
Senior SIEM Engineer
Coalfire · Remote, United States
About The Role
About Coalfire
Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.
But that’s not who we are – that’s just what we do.
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.
What You'll Do
ESSENTIAL RESPONSIBILITIES
- Design, implement, and maintain SIEM platform architectures across AWS, Azure, and GCP environments.
- Build and operate reliable log collection and ingestion pipelines, including forwarders, collectors, connectors, APIs, syslog, agents, and cloud-native services.
- Onboard, normalize, validate, and troubleshoot data sources from cloud platforms, operating systems, applications, network devices, identity systems, endpoint tools, and security controls.
- Establish and maintain platform standards for parsing, data models, field mappings, naming, tagging, retention, archival, access, and lifecycle management.
- Perform SIEM platform administration, including configuration, upgrades, patching, capacity planning, performance tuning, storage optimization, licensing, and availability monitoring.
- Develop and maintain infrastructure-as-code, automation, and deployment workflows using tools such as Terraform, Ansible, GitLab, GitHub, Python, or comparable technologies.
- Implement platform monitoring and health checks that identify ingestion gaps, pipeline failures, data quality issues, latency, resource constraints, and service degradation.
- Support the secure integration of SIEM platforms with endpoint, identity, vulnerability management, threat intelligence, network security, ticketing, and incident response systems.
- Provide dependable data and platform services to detection engineering and security operations teams; collaborate on use-case enablement without owning the full detection-development lifecycle.
- Support FedRAMP continuous monitoring and related compliance requirements by maintaining platform configurations, operational records, evidence, and repeatable procedures.
- Participate in platform changes, releases, migrations, and modernization efforts using documented change-management and testing practices.
- Follow and improve runbooks for platform incidents, data-source outages, ingestion failures, degraded performance, and other operational issues.
- Troubleshoot complex platform and integration issues, communicate impact clearly, and escalate appropriately when resolution requires additional expertise or authority.
- Create and maintain technical documentation, architecture diagrams, standard operating procedures, knowledge-base articles, and operational handoff materials.
- Participate in client meetings as a technical resource, explaining platform capabilities, requirements, constraints, risks, and remediation plans.
- Contribute to platform roadmaps, operational metrics, service improvements, and the development of reusable patterns across client environments.
WORK ENVIRONMENT/TRAVEL REQUIRED
- Remote or standard office environment.
- Travel of approximately 10% for corporate events, training, or client needs.
What You'll Bring
EXPERIENCE
- Proven experience implementing, administering, or operating SIEM and security logging platforms in enterprise, cloud, or high-compliance environments.
- Experience delivering platform capabilities from requirements and design through implementation, validation, documentation, and operational handoff.
- Demonstrated success integrating multiple security, cloud, endpoint, identity, network, and operational tools into a cohesive monitoring platform.
- Experience diagnosing data quality, ingestion, pipeline, performance, availability, access, and integration problems.
- Experience working under strict regulatory or industry frameworks while maintaining practical, reliable, and supportable platform operations.
- Demonstrable client-facing experience in a consulting, managed-services, or professional-services capacity is preferred.
- Hands-on systems engineering and architecture experience, including requirements definition, architecture development, systems integration, testing, and operational support.
- Cloud experience in architecture, design, implementation, operations, and automation within AWS, Azure, or GCP.
- Practical administration and troubleshooting experience with one or more SIEM platforms, such as Splunk, Microsoft Sentinel, Elastic, or Sumo Logic.
- Experience designing or operating log collection, ingestion, parsing, normalization, enrichment, and retention workflows.
- Working knowledge of cloud-native logging and security services, operating systems, networking, identity, APIs, and enterprise security tools.
- Experience with automation and infrastructure-as-code practices using tools such as Terraform, Ansible, GitLab, GitHub, Python, or similar technologies.
- Understanding of platform reliability concepts, including monitoring, alerting, capacity planning, performance management, availability, backup, recovery, and disaster recovery.
- Ability to work effectively in Agile environments with cross-functional technical teams.
- Excellent communication, organizational, documentation, and problem-solving skills, with the ability to explain complex technical information clearly.
- Demonstrated ability to work independently and collaboratively while maintaining a professional attitude and demeanor.
- Critical-thinking skills to balance security, compliance, reliability, cost, and mission requirements.
- Ability to adapt quickly and operate effectively in fast-paced, dynamic environments.
REQUIRED CERTIFICATIONS
- One SIEM or security operations certification, such as Splunk Enterprise Certified Admin, Sumo Logic Administration, or Microsoft Security Operations Analyst Associate.
- One professional-level cloud certification, such as AWS Solutions Architect Professional, AWS DevOps Engineer Professional, Azure Solutions Architect Expert, or GCP Cloud Architect.
Bonus Points
PREFERRED CERTIFICATIONS/SKILLS (not required)
- Splunk Enterprise Certified Architect or Splunk Certified Automation Developer.
- Cloud security, platform engineering, cybersecurity, or automation certifications.
- CISSP, GIAC, or comparable security certification.
- Experience with Terraform, Ansible, Python, GitLab CI/CD, GitHub Actions, or policy-as-code.
EDUCATION
Bachelor’s degree in information technology, computer science, cybersecurity, or a related field, or equivalent combination of education and work experience.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
