1,011,843open jobs
60,160companies
168,355added this week
Browse all
Salary
$140k – $160k per year
Location
Hybrid (New York, United States)
Seniority
Senior · 5+ years exp

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Jul 30, 2026. Idbny scores B on the Alion truth index.

Overview
Company
Impact
Profile match

SIEM Engineer - Job Description

Role Overview

The SIEM Engineer is responsible for designing, implementing, maintaining, and optimizing the organization's Security Information and Event Management (SIEM) platform. This role supports Security Operations by developing detection use cases, integrating log sources, improving threat visibility, and enhancing incident response capabilities across on-premises, cloud, and hybrid environments. The SIEM Engineer works closely with SOC analysts, incident responders, threat intelligence teams, infrastructure teams, and security leadership to strengthen the organization's cyber defense posture.

Key Responsibilities

  • SIEM Administration & Engineering
  • Manage and maintain enterprise SIEM platforms.
  • Configure and optimize log ingestion, normalization, parsing, and retention.
  • Integrate security data sources including:
    • Firewalls
    • IDS/IPS
    • EDR/XDR
    • Active Directory / Entra ID
    • Cloud platforms (Azure, AWS, GCP)
    • Network and endpoint security solutions
  • Ensure availability, scalability, and performance of SIEM infrastructure.
  • Detection Engineering & Use Case Development
  • Develop and maintain correlation rules, analytics, and detection content.
  • Create use cases aligned with MITRE ATT&CK techniques.
  • Tune detection rules to reduce false positives and improve alert fidelity.
  • Work with Purple Team, Red Team, and Threat Intelligence teams to improve detection coverage.
  • Implement new monitoring capabilities for emerging threats.
  • Security Monitoring & Incident Support
  • Support SOC operations through advanced threat detection and alert analysis.
  • Assist incident responders during investigations.
  • Correlate events across multiple technologies to identify malicious activity.
  • Perform root cause analysis and recommend containment improvements.
  • Develop dashboards and reporting for operational visibility.
  • Threat Hunting & Threat Intelligence Integration
  • Develop hunting queries to identify malicious behavior not detected by automated alerts.
  • Integrate threat intelligence feeds into the SIEM platform.
  • Create indicators of compromise (IOC) monitoring and enrichment processes.
  • Identify suspicious trends and emerging attack patterns.
  • Automation & Optimization
  • Automate SIEM administration and monitoring tasks using scripting.
  • Integrate SIEM with SOAR platforms and ticketing systems.
  • Develop workflows for alert enrichment, escalation, and incident response.
  • Improve operational efficiency through automation and orchestration.
  • Governance, Compliance & Reporting
  • Support regulatory and audit requirements.
  • Maintain SIEM documentation, runbooks, and standards.
  • Produce security metrics and executive reporting.
  • Ensure log retention and monitoring practices meet compliance requirements.

Required Qualifications

Experience

  • 5+ years of cybersecurity experience.
  • 3+ years managing and engineering SIEM platforms.
  • Experience supporting SOC operations and incident response.
  • Experience in financial services or regulated industries preferred.

Technical Skills

  • Expertise in platforms such as:
    • Microsoft Sentinel
    • Splunk
    • QRadar
    • LogRhythm
    • Elastic Security
    • CrowdStrike NG-SIEM
    • Cribl
  • Strong knowledge of:
    • Windows and Linux security logs
    • Network security monitoring
    • EDR/XDR technologies
    • Threat hunting methodologies
    • MITRE ATT&CK framework
    • Data ingestion pipelines
  • Scripting experience:
    • KQL
    • PowerShell
    • Python
    • SQL

Security Knowledge

  • Log management and event correlation.
  • Detection engineering.
  • Threat intelligence.
  • Incident response processes.
  • Vulnerability management concepts.
  • Zero Trust security principles.

Preferred Certifications

  • Microsoft Certified: Security Operations Analyst (SC-200)
  • Microsoft Sentinel Specialty
  • Splunk Enterprise Security Certified Admin
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • CISSP 

Compensation

The expected annual salary for this position is between $140,000 and $160,000 at the start of employment. A salary offer is determined on an individualized basis, taking into consideration factors such as an individual’s skills and experience. In addition to base salary, our total rewards package also includes eligibility for an annual bonus, medical, pharmacy, dental, and vision plans, life and disability insurance, employee wellness program, retirement and savings plans with employer contributions, generous holiday and paid time off schedules, parental leave, and tuition reimbursement.

Additional Information

The Bank Will Make Reasonable Accommodations To The Following Employees To Allow Them To Perform The Essential Functions Of Their Position, Except Where Doing So Would Result In Undue Hardship To The Bank

  • Those with a known mental or physical disability.
  • Pregnant individuals and/or individuals with pregnancy or childbirth-related medical conditions.
  • Victims of domestic violence, sex offenses or stalking.
  • Employees with religious observance and practice obligations.

Any employee who believes he or she needs an accommodation for any of the above reasons should contact their supervisor or a member of Human Resources to request such an accommodation. In each case, the Bank will engage in a good faith written or oral dialogue concerning the individual’s accommodation needs; potential accommodations that may address the individual’s accommodation needs, including alternatives to a requested accommodation; and the difficulties that such potential accommodations may pose for the employer.

The Bank retains the ultimate discretion to choose the appropriate reasonable accommodation. Upon reaching a final determination at the conclusion of the cooperative dialogue, the Bank will provide the requesting individual with a written final determination identifying any accommodation granted or denied. In addition, the Bank will maintain any information regarding the employee’s request and status in the strictest confidence, except as requested by the employee, as required on a need-to-know basis or as otherwise required by law.

Disclaimer

The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities from time to time, as needed.

All your information will be kept confidential according to EEO guidelines.

We are operating on a Hybrid schedule.

NO AGENCIES PLEASE.

IDB BANK, INCLUDING ITS SUBSIDIARIES AND DIVISIONS, PROVIDES EQUAL EMPLOYMENT OPPORTUNITIES TO ALL EMPLOYEES AND APPLICANTS FOR EMPLOYMENT WITHOUT REGARD TO RACE, COLOR, RELIGION, SEX, SEXUAL ORIENTATION, NATIONAL ORIGIN, AGE, DISABILITY, GENETIC STATUS, CITIZENSHIP STATUS, MARITAL STATUS, MILITARY OR VETERAN STATUS, CURRENT UNEMPLOYMENT OR ANY OTHER LEGALLY PROTECTED CATEGORY IN ACCORDANCE WITH APPLICABLE FEDERAL, STATE AND LOCAL LAW. NOTHING IN THIS SITE CONSTITUTES A PROMISE OR OFFER OF EMPLOYMENT.

Kindly review our Privacy Notice  and GLBA Consumer Privacy Notice.

Kindly review our Privacy Notice  and GLBA Consumer Privacy Notice.

Kindly review our Privacy Notice and GLBA Consumer Privacy Notice.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,011,843 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
New York
≈ $102k – $206k per year (Estimated) • Remote (Romania) • 5+ years exp • Bachelor's Degree
Python
JavaScript
Java
SQL
PowerShell
C#
Node JS
YARA
C#
.NET
DevOps
CI/CD
GitOps
Kubernetes
Cybersecurity
YARA
SIEM
Apply
≈ $104k – $235k per year (Estimated) • In office • Colombia
AI/ML
Model Context Protocol
AI Agents
LLM
Red Teaming
LLM Guardrails
NIST AI RMF
Machine Learning
DevOps
Kubernetes
Cybersecurity
Zero Trust
Sigstore
Kyverno
PKI
OWASP
Apply
$161k – $221k per year • In office • TS/SCI • 8+ years exp • Chicago
Python
PowerShell
AI/ML
Machine Learning
DevOps
Terraform
GCP
Azure
CI/CD
AWS
Cybersecurity
Okta
FedRAMP
DLP
Analytics
ETL/ELT
Apply
≈ $49k – $137k per year (Estimated) • Remote (Switzerland) • 2+ years exp
Cybersecurity
ISO 27001
Apply
GRC Specialist 3 days ago
≈ $43k – $119k per year (Estimated) • Hybrid • Full-Time • Buenos Aires
DevOps
IAM
Cybersecurity
ISO 27001
Apply
≈ $20k – $42k per year (Estimated) • In office • 4+ years exp • Moscow
Python
SQL
Python
FastAPI
Databases
PostgreSQL
Redis
Qdrant
RabbitMQ
ElasticSearch
Apache Kafka
OpenSearch
AI/ML
Copilot
Cursor
LangGraph
LangChain
Model Context Protocol
AI Agents
LLM
RAG
DevOps
Git
Gitflow
Management
Agile
Scrum
Apply
≈ $17k – $36k per year (Estimated) • In office • 1+ year exp • Saint Petersburg
Python
SQL
AI/ML
Cursor
Claude
ChatGPT
DevOps
DNS
VPN
Design
Figma
Management
Miro
Confluence
Notion
Jira
QA
Postman
Apply
$123k – $202k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • United States
DevOps
GCP
Azure
AWS
FinOps
SLI/SLO/SLA
Cybersecurity
Zero Trust
Least Privilege
Management
ITIL
Service Desk
Apply
≈ $16k – $39k per year (Estimated) • Remote (EAEU) • Moscow
SQL
Databases
RabbitMQ
Apache Kafka
DevOps
Rest API
Management
Miro
Confluence
Jira
Draw.io
UML
BPMN
QA
Swagger
Postman
Apply
≈ $34k – $84k per year (Estimated) • Remote (EAEU) • 3+ years exp • Moscow
Python
AI/ML
LoRA
AI Agents
ComfyUI
PEFT
Apply
$160k – $180k per year • Hybrid • Confidential • Bachelor's Degree • New York
Apply
$170k – $200k per year • Hybrid • 10+ years exp • Bachelor's Degree • New York
Apply
Financial Planner 22 days ago
$140k – $160k per year • Hybrid • Confidential • 5+ years exp • New York
Apply
$135k – $160k per year • Hybrid • Confidential • Aventura
Apply
$160k – $220k per year • Hybrid • Confidential • New York
Apply
$145k – $261k per year • Hybrid • 7+ years exp • Bachelor's Degree • New York
JavaScript
TypeScript
Node JS
AI/ML
Computer Vision
Machine Learning
Frontend
Zustand
Redux
GraphQL
D3.js
React.js
Deck.gl
OpenLayers
Mobile
State Management
DevOps
WebSockets
Apply
$83k – $124k per year • Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Chicago • San Francisco • Scottsdale • New York
Python
Java
SQL
Scala
Python
pySpark
Java
Maven
AI/ML
Hadoop
Spark
Machine Learning
DevOps
AWS
Amazon S3
Linux
Analytics
Tableau
ETL/ELT
Apply
$145k – $177k per year • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • New York • Chicago • San Francisco • Scottsdale
Management
Agile
Waterfall
Apply
$60k – $70k per year • In office • Full-Time • Bachelor's Degree • Boston • New York
Analytics
Microsoft Excel
Apply
$50k – $63k per year • In office • Full-Time • Master's Degree • New York
Management
Outlook
Microsoft Office
Apply
See all jobs
This is one of many
1,011,843 more open roles from verified company boards, updated every day.