Senior Information Security Engineer – SIEM, Detection
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-09-15
Listing for:
Jobtailor
Full Time
position Listed on 2026-09-15
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
- Own the architecture, configuration, health, and performance of the firm’s SIEM platform, including data ingestion, parsing, normalization, retention, and cost management, in partnership with Crowd Strike as the managed security service provider
- Onboard and maintain log sources across Microsoft Defender, Microsoft Entra , Microsoft 365, Microsoft Purview, Azure, Crowd Strike, network and firewall infrastructure, and key business applications using Event Hub, Graph API, and native connectors
- Design, build, test, and tune detection rules and analytics mapped to the MITRE ATT&CK framework
- Serve as senior technical lead for the Security Incident Response Team, guiding investigations from analysis and containment through recovery and reporting
- Advise the Director and leadership on incident response decisions
- Own and maintain the firm’s Incident Response Plan and playbooks as the environment, threats, and regulatory obligations evolve
- Own configuration of the Crowd Strike Falcon platform and related modules across firm endpoints and identities, including EDR, Identity Protection, Data Protection, prevention and update policies, integrations, and day‑to‑day tuning
- Manage adjacent security technologies that feed or act on Falcon data
- Build security automation and orchestration workflows for response actions, enrichment, and case management, integrating the SIEM, Crowd Strike, and Service Now
- Complete special projects and other duties as assigned
- Communicate information security issues, risks, and recommendations to technical and non-technical peers and management
- Bachelor’s degree in cybersecurity, information systems, or a related field, or equivalent years of experience
- Eight years or more of relevant information security experience, including security operations and incident response in an enterprise environment
- Hands‑on experience engineering a SIEM platform, including log source onboarding, forwarding infrastructure, parsing and normalization, and at least one major deployment or migration
- Experience developing and tuning detections, with working knowledge of the MITRE ATT&CK framework and query languages such as KQL or equivalent
- Experience owning the configuration of an enterprise EDR platform, including policy management, tuning, integrations, and containment actions;
Crowd Strike Falcon experience strongly preferred - Demonstrated experience leading incident response, including building or maintaining incident response plans and playbooks and running tabletop exercises
- Experience managing a managed detection and response or managed security service provider relationship as the primary technical counterpart, including tuning, escalation, and service reviews
- Working knowledge of Microsoft security tooling, including Microsoft Defender, Microsoft Entra , Microsoft 365, and Microsoft Purview
- Working knowledge of network security, firewalls, and email security controls
- Thorough understanding of current security principles, techniques, and protocols
- Ability to effectively communicate information security issues, risks, and recommendations to both technical and non-technical peers and management, including through well‑written reports
- Ability to problem‑solve
- Excellent interpersonal, verbal and written communication skills, including the ability to communicate effectively in a virtual environment
- Ability to concentrate on tasks, make decisions, and work calmly and effectively in a high‑pressure, deadline‑oriented environment
- Demonstrated ability to use good judgment and take initiative while asking for direction or clarification and consulting others as appropriate
- Willingness to be flexible with time and adjust to a changing work environment
- Ability to build and maintain positive internal and external…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×