Managed SIEM Detection Engineer
Core
Authoring and tuning detection content, optimizing SIEM performance and cost, and migrating detection logic to turn customer SIEMs into effective threat detection tools.
Role type
Senior IC detection engineer (SIEM)
Builds
Detection rules, SOAR playbooks, custom log parsers, and optimized SIEM configurations for co-managed security operations.
Domain
Cybersecurity, SIEM, Threat Detection
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SIEM architecture and data ingestion, detection rule development, SIEM migration between platforms, MITRE ATT&CK framework, Windows/macOS/Linux fundamentals, networking (TCP/IP, OSI), cloud IAM models, Python/Go scripting, Git/GitHub version control
Preferred skills
Sigma rule authoring, detection-as-code practices (CI/CD for rules), vendor certifications (Splunk, Microsoft, CrowdStrike), industry security certifications (GIAC, Security+)
Technologies
Splunk, Microsoft Sentinel, CrowdStrike NG SIEM, SOAR, Git/GitHub, Python, Go
Responsibilities
Author and tune detection content for defined security use cases; Optimize SIEM performance and cost by reducing alert noise and improving ingestion efficiency; Translate detection logic between SIEM platforms and write custom parsers for log sources; Partner with SOC to hand off environments ready for ongoing operations; Contribute to proprietary detection library and develop repeatable processes/templates; Track evolving threat landscape to develop new detections.
Seniority
Senior, hands-on IC