CareerPlanSign in

Senior Associate SIEM Implementation

Toronto, CA💼 Full-time💰 $84,700–$84,700🗓 2026-09-25

Core

Lead technical deliverables for SIEM implementation and operations, including log ingestion, use case development, and SOAR workflow automation for cloud and on-prem environments.

Role type

Senior IC cybersecurity engineer (SIEM/SOAR)

Builds

Production SIEM platforms (Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, Devo, Splunk) and automated detection workflows

Domain

Cybersecurity, Cloud Security, Security Operations

Deliverable

production ML models | product features | dashboards & analysis | infrastructure

Required skills

SIEM architecture and implementation, log management, threat detection methodologies, scripting (Python, PowerShell, Bash), cloud platforms (Azure, GCP, AWS), data pipeline tools (Cribl, DataBahn), SOAR playbook development, CI/CD practices for security content, REST APIs, JSON

Preferred skills

AI concepts and tools for security use cases, consulting/client delivery experience

Technologies

Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, Devo, Splunk, Logic Apps, Phantom, Demisto, XSOAR, GitHub, DataBahn

Responsibilities

Lead technical deliverables for SIEM implementation and security operations engagements, Perform Proof of Concept (PoC) and Proof of Value (PoV) engagements, Conduct SIEM assessments to identify gaps and recommend improvements, Develop and maintain data pipelines for log ingestion and enrichment, Integrate log sources using connectors and custom scripts, Build use cases aligned with NIST and MITRE ATT&CK frameworks, Implement detection rules using SPL/KQL, Develop dashboards, alerts, and workbooks for security monitoring, Implement SOAR workflows using Logic Apps, Phantom, Demisto, and XSOAR platforms, Perform health checks, tuning, and optimization of SIEM platforms, Create and maintain documentation including SOPs, runbooks, and architecture diagrams, Collaborate with cross-functional teams including SOC, threat hunters, infrastructure, and cloud teams, Lead technical deliverables for SIEM implementation and security operations engagements, Develop and support custom integrations to SIEM platforms, Apply AI capabilities in a security-focused manner to improve detection engineering and operational efficiency

Seniority

Senior, hands-on IC

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.