Principal SIEM Engineer - Remote
Los Angeles, Los Angeles County, California, 90079, USA
Listed on 2026-10-03
-
IT/Tech
Cybersecurity
The Principal SIEM Engineer is part of the Operations, Intelligence and Services (OIS) department, which resides on the Engineering team and reports to the Senior Director, Operations, Intelligence and Services. This is a senior, hands‑on individual contributor role on the SIEM and SOAR Engineering team. As our Principal SIEM Engineer, you will build and run the platform CIS’s Security Operations Center (SOC) works in: SIEM configuration and log source onboarding, SOAR case management and playbook automation, detection content, and troubleshooting of the ingestion and case creation pipeline from the collector through to the case an analyst opens.
This role requires hands‑on engineering in our SIEM and SOAR platform day to day. This role is also the terminal technical escalation point for the platform, which means owning a problem through to resolution rather than routing it onward, including holding the vendor accountable when the defect originates on their side. CIS provides support to U.S. State, Local, Tribal, and Territorial (SLTT) organizations through a set of cybersecurity solutions (IDS, PDNS, endpoint, and Managed Detection and Response) that feed data to CIS’s SOC, including support for organizations we define as underserved, those with very limited resources that are not well served by current commercial providers.
Those services keep growing in both volume and variety. Every managed service customer arrives with log sources that must be collected, parsed, tagged, validated, alerted on, and automated before the SOC can work them, and much of that is built per log source rather than once per customer. The person in this role must be able to carry a problem across the whole pipeline rather than hand it to a specialist.
You’ll Do
- Develop and maintain SOAR content in our platform, including case management configuration, escalation playbooks, and automations.
- Author and version playbook templates, including bulk escalation templates spanning multiple source types such as Crowd Strike and Albert, and coordinate changes with SOC leadership before deploying them.
- Configure and maintain the SIEM, including relay build and join to the SIEM, log source tagging, regular expressions, parsing validation, and alert definitions.
- Build and tune detection content across the sources CIS monitors, including Suricata, Crowd Strike, and Albert, along with third party endpoint, firewall, and network telemetry.
- Troubleshoot the ingestion and case creation pipeline end to end and serve as the tier 2 escalation point for the platform; covering every ingestion failure, playbook logic errors, data variance between third party portals and SOAR case data, and any undocumented error type, owned through to resolution.
- Participate in incident response for the platform, including the tier 2 after‑hours on‑call rotation, and maintain the alerting and routing behind it.
- Manage technical escalation with the SIEM and SOAR vendor as the CIS contact on severity cases.
- Diagnose vendor side defects and regressions, judge whether a vendor supplied fix is safe to accept, and design the remediation when it is not.
- Deliver the engineering steps of CIS Managed Detection and Response (MDR) and SOC as a service customer onboarding, including use case verification, onboarding guide development, relay build and join to the SIEM, log collection verification, tag and regular expression configuration, parsing validation with the vendor, alert definitions, SOAR case automation, user acceptance testing with the SOC, and health monitoring.
- Build connector and log source integrations and automate buildout where it is repeatable; sources span Windows and Unix host logs, network devices and firewalls, VPN and remote access, identity…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).