Cyber Defense Engineer - SIEM
Core
Architecting, developing, and implementing advanced security solutions using AI/ML to enhance cyber defense investigations and incident response capabilities within a SIEM/SOAR platform.
Role type
Senior IC Cyber Defense Engineer (SIEM/AI)
Builds
AI-enhanced detection systems, automation pipelines, and intelligent response playbooks for the organization's security operations.
Domain
Cybersecurity, Artificial Intelligence, Machine Learning, SIEM Engineering
Deliverable
production ML models
Required skills
SIEM engineering, AI/ML integration, anomaly detection, behavioral analytics, threat correlation, API development, scripting (KQL, Python, Powershell), log ingestion, Microsoft security stack (Sentinel, Defender)
Preferred skills
Multi-tenant or MSP environment experience
Technologies
Microsoft Sentinel, Defender suite, KQL, Python, Powershell
Responsibilities
Design and deploy AI-enhanced detections and automations to reduce alert fatigue; Engineer and optimize SIEM pipelines for anomaly detection and threat correlation; Integrate SIEM with security tools to build a context-rich monitoring ecosystem; Develop AI-assisted threat detection models including UEBA and predictive analytics; Build automated response orchestration and intelligent playbooks; Partner with IT teams to ensure comprehensive telemetry collection and high-quality data pipelines.
Seniority
Mid-Senior, hands-on IC