Sr. Security Engineer - SIEM & NDR
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, Systems Engineer
Company Overview
KLA is a global leader in diversified electronics for the semiconductor manufacturing ecosystem. Virtually every electronic device in the world is produced using our technologies. No laptop, smartphone, wearable device, voice-controlled gadget, flexible screen, VR device or smart car would have made it into it without us. KLA invents systems and solutions for the manufacturing of wafers and reticles, integrated circuits, packaging, printed circuit boards and flat panel displays.
The innovative ideas and devices that are advancing humanity all begin with inspiration, research and development. KLA focuses more than average on innovation and we invest 15% of sales back into R&D. Our expert teams of physicists, engineers, data scientists and problem-solvers work together with the world’s leading technology providers to accelerate the delivery of tomorrow’s electronic devices. Life here is exciting and our teams thrive on tackling really hard problems.
There is never a dull moment with us.
The Cybersecurity group at KLA is involved in every aspect of the global business. The KLA Cybersecurity group defends against cyber-attacks and provides cybersecurity tools, incident response services and assessment capabilities to safeguard the environments that support the essential operations of KLA. We are passionate about identifying adversarial activities and anticipating a wide variety of threats to strengthen our defenses and the overall protection of KLA Intellectual Property.
We are seeking an experienced and highly motivated Senior Security Engineer to join our Cyber Operations team. This role will focus on the engineering, implementation, and operational support of our Security Information and Event Management (SIEM) and Network, Detection & Response (NDR) platforms. The successful candidate will play a critical role in advancing our organization's threat detection and response capabilities through expert management of security technologies and collaborative engagement with various cybersecurity stakeholders.
ResponsibilitiesDesign, implement, and maintain the Google Sec Ops SIEM platform, including log ingestion, parsing, rule creation, and dashboard development.
Leverage modern data-pipeline management and log-reduction technologies to improve data ingestion efficiency and optimize storage management.
Build and maintain system health checks, high-availability configurations, and reliable log-pipeline workflows.
Collaborate with customers to understand their security operations needs and develop tailored SIEM strategies and roadmaps.
Enable customers to fine-tune detection logic, correlation rules, and alerting mechanisms to maximize effectiveness and minimize noise.
Integrate SIEM platforms with broader security ecosystems including SOAR, EDR, threat intelligence, and cloud-native security tools.
Continuously optimize detection rules, use cases, UEBA analytics, and SOAR playbooks to enhance threat visibility and reduce false positives.
Develop and maintain documentation for SIEM/NDR architecture, configurations, and operational procedures.
Monitor, troubleshoot, and resolve issues related to SIEM and NDR platform availability, performance, and data quality.
Stay current with emerging threats, vulnerabilities, and advancements in security technologies to recommend improvements.
Support compliance and audit activities by ensuring proper log retention, data integrity, and access controls.
Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience
Five (5) years of hands-on cybersecurity engineering experience focusing on SIEM platforms in large enterprise environments
Three (3) years of proven experience in Google Sec Ops SIEM administration, engineering, and integration
Three (3) years of experience working with Vectra or a similar NDR platform
Expert-level understanding of security telemetry, including logs from firewalls, endpoints, cloud services, identity providers, and applications
This is a Hybrid role and will be based out of our Midwest HQ in Ann Arbor, MI
Base Pay…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).