Security Engineer (SIEM)
Core
Design, implement, and manage security monitoring and detection capabilities within a classified Microsoft Azure environment, focusing on SIEM administration, threat hunting, and incident response.
Role type
Senior IC Security Engineer (SIEM/Detection Engineering)
Builds
Security monitoring dashboards, automated response playbooks, and detection use cases for a classified Azure environment
Domain
Cybersecurity, Cloud Security (Azure), National Security
Required skills
SIEM architecture and configuration, Kusto Query Language (KQL), threat hunting, incident response, security automation (SOAR), MITRE ATT&CK mapping, data ingestion architecture, alert tuning
Preferred skills
Experience with PROTECTED or higher security classifications, ISM and PSPF requirements, Microsoft Defender XDR/Endpoint/Identity/Cloud/Entra ID
Technologies
Microsoft Sentinel, Azure Log Analytics, Azure Logic Apps, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud, Microsoft Entra ID
Responsibilities
Administer and configure Microsoft Sentinel and Azure security monitoring platforms; Design and optimize SIEM detection use cases and analytics rules; Perform alert tuning to reduce false positives; Develop automated response playbooks; Conduct threat hunting activities; Investigate and support response to security incidents; Integrate new data sources to improve visibility
Seniority
Senior, hands-on IC