to leave the environment cleaner, quieter, and more defensible than...SeniorContract workTemporary workImmediate startRemote workShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior SIEM Engineer. Be the first to apply!
Related searches
- senior fund accountant United States
- senior office manager United States
- senior director ecommerce United States
- senior automation controls engineer United States
- senior accounts payable United States
- senior brand designer United States
- senior financial advisor United States
- senior underwriter United States
- senior cost analyst United States
- senior environmental advisor United States

