RVC
JobsFor Employers
  1. Jobs
  2. /
  3. SIEM Engineer III

SIEM Engineer III

ecsfederal | Information technology and defense services
1h 27m ago
Remote In-Country
Full Time
United States of America
$120k - $170k USD/yr

Everforth ECS is seeking a SIEM Engineer III to join our team remotely.

At ECS Federal, we're driven by a commitment to excellence and innovation in solving complex challenges. As a premier provider of advanced technology solutions and services, our mission is to secure and optimize the most critical commercial, government, defense, and intelligence projects across the country. Our team is composed of dynamic professionals who thrive in a collaborative and empowering environment, where our team members leverage the latest technologies and insights to make a real-world impact. Join us and be part of a forward-thinking organization that values your expertise and supports your professional growth.

The SIEM Engineer III is responsible for engineering, implementing, maintaining, and optimizing enterprise Security Information and Event Management (SIEM) platforms and the supporting infrastructure that enables effective security monitoring and incident response operations. This role works closely with Security Engineering teams, SOC analysts, enterprise IT teams, platform owners, vendors, and client organizations to ensure the reliability, scalability, security, and operational effectiveness of SIEM capabilities. The SIEM Engineer III serves as a senior technical resource for complex SIEM initiatives, including platform deployments, upgrades, data source integrations, infrastructure migrations, performance optimization, automation, and troubleshooting. This role will also provide technical guidance to junior engineers and contribute to the continuous improvement of SIEM engineering processes, documentation, and operational standards.

Responsibilities

  • SIEM Platform Engineering: Engineer, deploy, configure, maintain, and optimize enterprise SIEM platforms such as Elastic Security, CrowdStrike Falcon Next-Gen SIEM, Splunk Enterprise Security, Microsoft Sentinel, or similar technologies across cloud, on-premises, and hybrid environments.
  • SIEM Infrastructure Management: Support the underlying infrastructure and components required for SIEM operations, including collectors, aggregators, data nodes, forwarders, agents, connectors, APIs, and other supporting services.
  • Log Source & Data Integration: Design, configure, and maintain integrations for security telemetry from endpoints, network devices, firewalls, identity platforms, cloud environments, applications, operating systems, and other enterprise technologies.
  • Data Pipeline Engineering: Configure and troubleshoot data collection, forwarding, parsing, normalization, enrichment, filtering, and routing to ensure security telemetry is reliably delivered and usable within supported SIEM platforms.
  • Platform Maintenance & Upgrades: Perform SIEM platform upgrades, patches, configuration changes, migrations, and lifecycle management activities while minimizing operational disruption and maintaining security visibility.
  • Performance & Health Monitoring: Conduct routine health checks and proactively monitor SIEM infrastructure, ingestion pipelines, storage, system performance, capacity, and availability. Identify and remediate issues before they impact security operations.
  • Complex Troubleshooting: Serve as a senior escalation point for complex SIEM infrastructure, integration, ingestion, and platform issues. Lead root-cause analysis and coordinate resolution with internal teams and technology vendors when necessary.
  • Configuration Management: Maintain and optimize SIEM configurations to support changing environments, new data sources, platform requirements, and operational needs while following established change-management processes.
  • Security Operations Support: Partner with SOC analysts and other cybersecurity teams to ensure required telemetry and SIEM capabilities are available to support monitoring, investigation, threat hunting, incident response, and other security operations.
  • Client & Stakeholder Support: Work directly with internal stakeholders and client organizations to understand technical requirements, coordinate SIEM engineering activities, communicate risks or dependencies, and support successful implementation of security monitoring capabilities.
  • Technical Leadership & Mentoring: Provide technical guidance and mentorship to junior SIEM engineers, support knowledge transfer, and assist with troubleshooting and complex engineering activities without serving as the team's formal people manager.
  • Documentation: Develop and maintain detailed technical documentation, including architecture diagrams, integration procedures, configuration standards, troubleshooting guides, operational runbooks, and standard operating procedures.
  • Vendor Management: Engage SIEM and security technology vendors to troubleshoot complex issues, evaluate platform capabilities, coordinate support cases, and assist with implementation or upgrade activities.
  • Continuous Improvement: Identify opportunities to improve SIEM reliability, scalability, automation, operational efficiency, and engineering processes across supported environments.

Education Requirements

  • Bachelor’s degree in computer science, information security, or a related field. Will consider experience in lieu of a degree.

Salary Range: $120,000 - $170,000

General Description of Benefits 

  • At least five years of relevant cybersecurity, SIEM, security engineering, or systems engineering experience, with demonstrated experience supporting enterprise security monitoring technologies.
  • Strong knowledge of SIEM concepts and hands-on experience with one or more enterprise SIEM platforms such as Elastic Security, CrowdStrike Falcon Next-Gen SIEM, Splunk Enterprise Security, Microsoft Sentinel, or comparable technologies.
  • Demonstrated experience deploying, configuring, maintaining, upgrading, and troubleshooting enterprise SIEM platforms and supporting infrastructure.
  • Experience integrating enterprise data sources and security technologies into SIEM platforms, including troubleshooting ingestion, connectivity, parsing, normalization, and data quality issues.
  • Strong understanding of Windows and Linux operating systems and the infrastructure, networking, and security concepts required to support enterprise SIEM environments.
  • Working knowledge of cloud environments and cloud-based security telemetry, including platforms such as AWS, Microsoft Azure, and/or Google Cloud.
  • Proficiency with scripting or automation technologies such as Python, PowerShell, Bash, REST APIs, or similar technologies.
  • SIEM Query Languages: Proficiency with SIEM search, query, and analytics languages such as KQL, SPL, CQL, EQL, ES|QL, or similar technologies used to search, analyze, and troubleshoot security telemetry.
  • Strong troubleshooting and problem-solving skills with the ability to independently investigate and resolve complex technical issues.
  • Comprehensive understanding of cybersecurity concepts, security monitoring, common attack methodologies, and the role of SIEM technologies within security operations.
  • Ability to lead complex technical efforts and provide guidance and mentorship to junior engineers.
  • Strong verbal and written communication skills, including the ability to create technical documentation and communicate complex technical concepts to both technical and non-technical stakeholders.
  • Ability to think strategically about SIEM technologies and identify opportunities to improve platform reliability, scalability, automation, and overall security capabilities using traditional methods and/or AI driven technologies.

Other Requirements of the position include:

  • Able and willing to obtain a US Security Clearance.
  • On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capabilities.

Required Skills

awsbashgcplinuxmicrosoft azureparsingpowershellpythonrestapisiemtechnical_documentationwindows

Required Languages

🇬🇧 English

Related searches

  • Remote Jobs in USA
  • Jobs in USA
  • Remote In-Country Jobs
  • Senior Jobs
1 jobs
Sort by
1h 27m ago

SIEM Engineer III

ecsfederal·Information technology and defense services
$120k - $170k USD/yr
awsbashgcplinux+8
📡Remote In-Country
|United States of America
General InfoSec
No similar jobs match these filters. Try changing or clearing a filter.
Remote roles
PythonJavaReactTypeScriptGoDevOpsNode.jsC# / .NET
Countries
United StatesUnited KingdomCanadaUS & EMEAGermanyPolandSpainNetherlandsPortugal
Experience
SeniorMid-levelJunior
R© 2026 RVC Globalbuild 1c14ed13
AboutPricingContactPrivacyCookiesRefundsTerms & ConditionsFor Employers