SIEM Engineer
SIEM EngineerSalary: $150k-$160k + bonusLocation: Chicago, IL or Austin, TXHybrid: 3 days onsite, 2 days remote*We are unable to provide sponsorship for this role*QualificationsBachelor’s degree3–5 years in IT or engineering2–3 years focused on SIEM, logging, or security analytics.Hands-on experience working with SIEM platforms such as Google SecOps (Chronicle), Splunk, Exabeam, or Microsoft Sentinel.Experience working with Cribl, including pipeline configuration and log onboarding, preferred.Familiarity with integrating log sources using APIs, syslog, or agents.Experience building dashboards, alerts, and queries to support security monitoring and operations.Understanding of common log sources, including endpoint, network, identity, cloud, SaaS (Software as a Service), and application logs.Ability to work effectively with cross-functional teams and communicate technical concepts clearly.Exposure to scripting or query languages (e.g., SPL, KQL, Python, Regex) and cloud platforms (Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP)) is a plus.Strong analytical skills, attention to detail, and a proactive approach to learning and improvement.ResponsibilitiesAssist in the implementation, administration, and ongoing optimization of the Firm’s SIEM platform (e.g., Google Security Operations (SecOps), Splunk, Exabeam, Microsoft Sentinel).Support the design and maintenance of Cribl pipelines, including data routing, filtering, enrichment, and performance optimization.Build and maintain integrations for standard and custom log sources using APIs, agents, syslog, and cloud-native logging services.Partner with Cybersecurity Operations to develop and refine SIEM use cases, correlation rules, and alerting logic.Create and enhance dashboards, searches, and reports to support SOC (Security Operations Center) operations and threat hunting.Contribute to documentation of SIEM architecture, data flows, onboarding processes, and operational procedures.Help establish and monitor data quality standards to ensure reliable and accurate telemetry.Work with IT, Cloud, and Application teams to onboard new systems and ensure proper logging coverage.Provide support during security incidents, assisting with investigation and analysis efforts.Stay current on SIEM technologies, security analytics, and observability trends to enhance capabilities.