{"id":778271,"url":"https://alion.io/job/idbny-siem-engineer","title":"SIEM Engineer","company":{"id":678464,"name":"Idbny","domain":"idbny.com","url":"https://alion.io/company/idbny","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"B","score":75,"open_postings":9,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-04T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["New York, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":140000,"max":160000,"currency":"USD","period":"year","gross":null,"usd_annual":160000},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Crowdstrike","optional":false},{"name":"Elastic SIEM","optional":false},{"name":"GCP","optional":false},{"name":"IBM QRadar","optional":false},{"name":"Linux","optional":false},{"name":"LogRhythm","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Red Teaming","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false},{"name":"SQL","optional":false},{"name":"Windows","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-07-30T19:36:23Z","employer_posted_date":"2026-07-30","last_verified_at":"2026-10-05T00:15:36Z","board_verified":true,"closed_at":null,"days_open":66,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":66},"description":"SIEM Engineer - Job Description\nRole Overview\nThe SIEM Engineer is responsible for designing, implementing, maintaining, and optimizing the organization's Security Information and Event Management (SIEM) platform. This role supports Security Operations by developing detection use cases, integrating log sources, improving threat visibility, and enhancing incident response capabilities across on-premises, cloud, and hybrid environments. The SIEM Engineer works closely with SOC analysts, incident responders, threat intelligence teams, infrastructure teams, and security leadership to strengthen the organization's cyber defense posture.\nKey Responsibilities\n SIEM Administration & Engineering\nManage and maintain enterprise SIEM platforms.\nConfigure and optimize log ingestion, normalization, parsing, and retention.\nIntegrate security data sources including:\nFirewalls\nIDS/IPS\nEDR/XDR\nActive Directory / Entra ID\nCloud platforms (Azure, AWS, GCP)\nNetwork and endpoint security solutions\nEnsure availability, scalability, and performance of SIEM infrastructure.\nDetection Engineering & Use Case Development\nDevelop and maintain correlation rules, analytics, and detection content.\nCreate use cases aligned with MITRE ATT&CK techniques.\nTune detection rules to reduce false positives and improve alert fidelity.\nWork with Purple Team, Red Team, and Threat Intelligence teams to improve detection coverage.\nImplement new monitoring capabilities for emerging threats.\nSecurity Monitoring & Incident Support\nSupport SOC operations through advanced threat detection and alert analysis.\nAssist incident responders during investigations.\nCorrelate events across multiple technologies to identify malicious activity.\nPerform root cause analysis and recommend containment improvements.\nDevelop dashboards and reporting for operational visibility.\n Threat Hunting & Threat Intelligence Integration\nDevelop hunting queries to identify malicious behavior not detected by automated alerts.\nIntegrate threat intelligence feeds into the SIEM platform.\nCreate indicators of compromise (IOC) monitoring and enrichment processes.\nIdentify suspicious trends and emerging attack patterns.\nAutomation & Optimization\nAutomate SIEM administration and monitoring tasks using scripting.\nIntegrate SIEM with SOAR platforms and ticketing systems.\nDevelop workflows for alert enrichment, escalation, and incident response.\nImprove operational efficiency through automation and orchestration.\nGovernance, Compliance & Reporting\nSupport regulatory and audit requirements.\nMaintain SIEM documentation, runbooks, and standards.\nProduce security metrics and executive reporting.\nEnsure log retention and monitoring practices meet compliance requirements.\nRequired Qualifications\nExperience\n5+ years of cybersecurity experience.\n3+ years managing and engineering SIEM platforms.\nExperience supporting SOC operations and incident response.\nExperience in financial services or regulated industries preferred.\nTechnical Skills\nExpertise in platforms such as:\nMicrosoft Sentinel\nSplunk\nQRadar\nLogRhythm\nElastic Security\nCrowdStrike NG-SIEM\nCribl\nStrong knowledge of:\nWindows and Linux security logs\nNetwork security monitoring\nEDR/XDR technologies\nThreat hunting methodologies\nMITRE ATT&CK framework\nData ingestion pipelines\nScripting experience:\nKQL\nPowerShell\nPython\nSQL\nSecurity Knowledge\nLog management and event correlation.\nDetection engineering.\nThreat intelligence.\nIncident response processes.\nVulnerability management concepts.\nZero Trust security principles.\nPreferred Certifications\nMicrosoft Certified: Security Operations Analyst (SC-200)\nMicrosoft Sentinel Specialty\nSplunk Enterprise Security Certified Admin\nGIAC Certified Incident Handler (GCIH)\nGIAC Certified Intrusion Analyst (GCIA)\nCISSP \nCompensation\n The expected annual salary for this position is between $140,000 and $160,000 at the start of employment. A salary offer is determined on an individualized basis, taking into consideration factors such as an individual’s skills and experience. In addition to base salary, our total rewards package also includes eligibility for an annual bonus, medical, pharmacy, dental, and vision plans, life and disability insurance, employee wellness program, retirement and savings plans with employer contributions, generous holiday and paid time off schedules, parental leave, and tuition reimbursement.\nAdditional Information\nThe Bank Will Make Reasonable Accommodations To The Following Employees To Allow Them To Perform The Essential Functions Of Their Position, Except Where Doing So Would Result In Undue Hardship To The Bank\nThose with a known mental or physical disability.\nPregnant individuals and/or individuals with pregnancy or childbirth-related medical conditions.\nVictims of domestic violence, sex offenses or stalking.\nEmployees with religious observance and practice obligations.\nAny employee who believes he or she needs an accommodation for any of the above reasons should contact their supervisor or a member of Human Resources to request such an accommodation. In each case, the Bank will engage in a good faith written or oral dialogue concerning the individual’s accommodation needs; potential accommodations that may address the individual’s accommodation needs, including alternatives to a requested accommodation; and the difficulties that such potential accommodations may pose for the employer.\nThe Bank retains the ultimate discretion to choose the appropriate reasonable accommodation. Upon reaching a final determination at the conclusion of the cooperative dialogue, the Bank will provide the requesting individual with a written final determination identifying any accommodation granted or denied. In addition, the Bank will maintain any information regarding the employee’s request and status in the strictest confidence, except as requested by the employee, as required on a need-to-know basis or as otherwise required by law.\nDisclaimer\n The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities from time to time, as needed.\nAll your information will be kept confidential according to EEO guidelines.\nWe are operating on a Hybrid schedule.\nNO AGENCIES PLEASE.\n IDB BANK, INCLUDING ITS SUBSIDIARIES AND DIVISIONS, PROVIDES EQUAL EMPLOYMENT OPPORTUNITIES TO ALL EMPLOYEES AND APPLICANTS FOR EMPLOYMENT WITHOUT REGARD TO RACE, COLOR, RELIGION, SEX, SEXUAL ORIENTATION, NATIONAL ORIGIN, AGE, DISABILITY, GENETIC STATUS, CITIZENSHIP STATUS, MARITAL STATUS, MILITARY OR VETERAN STATUS, CURRENT UNEMPLOYMENT OR ANY OTHER LEGALLY PROTECTED CATEGORY IN ACCORDANCE WITH APPLICABLE FEDERAL, STATE AND LOCAL LAW. NOTHING IN THIS SITE CONSTITUTES A PROMISE OR OFFER OF EMPLOYMENT.\nKindly review our Privacy Notice and GLBA Consumer Privacy Notice.\nKindly review our Privacy Notice and GLBA Consumer Privacy Notice.\nKindly review our Privacy Notice and GLBA Consumer Privacy Notice.","description_format":"text","description_chars":7191,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Parental leave","Retirement plans"],"hiring_locations":[{"name":"United States","iso":"US","kind":"region"},{"name":"Argentina","iso":"AR","kind":"region"},{"name":"Brazil","iso":"BR","kind":"region"},{"name":"Canada","iso":"CA","kind":"region"},{"name":"Colombia","iso":null,"kind":"region"},{"name":"Mexico","iso":"MX","kind":"region"},{"name":"Anguilla","iso":null,"kind":"region"},{"name":"Antigua and Barbuda","iso":"AG","kind":"region"},{"name":"Aruba","iso":"AW","kind":"region"},{"name":"Bahamas","iso":"BS","kind":"region"},{"name":"Barbados","iso":"BB","kind":"region"},{"name":"Belize","iso":"BZ","kind":"region"},{"name":"Bermuda","iso":"BM","kind":"region"},{"name":"Bolivia","iso":"BO","kind":"region"},{"name":"British Virgin Islands","iso":"VG","kind":"region"},{"name":"Bonaire, Sint Eustatius and Saba","iso":"BQ","kind":"region"},{"name":"Cayman Islands","iso":"KY","kind":"region"},{"name":"Chile","iso":"CL","kind":"region"},{"name":"Costa Rica","iso":"CR","kind":"region"},{"name":"Curaçao","iso":"CW","kind":"region"},{"name":"Dominica","iso":"DM","kind":"region"},{"name":"Dominican Republic","iso":"DO","kind":"region"},{"name":"Ecuador","iso":"EC","kind":"region"},{"name":"El Salvador","iso":"SV","kind":"region"},{"name":"Falkland Islands","iso":"FK","kind":"region"},{"name":"French Guiana","iso":"GF","kind":"region"},{"name":"Greenland","iso":"GL","kind":"region"},{"name":"Grenada","iso":"GD","kind":"region"},{"name":"Guadeloupe","iso":"GP","kind":"region"},{"name":"Guatemala","iso":"GT","kind":"region"},{"name":"Guyana","iso":"GY","kind":"region"},{"name":"Haiti","iso":"HT","kind":"region"},{"name":"Honduras","iso":"HN","kind":"region"},{"name":"Jamaica","iso":"JM","kind":"region"},{"name":"Martinique","iso":"MQ","kind":"region"},{"name":"Montserrat","iso":"MS","kind":"region"},{"name":"Nicaragua","iso":"NI","kind":"region"},{"name":"Panama","iso":"PA","kind":"region"},{"name":"Paraguay","iso":"PY","kind":"region"},{"name":"Peru","iso":"PE","kind":"region"},{"name":"Puerto Rico","iso":"PR","kind":"region"},{"name":"Saint Kitts and Nevis","iso":"KN","kind":"region"},{"name":"Saint Lucia","iso":"LC","kind":"region"},{"name":"Saint Vincent and the Grenadines","iso":null,"kind":"region"},{"name":"Saint-Pierre and Miquelon","iso":"PM","kind":"region"},{"name":"Sint Maarten","iso":"SX","kind":"region"},{"name":"Suriname","iso":"SR","kind":"region"},{"name":"Trinidad and Tobago","iso":"TT","kind":"region"},{"name":"Turks and Caicos Islands","iso":"TC","kind":"region"},{"name":"Uruguay","iso":"UY","kind":"region"},{"name":"United States Virgin Islands","iso":"VI","kind":"region"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Security Operations"],"lifecycle":[{"event":"open","at":"2026-09-11T23:44:18Z"}],"visa":[],"liveness":{"score":12,"band":"cold","label":"Long shot","p_open":1,"p_active":0.439,"p_room":0.28,"age_days":65,"expected_fill_days":24,"reasons":["conf:1","win:tail","crowd:"],"computed_at":"2026-10-04T05:45:00Z"},"pay":{"stated_usd_annual":160000,"is_top_pay":false},"html_url":"https://alion.io/job/idbny-siem-engineer","json_url":"https://alion.io/job/idbny-siem-engineer.json","meta":{"generated_at":"2026-10-05T01:16:59Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1670,"day_limit":5000,"remaining_today":3330,"minute_limit":60,"resets_at":"2026-10-06T00:00:00Z"}}}