Senior Associate SIEM Implementation
Core
Lead technical deliverables for SIEM implementation and operations, including log ingestion, use case development, and SOAR workflow automation for cloud and on-prem environments.
Role type
Senior IC cybersecurity engineer (SIEM/SOAR)
Builds
Production SIEM platforms (Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, Devo, Splunk) and automated detection workflows
Domain
Cybersecurity, Cloud Security, Security Operations
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SIEM architecture and implementation, log management, threat detection methodologies, scripting (Python, PowerShell, Bash), cloud platforms (Azure, GCP, AWS), data pipeline tools (Cribl, DataBahn), SOAR playbook development, CI/CD practices for security content, REST APIs, JSON
Preferred skills
AI concepts and tools for security use cases, consulting/client delivery experience
Technologies
Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, Devo, Splunk, Logic Apps, Phantom, Demisto, XSOAR, GitHub, DataBahn
Responsibilities
Lead technical deliverables for SIEM implementation and security operations engagements, Perform Proof of Concept (PoC) and Proof of Value (PoV) engagements, Conduct SIEM assessments to identify gaps and recommend improvements, Develop and maintain data pipelines for log ingestion and enrichment, Integrate log sources using connectors and custom scripts, Build use cases aligned with NIST and MITRE ATT&CK frameworks, Implement detection rules using SPL/KQL, Develop dashboards, alerts, and workbooks for security monitoring, Implement SOAR workflows using Logic Apps, Phantom, Demisto, and XSOAR platforms, Perform health checks, tuning, and optimization of SIEM platforms, Create and maintain documentation including SOPs, runbooks, and architecture diagrams, Collaborate with cross-functional teams including SOC, threat hunters, infrastructure, and cloud teams, Lead technical deliverables for SIEM implementation and security operations engagements, Develop and support custom integrations to SIEM platforms, Apply AI capabilities in a security-focused manner to improve detection engineering and operational efficiency
Seniority
Senior, hands-on IC