Назад
Company hidden
3 дня назад

Senior Cyber Security Engineer - SIEM and Automation

168 000 - 195 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Cyber Security Engineer - SIEM and Automation (SIEM/Detection Engineering): Developing high-fidelity SIEM use cases, integrating security data sources, and optimizing alerting with an accent on MITRE ATT&CK alignment, logging quality, and actionable detection. Focus on building detection logic, onboarding and normalizing telemetry, tuning alerts, and supporting SOAR-driven security automation.

Location: Hybrid work from hirify.global offices in Woodland Hills, California; Jersey City, New Jersey; or Houston, Texas. Estimated travel may be up to 25%. Relocation is not provided.

Salary: $168,000–$195,000 annually, plus eligibility for a discretionary bonus.

Company

hirify.global provides financial products and services in partnership with financial professionals and institutions.

What you will do

  • Design, develop, and maintain SIEM detection use cases aligned with MITRE ATT&CK and threat intelligence.
  • Translate threat scenarios into detection logic, correlation rules, and improved detection coverage.
  • Define logging requirements and analyze telemetry across cloud, endpoint, network, and application layers.
  • Integrate EDR, IAM, firewall, SaaS, and other data sources using APIs, agents, and log pipelines.
  • Tune alerts, reduce false positives, and implement risk-based prioritization strategies.
  • Optimize SIEM performance, scalability, and cost efficiency while developing dashboards and supporting SOAR integrations.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, or a related field, or equivalent experience.
  • 3–7+ years of experience in SIEM engineering, detection engineering, or security operations.
  • Hands-on experience with Splunk, Microsoft Sentinel, QRadar, Elastic, or comparable SIEM platforms.
  • Strong understanding of Windows, Linux, cloud, and network-device log sources.
  • Experience with SPL, KQL, Lucene, SQL, data-source onboarding, and log parsing.
  • Knowledge of MITRE ATT&CK, threat detection methodologies, and adversary tactics and techniques.

Nice to have

  • Experience with SOAR platforms, security automation, and detection-as-code.
  • Familiarity with AWS, Azure, GCP, and native cloud logging tools.
  • Scripting or programming experience with Python or PowerShell.
  • Security certifications such as GCIA, GCIH, CISSP, Splunk Certified, or Microsoft SC-200.

Culture & Benefits

  • Hybrid work combining office and remote work.
  • Medical, dental, vision, mental health, and wellness support.
  • U.S. 401(k) contributions, including matching and company contributions subject to plan terms.
  • At least 24 paid time off days for eligible employees.
  • Employee assistance, charitable donation matching, and up to 16 hours of annual volunteer time off.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →