376,406open jobs
9,791companies
48,125added this week
Browse all
Salary
$85k – $141k per year
Location
Remote (United States)
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match
Coalfire is a cybersecurity and compliance services company that secures the future of businesses by solving complex cybersecurity challenges and is trusted by leading organizations across various sectors.

POSITION SUMMARY:

Coalfire is on a mission to make the world a safer place by solving our clients’ toughest cybersecurity challenges.

As a leading cybersecurity solutions provider serving both private and public sector clients, we work at the cutting edge of technology-advising, assessing, automating, and guiding organizations through the ever-changing security landscape. Our professionals thrive on delivering unbiased assessments, expert guidance, and innovative strategies tailored to each client’s unique needs.

We are looking for a SIEM Platform Engineer to design, implement, operate, and continuously improve the security information and event management platforms that support Coalfire’s managed security and compliance services. This role owns the reliability and scalability of SIEM platform capabilities across cloud and high-compliance environments, including log collection, data onboarding, platform health, retention, performance, access, integrations, and operational automation.

The SIEM Platform Engineer partners closely with detection engineering, security operations, cloud engineering, compliance, and client stakeholders. The role ensures that SIEM platforms deliver high-quality, accessible, and appropriately governed security data while supporting continuous monitoring and regulatory requirements such as FedRAMP.

What You'll Do

    ESSENTIAL RESPONSIBILITIES:

  • Design, implement, and maintain SIEM platform architectures across AWS, Azure, and GCP environments.
  • Build and operate reliable log collection and ingestion pipelines, including forwarders, collectors, connectors, APIs, syslog, agents, and cloud-native services.
  • Onboard, normalize, validate, and troubleshoot data sources from cloud platforms, operating systems, applications, network devices, identity systems, endpoint tools, and security controls.
  • Establish and maintain platform standards for parsing, data models, field mappings, naming, tagging, retention, archival, access, and lifecycle management.
  • Perform SIEM platform administration, including configuration, upgrades, patching, capacity planning, performance tuning, storage optimization, licensing, and availability monitoring.
  • Develop and maintain infrastructure-as-code, automation, and deployment workflows using tools such as Terraform, Ansible, GitLab, GitHub, Python, or comparable technologies.
  • Implement platform monitoring and health checks that identify ingestion gaps, pipeline failures, data quality issues, latency, resource constraints, and service degradation.
  • Support the secure integration of SIEM platforms with endpoint, identity, vulnerability management, threat intelligence, network security, ticketing, and incident response systems.
  • Provide dependable data and platform services to detection engineering and security operations teams; collaborate on use-case enablement without owning the full detection-development lifecycle.
  • Support FedRAMP continuous monitoring and related compliance requirements by maintaining platform configurations, operational records, evidence, and repeatable procedures.
  • Participate in platform changes, releases, migrations, and modernization efforts using documented change-management and testing practices.
  • Follow and improve runbooks for platform incidents, data-source outages, ingestion failures, degraded performance, and other operational issues.
  • Troubleshoot complex platform and integration issues, communicate impact clearly, and escalate appropriately when resolution requires additional expertise or authority.
  • Create and maintain technical documentation, architecture diagrams, standard operating procedures, knowledge-base articles, and operational handoff materials.
  • Participate in client meetings as a technical resource, explaining platform capabilities, requirements, constraints, risks, and remediation plans.
  • Contribute to platform roadmaps, operational metrics, service improvements, and the development of reusable patterns across client environments.
  • WORK ENVIRONMENT/TRAVEL REQUIRED:

    Remote or standard office environment.

    Travel of approximately 10% for corporate events, training, or client needs.

What You'll Bring

    EXPERIENCE:

  • Proven experience implementing, administering, or operating SIEM and security logging platforms in enterprise, cloud, or high-compliance environments.
  • Experience delivering platform capabilities from requirements and design through implementation, validation, documentation, and operational handoff.
  • Demonstrated success integrating multiple security, cloud, endpoint, identity, network, and operational tools into a cohesive monitoring platform.
  • Experience diagnosing data quality, ingestion, pipeline, performance, availability, access, and integration problems.
  • Experience working under strict regulatory or industry frameworks while maintaining practical, reliable, and supportable platform operations.
  • Demonstrable client-facing experience in a consulting, managed-services, or professional-services capacity is preferred.
  • Hands-on systems engineering and architecture experience, including requirements definition, architecture development, systems integration, testing, and operational support.
  • Cloud experience in architecture, design, implementation, operations, and automation within AWS, Azure, or GCP.
  • Practical administration and troubleshooting experience with one or more SIEM platforms, such as Splunk, Microsoft Sentinel, Elastic, or Sumo Logic.
  • Experience designing or operating log collection, ingestion, parsing, normalization, enrichment, and retention workflows.
  • Working knowledge of cloud-native logging and security services, operating systems, networking, identity, APIs, and enterprise security tools.
  • Experience with automation and infrastructure-as-code practices using tools such as Terraform, Ansible, GitLab, GitHub, Python, or similar technologies.
  • Understanding of platform reliability concepts, including monitoring, alerting, capacity planning, performance management, availability, backup, recovery, and disaster recovery.
  • Ability to work effectively in Agile environments with cross-functional technical teams.
  • Excellent communication, organizational, documentation, and problem-solving skills, with the ability to explain complex technical information clearly.
  • Demonstrated ability to work independently and collaboratively while maintaining a professional attitude and demeanor.
  • Critical-thinking skills to balance security, compliance, reliability, cost, and mission requirements.
  • Ability to adapt quickly and operate effectively in fast-paced, dynamic environments.
  • REQUIRED CERTIFICATIONS:

  • One SIEM or security operations certification, such as Splunk Enterprise Certified Admin, Sumo Logic Administration, or Microsoft Security Operations Analyst Associate.
  • One professional-level cloud certification, such as AWS Solutions Architect Professional, AWS DevOps Engineer Professional, Azure Solutions Architect Expert, or GCP Cloud Architect.

Bonus Points

    PREFERRED CERTIFICATIONS/SKILLS (not required):

  • Splunk Enterprise Certified Architect or Splunk Certified Automation Developer.
  • Cloud security, platform engineering, cybersecurity, or automation certifications.
  • CISSP, GIAC, or comparable security certification.
  • Experience with Terraform, Ansible, Python, GitLab CI/CD, GitHub Actions, or policy-as-code.
  • EDUCATION:

    Bachelor’s degree in information technology, computer science, cybersecurity, or a related field, or equivalent combination of education and work experience.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
376,406 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
SDE III - Fullstack 3 hours ago
$21k – $58k per year (Estimated) • In office • 6+ years exp • Bachelor's Degree • Bengaluru
Java
Python
SQL
JavaScript
Java
Spring Boot
Python
Django
Frontend
React.js
DevOps
AWS
CI/CD
Git
Rest API
Apply
Engineering Manager 3 hours ago
$35k – $78k per year (Estimated) • In office • Full-Time • 10+ years exp • Noida
JavaScript
SQL
TypeScript
Java
Java
Spring Boot
Spring Cloud
Databases
PostgreSQL
Redis
Frontend
Angular
DevOps
AWS
CI/CD
Docker
Git
GitHub
GitHub Actions
Jenkins
Kubernetes
Nginx
Rest API
Shift-Left
Cybersecurity
Shift-Left Security
SonarQube
Apply
$30k – $78k per year (Estimated) • In office • 5+ years exp • Bengaluru
Python
Python
Django
Django REST Framework
DevOps
Azure
Azure AKS
CI/CD
Kubernetes
Apply
$116k – $255k per year (Estimated) • Equity • Remote • Full-Time
Go
Kotlin
Python
Databases
Databricks
FAISS
Google BigQuery
Pinecone
Snowflake
Weaviate
AI/ML
AI Agents
Braintrust
Fine-tuning
Function Calling
Langfuse
LangSmith
LLM
LLM Guardrails
MLFlow
Model Context Protocol
Prefect
Prompt Engineering
RAG
RLHF
Text-to-Speech
DevOps
AWS
CI/CD
Vector
Apply
$75k – $165k per year (Estimated) • Equity • Remote • Full-Time
Go
Kotlin
Python
Databases
Databricks
FAISS
Google BigQuery
Pinecone
Snowflake
Weaviate
AI/ML
AI Agents
Braintrust
Fine-tuning
Function Calling
Langfuse
LangSmith
LLM
LLM Guardrails
MLFlow
Model Context Protocol
Prefect
Prompt Engineering
RAG
RLHF
Text-to-Speech
DevOps
AWS
CI/CD
Vector
Apply
$113k – $189k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
Cybersecurity
FedRAMP
GDPR
ISO 27001
PCI DSS
Apply
$64k – $117k per year • Remote • Full-Time • 3+ years exp • Bachelor's Degree
PowerShell
Python
Ruby
Cybersecurity
FedRAMP
HIPAA
Apply
$109k – $182k per year • Remote • Full-Time • 10+ years exp
DevOps
AWS
Azure
CI/CD
GCP
Terraform
Cybersecurity
CIS Benchmarks
FedRAMP
NIST 800-53
Apply
$80k – $134k per year • Remote • Full-Time • 2+ years exp
DevOps
Ansible
AWS
Azure
GCP
Splunk
Terraform
GitHub
GitLab
Cybersecurity
FedRAMP
HIPAA
LogRhythm
Microsoft Sentinel
MITRE ATT&CK
NIST 800-53
Sumo Logic
Apply
$109k – $182k per year • Remote • Full-Time • 2+ years exp
AI/ML
Vertex AI
DevOps
GCP
Terraform
IAM
Cybersecurity
FedRAMP
Google SecOps
HIPAA
Wiz
Apply
See all jobs
This is one of many
376,406 more open roles from verified company boards, updated every day.