SIEM Engineer III

Fairfax, VA, US • Posted 1 hour ago • Updated 1 hour ago
Full Time
On-site
USD $120,000.00 - 170,000.00 per year
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Event Management
  • Performance Tuning
  • Aggregator
  • Data Integration
  • Extract
  • Transform
  • Load
  • Data Collection
  • Lifecycle Management
  • Storage
  • Root Cause Analysis
  • Configuration Management
  • IT Management
  • Engineering Support
  • Knowledge Transfer
  • Documentation
  • Standard Operating Procedure
  • Vendor Management
  • Continuous Improvement
  • Operational Efficiency
  • Computer Science
  • Information Security
  • Systems Engineering
  • Normalization
  • Data Quality
  • Microsoft Windows
  • Linux
  • Operating Systems
  • Computer Networking
  • Amazon Web Services
  • Microsoft Azure
  • Google Cloud Platform
  • Google Cloud
  • Scripting
  • Python
  • Windows PowerShell
  • Bash
  • SPL
  • Elasticsearch
  • Problem Solving
  • Conflict Resolution
  • Security Operations
  • Mentorship
  • Communication
  • Technical Writing
  • Scalability
  • Security Clearance
  • Incident Management
  • System On A Chip
  • Splunk
  • Microsoft
  • Migration
  • Network Security
  • Cloud Security
  • Threat Analysis
  • Vulnerability Management
  • Management
  • Ansible
  • Terraform
  • Progress Chef
  • Puppet
  • Network Design
  • Network
  • Routing
  • Firewall
  • Proxies
  • Project Management
  • Agile
  • Change Management
  • Machine Learning (ML)
  • Analytics
  • SIEM
  • Cloud Computing
  • Security Engineering
  • System Integration Testing
  • Lighting
  • SAP BASIS
  • Law
  • Artificial Intelligence
  • Cyber Security
  • Partnership
  • Innovation
  • Accountability

Summary

Job Description

Everforth ECS is seeking a SIEM Engineer III to join our team remotely.

At ECS Federal, we're driven by a commitment to excellence and innovation in solving complex challenges. As a premier provider of advanced technology solutions and services, our mission is to secure and optimize the most critical commercial, government, defense, and intelligence projects across the country. Our team is composed of dynamic professionals who thrive in a collaborative and empowering environment, where our team members leverage the latest technologies and insights to make a real-world impact. Join us and be part of a forward-thinking organization that values your expertise and supports your professional growth.

The SIEM Engineer III is responsible for engineering, implementing, maintaining, and optimizing enterprise Security Information and Event Management (SIEM) platforms and the supporting infrastructure that enables effective security monitoring and incident response operations. This role works closely with Security Engineering teams, SOC analysts, enterprise IT teams, platform owners, vendors, and client organizations to ensure the reliability, scalability, security, and operational effectiveness of SIEM capabilities. The SIEM Engineer III serves as a senior technical resource for complex SIEM initiatives, including platform deployments, upgrades, data source integrations, infrastructure migrations, performance optimization, automation, and troubleshooting. This role will also provide technical guidance to junior engineers and contribute to the continuous improvement of SIEM engineering processes, documentation, and operational standards.

Responsibilities
  • SIEM Platform Engineering: Engineer, deploy, configure, maintain, and optimize enterprise SIEM platforms such as Elastic Security, CrowdStrike Falcon Next-Gen SIEM, Splunk Enterprise Security, Microsoft Sentinel, or similar technologies across cloud, on-premises, and hybrid environments.
  • SIEM Infrastructure Management: Support the underlying infrastructure and components required for SIEM operations, including collectors, aggregators, data nodes, forwarders, agents, connectors, APIs, and other supporting services.
  • Log Source & Data Integration: Design, configure, and maintain integrations for security telemetry from endpoints, network devices, firewalls, identity platforms, cloud environments, applications, operating systems, and other enterprise technologies.
  • Data Pipeline Engineering: Configure and troubleshoot data collection, forwarding, parsing, normalization, enrichment, filtering, and routing to ensure security telemetry is reliably delivered and usable within supported SIEM platforms.
  • Platform Maintenance & Upgrades: Perform SIEM platform upgrades, patches, configuration changes, migrations, and lifecycle management activities while minimizing operational disruption and maintaining security visibility.
  • Performance & Health Monitoring: Conduct routine health checks and proactively monitor SIEM infrastructure, ingestion pipelines, storage, system performance, capacity, and availability. Identify and remediate issues before they impact security operations.
  • Complex Troubleshooting: Serve as a senior escalation point for complex SIEM infrastructure, integration, ingestion, and platform issues. Lead root-cause analysis and coordinate resolution with internal teams and technology vendors when necessary.
  • Configuration Management: Maintain and optimize SIEM configurations to support changing environments, new data sources, platform requirements, and operational needs while following established change-management processes.
  • Security Operations Support: Partner with SOC analysts and other cybersecurity teams to ensure required telemetry and SIEM capabilities are available to support monitoring, investigation, threat hunting, incident response, and other security operations.
  • Client & Stakeholder Support: Work directly with internal stakeholders and client organizations to understand technical requirements, coordinate SIEM engineering activities, communicate risks or dependencies, and support successful implementation of security monitoring capabilities.
  • Technical Leadership & Mentoring: Provide technical guidance and mentorship to junior SIEM engineers, support knowledge transfer, and assist with troubleshooting and complex engineering activities without serving as the team's formal people manager.
  • Documentation: Develop and maintain detailed technical documentation, including architecture diagrams, integration procedures, configuration standards, troubleshooting guides, operational runbooks, and standard operating procedures.
  • Vendor Management: Engage SIEM and security technology vendors to troubleshoot complex issues, evaluate platform capabilities, coordinate support cases, and assist with implementation or upgrade activities.
  • Continuous Improvement: Identify opportunities to improve SIEM reliability, scalability, automation, operational efficiency, and engineering processes across supported environments.

Education Requirements
  • Bachelor's degree in computer science, information security, or a related field. Will consider experience in lieu of a degree.

Salary Range: $120,000 - $170,000

General Description of Benefits

Required Skills

  • At least five years of relevant cybersecurity, SIEM, security engineering, or systems engineering experience, with demonstrated experience supporting enterprise security monitoring technologies.
  • Strong knowledge of SIEM concepts and hands-on experience with one or more enterprise SIEM platforms such as Elastic Security, CrowdStrike Falcon Next-Gen SIEM, Splunk Enterprise Security, Microsoft Sentinel, or comparable technologies.
  • Demonstrated experience deploying, configuring, maintaining, upgrading, and troubleshooting enterprise SIEM platforms and supporting infrastructure.
  • Experience integrating enterprise data sources and security technologies into SIEM platforms, including troubleshooting ingestion, connectivity, parsing, normalization, and data quality issues.
  • Strong understanding of Windows and Linux operating systems and the infrastructure, networking, and security concepts required to support enterprise SIEM environments.
  • Working knowledge of cloud environments and cloud-based security telemetry, including platforms such as AWS, Microsoft Azure, and/or Google Cloud.
  • Proficiency with scripting or automation technologies such as Python, PowerShell, Bash, REST APIs, or similar technologies.
  • SIEM Query Languages: Proficiency with SIEM search, query, and analytics languages such as KQL, SPL, CQL, EQL, ES|QL, or similar technologies used to search, analyze, and troubleshoot security telemetry.
  • Strong troubleshooting and problem-solving skills with the ability to independently investigate and resolve complex technical issues.
  • Comprehensive understanding of cybersecurity concepts, security monitoring, common attack methodologies, and the role of SIEM technologies within security operations.
  • Ability to lead complex technical efforts and provide guidance and mentorship to junior engineers.
  • Strong verbal and written communication skills, including the ability to create technical documentation and communicate complex technical concepts to both technical and non-technical stakeholders.
  • Ability to think strategically about SIEM technologies and identify opportunities to improve platform reliability, scalability, automation, and overall security capabilities using traditional methods and/or AI driven technologies.

Other Requirements of the position include:
  • Able and willing to obtain a US Security Clearance.
  • On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capabilities.


Desired Skills

  • Advanced hands-on experience with one or more SIEM platforms, including Elastic Security, CrowdStrike Falcon Next-Gen SIEM, Splunk Enterprise Security, Microsoft Sentinel, or similar enterprise SIEM technologies.
  • Experience administering SIEM environments in both cloud-hosted and self-managed/on-premises architectures.
  • Experience with SIEM migrations, infrastructure modernization, platform upgrades, or large-scale data source migrations.
  • Experience integrating SIEM platforms with EDR/XDR, SOAR, identity security, network security, cloud security, threat intelligence, vulnerability management, and other cybersecurity technologies.
  • Experience with configuration and infrastructure management technologies such as Ansible, Terraform, Chef, Puppet, or similar tools.
  • Experience working with APIs and developing automation to support security engineering and SIEM operations.
  • Understanding of advanced network infrastructure, including cloud networks, virtual networks, network segmentation, routing, firewalls, proxies, and load balancers.
  • Experience supporting SIEM platforms within a managed security services or multi-client environment.
  • Experience with project management methodologies such as Agile and working within formal change-management processes.
  • Familiarity with machine learning, AI-assisted security analytics, and emerging capabilities within modern SIEM platforms.
  • Relevant industry or vendor certifications associated with SIEM, cloud, cybersecurity, or security engineering technologies.
Physical Demands
  • While performing the duties of this job, the employee is regularly required to sit at a desk and use a computer for extended periods.
  • The position is generally sedentary but may require walking or standing for brief periods of time.
  • Employee may occasionally be required to move, carry, push, pull and/or lift objects up to 10 pounds.
Work Environment
  • Job is performed in an office place setting.
  • The noise level in the work environment is generally very low with minimal background noise.
  • Comfortable climate control and adequate lighting.

#EverforthECS1

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We value:
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10112MAN
  • Position Id: 5009
  • Posted 1 hour ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Washington, District of Columbia

Today

Full-time

Fort Belvoir, Virginia

Today

Full-time

USD 171,300.00 - 205,100.00 per year

Washington, District of Columbia

Today

Full-time

Washington, District of Columbia

Today

Full-time

USD 80,001.00 - 120,000.00 per year

Search all similar jobs