Назад
Company hidden
5 часов назад

Managed SIEM Detection Engineer (Cybersecurity)

111 900 - 162 300$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Managed SIEM Detection Engineer (SIEM/Cybersecurity): Delivering detection engineering and SIEM optimization engagements that improve threat coverage, alert fidelity, log ingestion efficiency, and customer security operations with an accent on detection content, platform migrations, and custom log parsing. Focus on translating detection logic across Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, developing SOAR playbooks, and applying MITRE ATT&CK to complex customer environments.

Location: Remote within the United States. Candidates must be authorized to work in the United States. Willingness to travel up to 20% is required.

Salary: $111,900–$162,300 USD base, plus bonus eligibility and equity. The primary target range is $120,000–$140,000 based on experience, skills, and market data.

Company

hirify.global provides cybersecurity services and co-managed security operations, including SIEM and detection engineering capabilities.

What you will do

  • Deliver professional services engagements covering detection strategy, MITRE ATT&CK assessments, SIEM optimization, integrations, SOAR playbooks, and custom log parsing.
  • Develop, validate, and tune detection content for defined security use cases, improving coverage and alert fidelity.
  • Optimize SIEM performance and cost by reducing alert noise and improving log ingestion efficiency.
  • Translate detection logic between SIEM platforms and create parsers for standard and non-standard log sources.
  • Partner with Detection Engineering, the SOC, Sales, and Customer Success to prepare environments for co-managed operations.
  • Build repeatable processes, templates, tooling, and a proprietary detection library while tracking the evolving threat landscape.

Requirements

  • Hands-on expertise with Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development.
  • 3+ years of experience with detection and response tooling, especially SIEM, SOAR, and EDR.
  • 3+ years of writing, deploying, and tuning custom detections using Windows Event Logs, auditd, CloudTrail, and similar datasets.
  • Experience migrating SIEM platforms, translating detection logic, and redirecting log sources.
  • Knowledge of attacker tactics, techniques, MITRE ATT&CK, Windows, macOS, Linux, networking, and cloud IAM.
  • Basic proficiency in Python, Go, or a similar language, plus Git/GitHub experience for detection content and scripts. Must be authorized to work in the United States; immigration visa sponsorship is not available.

Nice to have

  • SIEM or vendor certifications such as Splunk, Microsoft SC-200, or CrowdStrike certifications.
  • Experience with Sigma, platform-agnostic detections, detection-as-code, testing, and CI/CD.
  • GIAC, Security+, or similar security certifications.
  • Bachelor's degree in Computer Science or Information Security.

Culture & Benefits

  • Opportunity to help shape a new professional services function and grow into a leadership role.
  • Exposure to complex SIEM and detection challenges across varied customer environments.
  • Unlimited paid time off, up to 24 weeks of parental leave, and health benefits.
  • Work location flexibility within the United States.
  • Collaboration with Detection Engineering, the SOC, Sales, and Customer Success.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →