Cyber Defense Engineer - SIEM
Listed on 2026-08-11
-
IT/Tech
Cybersecurity, AI Engineer (Applied/Software)
the company
northmark strategies is a leading investment firm, combining capital, innovation, and engineering to drive long-term value. From operating complex businesses to backing breakthrough technologies, our mission is to build enduring businesses. Our team combines intelligent risk-taking, operational excellence, exceptional talent, and world-class computing capacity to create shareholder value.
our company offers a dynamic environment where individuals have the freedom to lead companies toward bold achievements by embracing innovation, leveraging technology, and fostering differentiated business strategies. Our values are integrity, ability, and energy, and the company aims to hire individuals who possess those qualities.
at northmark strategies, we believe the future isn’t something to hope for, it’s something to build. We don’t just invest, we create. Bringing together strategic insight and technical horsepower to deliver outcomes that endure.
the positionthe cyber defense engineer – siem reports to the director of cyber defense and operates within the office of the ciso. This role is responsible for architecting, developing, and implementing advanced security solutions that enhance cyber defense investigations and incident response capabilities.
this position places a strong emphasis on ai-driven security engineering, including the development of intelligent detection systems, automation pipelines, and data-driven defense mechanisms. The ideal candidate will combine deep expertise in the microsoft security ecosystem with experience leveraging artificial intelligence and machine learning to improve siem/soar performance, detection fidelity, and operational efficiency.
you will collaborate across it and security teams to design scalable logging, enrichment, and response architectures, while continuously advancing the organization’s ai-enabled siem engineering maturity.
responsibilitiesdesign, develop, and deploy ai-enhanced detections and automations within the siem/soar platform to improve signal-to-noise ratio and reduce alert fatigue.
- engineer and optimize siem pipelines using ai/ml techniques for anomaly detection, behavioral analytics, and threat correlation.
- integrate siem with security tools and data sources to build a context-rich, intelligence-driven monitoring ecosystem.
- develop and implement ai-assisted threat detection models, including user/entity behavior analytics (ueba) and predictive analytics.
- collaborate with cyber defense operations to identify emerging threats and capability gaps, leveraging ai to proactively strengthen defenses.
- build and maintain automated response orchestration and intelligent playbooks that adapt based on threat context.
- design automation for alert enrichment, triage, and response using both rule-based and ai-assisted decisioning frameworks.
- partner with it and engineering teams to ensure comprehensive telemetry collection and high-quality data pipelines.
- continuously improve siem engineering practices, including data normalization, enrichment strategies, and ai model tuning.
- support soc operations by enhancing detection engineering, incident response workflows, and operational metrics through ai augmentation.
- bachelor’s degree in computer science, information security, or a related field.
- 4–6+ years of experience in cybersecurity engineering, soc engineering, or insider threat.
- demonstrated expertise in siem engineering and security monitoring at scale.
- experience integrating or developing ai/ml capabilities within security operations or detection engineering.
- strong understanding of the microsoft security stack (e.g., sentinel, defender suite)
- proficiency with automation tooling and scripting languages (kql, python, powershell)
- proficiency in api development with the goal of integrating security tooling
- familiarity with various log ingestion methodologies into a siem environment.
- experience in multi-tenant or msp like environments a plus
- highly motivated self-starter who thrives on positively influencing the environment.
it is impossible to list every requirement for, or responsibility of, any position. Similarly, we cannot identify all the skills a…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).