SIEM Engineer
Listed on 2026-07-17
-
IT/Tech
Cybersecurity, Security Management & Operations, Network Security, Systems Engineer
Zachary Piper Solutions is seeking a SIEM Engineer to join a federal technology services organization supporting enterprise cybersecurity operations and mission-critical security programs. This role is on-site in Newington, VA and requires an active TS/SCI clearance.
This role will involve designing, implementing, tuning, and optimizing Splunk Enterprise and Splunk Enterprise Security to strengthen enterprise security monitoring, threat detection, incident response, and SIEM operations while partnering with security engineering, SOC, threat intelligence, and infrastructure teams to enhance overall cybersecurity visibility and resilience.
Responsibilities of the SIEM Engineer:- Design, implement, configure, and maintain Splunk Enterprise and Splunk Enterprise Security to support enterprise-scale security monitoring and threat detection.
- Develop, optimize, and tune SIEM use cases, correlation searches, detection rules, dashboards, and alerts to improve detection accuracy and reduce false positives.
- Analyze and correlate security events across Windows, Linux, firewalls, IDS/IPS, cloud platforms, and other enterprise log sources to identify threats and support incident response.
- Manage log ingestion, normalization, retention, and event correlation to ensure effective SIEM operations and data visibility.
- Partner with SOC analysts, security engineers, threat intelligence, and IT infrastructure teams to improve monitoring capabilities and overall security posture.
- Support cybersecurity investigations by identifying, analyzing, and responding to security events across multiple data sources.
- Implement automation and scripting solutions using Python, Bash, or Power Shell to improve operational efficiency and SIEM functionality.
- Support continuous improvement initiatives by integrating threat intelligence, cloud security monitoring, SOAR capabilities, and cybersecurity best practices into the enterprise security platform.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience).
- 3+ years of experience in SIEM engineering, cybersecurity monitoring, or security analytics.
- Hands‑on experience with Splunk Enterprise Security, Splunk Enterprise, or other SIEM platforms such as IBM QRadar.
- Experience with log management, event correlation, alert tuning, SIEM use case development, and detection engineering.
- Strong understanding of Windows, Linux, firewall, IDS/IPS, cloud, and other enterprise security logs.
- Experience with Python, Bash, or Power Shell, along with knowledge of TCP/IP, DNS, HTTP/S, and cybersecurity frameworks including NIST and MITRE ATT&CK.
- Experience with AWS, Azure, or GCP security monitoring, SOAR platforms, threat intelligence integration, and supporting federal or DoD cybersecurity environments is preferred.
- Active TS/SCI security clearance.
- Salary Range: $180,000 - $195,000
* depending on experience* - Comprehensive Benefits:
Cigna Medical, Dental, Vision, 401k Plan, PTO, Holidays, Sick Leave if required by law
This job opens for applications on 07/14. Applications for this job will be accepted for at least 30 days from the posting date.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).