Назад
Company hidden
8 часов назад

Senior Security Engineer (Elastic SIEM)

123 000 - 180 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Senior Security Engineer (Elastic SIEM): Building and optimizing scalable detection pipelines and improving telemetry quality with an accent on Detection-as-Code and SIEM platform optimization. Focus on developing high-confidence detections, automating workflows with CI/CD, and mapping coverage to MITRE ATT&CK.

Location: Burlington, MA, USA

Salary: $123,000–$180,000

Company

A global leader in cyber protection providing an AI-powered integrated platform that unifies operations management, cybersecurity, and data protection.

What you will do

  • Own and optimize the Elastic Security platform, including Elasticsearch, Kibana, Fleet, Logstash, and Elastic Agents.
  • Design and maintain ingestion pipelines for cloud, endpoint, network, and application telemetry.
  • Build and maintain a Detection-as-Code pipeline utilizing Git-based workflows and CI/CD automation.
  • Develop and tune high-fidelity detections using EQL and KQL, mapping them to the MITRE ATT&CK framework.
  • Serve as a Tier 2 escalation point for complex security events, performing initial scoping and containment.
  • Collaborate with infrastructure and DevSecOps teams to enhance logging and overall visibility.

Requirements

  • 5+ years of cybersecurity engineering experience.
  • 3+ years of experience in SIEM engineering, detection engineering, or security analytics.
  • Strong hands-on expertise with Elastic Security and the Elastic Stack.
  • Experience implementing Detection-as-Code workflows via Git and CI/CD pipelines.
  • Proficiency in Python and/or PowerShell scripting.
  • Experience with AWS CloudTrail, VPC Flow Logs, and general TCP/IP and DNS attack patterns.

Nice to have

  • SOAR playbook development and automated response workflows.
  • Sigma rule development.
  • Familiarity with the Elastic detection-rules ecosystem.
  • Experience with Terraform or Ansible.
  • Background in SOC or Incident Response.

Culture & Benefits

  • Comprehensive medical, dental, and vision insurance.
  • 401(k) retirement plan with company match.
  • Flexible spending accounts (FSA).
  • Disability and life insurance.
  • Generous vacation policy.
  • Innovative, high-growth environment focused on accountability and impact.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →