Security Information and Event Management (SIEM) Engineer – Senior Consultant
Core
Lead the design, implementation, and continuous improvement of SIEM capabilities for a federal law enforcement agency's classified environment, combining hands-on engineering with client-facing consulting.
Role type
Senior IC Security Consultant (SIEM)
Builds
Production SIEM monitoring solutions, detection use cases, and incident response support for classified data processing systems.
Domain
Federal Cybersecurity / Classified Environments
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SIEM engineering, log ingestion architecture, correlation rule development, incident response support, stakeholder consulting, team mentoring
Preferred skills
Cloud security integration (AWS/Azure/GCP), SOAR automation, NIST framework alignment, hybrid/zero-trust architecture experience
Technologies
Splunk, Elastic, Sentinel, AWS, Azure, GCP, SOAR
Responsibilities
Lead SIEM strategy workshops and roadmap development; Architect log ingestion pipelines and develop correlation rules; Align monitoring to NIST SP 800-53 and ISCM requirements; Extend SIEM coverage to cloud environments; Integrate SIEM with SOAR and automate enrichment; Establish content lifecycle governance and mentor junior staff.
Seniority
Senior, hands-on IC with strategy & mentorship