SIEM Infrastructure and Detection Engineer

Portland, OR, US • Posted 5 hours ago • Updated 5 hours ago
Full Time
On-site
Fitment

Dice Job Match Score™

🎯 Assessing qualifications...

Job Details

Skills

  • Energy
  • Information Security
  • Continuous Monitoring
  • IDS
  • IPS
  • Firewall
  • TIP
  • Dashboard
  • High Availability
  • Collaboration
  • Reporting
  • Documentation
  • Standard Operating Procedure
  • Design Of Experiments
  • Security Clearance
  • IBM QRadar
  • LogRhythm
  • Onboarding
  • Network
  • SaaS
  • Scripting
  • Python
  • Windows PowerShell
  • Bash
  • Data Integration
  • Configuration Management
  • Ansible
  • Terraform
  • Progress Chef
  • Puppet
  • Microsoft
  • Trend Micro
  • SIEM
  • Clustering
  • Regulatory Compliance
  • TAS
  • Elasticsearch
  • Kibana
  • Management
  • Vulnerability Management
  • Configuration Management Database
  • Cloud Computing
  • Orchestration
  • Cloud Security
  • Amazon Web Services
  • Microsoft Azure
  • Google Cloud
  • Google Cloud Platform
  • ICS
  • NIST SP 800 Series
  • Clinical Data Management
  • Splunk
  • CISSP
  • SAP BASIS
  • Law
  • Artificial Intelligence
  • Cyber Security
  • Partnership
  • Innovation
  • Accountability

Summary

Job Description

Everforth ECS is seeking an SIEM Infrastructure and Detection Engineer to join our team in our Portland, OR (Hybrid) office.

The SIEM Infrastructure and Detection Engineer supports a federal energy sector cybersecurity program by engineering, maintaining, and optimizing the SIEM infrastructure and security monitoring platform, including detections, visualizations, dashboards, and reporting. This role ensures the reliability and effectiveness of SIEM and related monitoring tools to meet Information Security Continuous Monitoring (ISCM) and Department of Homeland Security (DHS) Continuous Diagnostics and Mitigation (CDM) requirements. The engineer works directly with security analysts, system owners, and DHS CDM teams to ensure continuous visibility, timely detection, and compliance with federal cybersecurity standards.

Core Capabilities
  • Lead the design, deployment, and monitoring of enterprise SIEM platforms (e.g., Splunk, Elastic Stack)
  • Architect, implement, and maintain integrations with enterprise systems, cloud environments, and security tools (e.g., EDR, IDS/IPS, firewalls, TIP)
  • Develop and optimize dashboards, alerts, and data pipelines
  • Automate platform tasks and SIEM processes using scripting (e.g., Python, PowerShell, bash)
  • Monitor and tune platform performance to ensure high availability and accuracy of security data
  • Troubleshoot and resolve platform-related issues in coordination with analysts and engineers
  • Collaborate with federal stakeholders to align SIEM capabilities with ISCM and CDM reporting requirements
  • Maintain documentation of platform configurations, standard operating procedures, and system baselines


Required Skills

  • U.S. Citizenship with ability to obtain and maintain a DOE "L" clearance
  • Hands-on experience with at least one enterprise SIEM platform (Splunk, Elastic, QRadar, or LogRhythm)
  • Experience integrating SIEM with enterprise IT systems, cloud platforms, or endpoint detection tools
  • Experience onboarding diverse log sources (network, endpoint, cloud, SaaS) and tuning correlation rules
  • Proficiency in scripting (Python, PowerShell, or Bash) for automation and data integration
  • Experience with configuration management tools (e.g., Ansible, Terraform, Chef, Puppet)
  • Experience with Application Control (Carbon Black) and Endpoint Detection and Response platforms (Microsoft Defender, CrowdStrike, Trend Micro)
  • Minimum 5 years of experience in cybersecurity engineering and security monitoring, including 3+ years dedicated to SIEM engineering


Desired Skills

  • Advanced Splunk engineering experience (indexer/search head clustering, CIM compliance, custom TAs)
  • Experience with Elastic Stack (Elasticsearch, Logstash, Kibana) deployment and management
  • Hands-on experience with Axonius administration and integration across vulnerability management, CMDB, cloud, and, security tooling.
  • Familiarity with SOAR integration and orchestration for automated response
  • Familiarity with Zero Trust principles and cloud security architectures (AWS, Azure, Google Cloud Platform)
  • Exposure to OT/ICS environments within critical infrastructure
  • Strong understanding of federal cybersecurity frameworks (e.g., NIST SP 800-53, ISCM, CDM)
  • Relevant certifications such as Splunk Certified Admin, Elastic Engineer, or CISSP

#EverforthECS1

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We value:
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10112MAN
  • Position Id: 3894
  • Posted 5 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Portland, Oregon

Today

Full-time

Portland, Oregon

Today

Full-time

Portland, Oregon

Today

Full-time

Portland, Oregon

Today

Full-time

Search all similar jobs