What are the responsibilities and job description for the SIEM Engineer position at Eliassen Group?
Hybrid 2 Days Onsite/3 Days Remote in Washington, DC
Our client seeks a SIEM Engineer to support enterprise security monitoring, detection engineering, and log management within a federal SOC environment. The role administers SIEM platforms, onboards telemetry, tunes detections, and integrates security tools to improve visibility and response outcomes
.
Due to client requirements, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insuranc
e.Rate: $71.00 to $76.00/hr.
w2
Responsibilit
- iesAdminister and support SIEM platforms such as Splunk and Microsoft Sentin
- el.Develop and maintain search queries, dashboards, alerts, and detection log
- ic.Perform telemetry onboarding, including log source integration and troubleshooti
- ng.Analyze and optimize data pipelines for accurate, real-time monitori
- ng.Tune alerts and detections to reduce false positives and improve signal quali
- ty.Develop and refine correlation rules and detection use cas
- es.Integrate SIEM with EDR/XDR, vulnerability management, and ticketing syste
- ms.Collaborate with SOC analysts and engineers to improve detection and response workflo
- ws.Support incident investigations through log analysis and data correlati
- on.Develop documentation for SIEM configurations, onboarding processes, and detection conte
- nt.Contribute to operational reporting and metrics related to SIEM performan
ce.
Experience Requirem
- ents5 years in SIEM engineering, SOC operations, or cybersecurity engineer
- ing.Hands-on experience with Splunk administration, search, dashboards, alerting, or detection supp
- ort.Experience with telemetry onboarding and log source troubleshoot
- ing.Background in alert tuning, correlation logic, detection refinement, and false-positive reduct
- ion.Experience integrating SIEM with security and IT operations to
- ols.Understanding of log management, security monitoring, and detection methodolog
- ies.Experience in enterprise or 24x7 SOC environme
- nts.Preferred: experience supporting federal environments or regulated frameworks such as FISMA and N
- IST.Preferred: familiarity with detection engineering frameworks and threat model
- ing.Preferred: scripting for automation using Python or PowerSh
- ell.Preferred: knowledge of log normalization, parsing, and data enrichm
- ent.Preferred certifications: Splunk (Power User, Admin, Architect), Microsoft Security/Sentinel, Security or Cy
- SA .Technical environment exposure: Splunk, Microsoft Sentinel, Microsoft Defender, Rapid7 InsightVM, Veracode, Jira, Confluence, AWS, Azure, Okta, Entra ID/PIM, CyberArk, Intune, Device42, Microsoft Purview, Appian, Oracle, and hybrid on-prem plus cl
Salary : $71 - $76