Haystack
← Back to Jobs
Technology
RT

Senior SIEM SecOps Engineer

Request Technology, LLCAustin, TX🇺🇸United StatesPosted 14 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

***We are unable to sponsor for this permanent full-time role***

***Position is bonus eligible***

Prestigious Global Firm is currently seeking a Senior SIEM SecOps Engineer. Candidate will play a key role in the implementation, optimization, and day-to-day management of Security Information and Event Management (SIEM) platform. Candidate will contribute to the ingestion, normalization, and enrichment of security telemetry while supporting detection engineering, incident response, and security analytics. Will collaborate with Cybersecurity Operations, IT, Infrastructure, Cloud, and Application teams to onboard log sources, develop detections, and create dashboards that drive visibility and response. 

Responsibilities:

  • SIEM Platform Support – Assist in the implementation, administration, and ongoing optimization of the Firm’s SIEM platform (e.g., Google Security Operations (SecOps), Splunk, Exabeam, Microsoft Sentinel). 
  • Cribl Development – Support the design and maintenance of Cribl pipelines, including data routing, filtering, enrichment, and performance optimization. 
  • Log Integration – Build and maintain integrations for standard and custom log sources using APIs, agents, syslog, and cloud-native logging services. 
  • Detection Enablement – Partner with Cybersecurity Operations to develop and refine SIEM use cases, correlation rules, and alerting logic. 
  • Dashboards & Reporting – Create and enhance dashboards, searches, and reports to support SOC (Security Operations Center) operations and threat hunting. 
  • Documentation – Contribute to documentation of SIEM architecture, data flows, onboarding processes, and operational procedures. 
  • Data Quality Assurance – Help establish and monitor data quality standards to ensure reliable and accurate telemetry. 
  • Cross-Team Collaboration – Work with IT, Cloud, and Application teams to onboard new systems and ensure proper logging coverage. 
  • Incident Support – Provide support during security incidents, assisting with investigation and analysis efforts. 
  • Continuous Learning – Stay current on SIEM technologies, security analytics, and observability trends to enhance capabilities. 

Qualifications:

  • Education – Bachelor’s degree or equivalent professional experience required. 
  • Experience – Minimum of 3–5 years in IT or engineering, with at least 2–3 years focused on SIEM, logging, or security analytics. 
  • SIEM Fundamentals – Hands-on experience working with SIEM platforms such as Google SecOps (Chronicle), Splunk, Exabeam, or Microsoft Sentinel. 
  • Cribl Exposure – Experience working with Cribl, including pipeline configuration and log onboarding, preferred. 
  • Data Integration Skills – Familiarity with integrating log sources using APIs, syslog, or agents. 
  • Analytics & Visualization – Experience building dashboards, alerts, and queries to support security monitoring and operations. 
  • Security Knowledge – Understanding of common log sources, including endpoint, network, identity, cloud, SaaS (Software as a Service), and application logs. 
  • Collaboration & Communication – Ability to work effectively with cross-functional teams and communicate technical concepts clearly. 
  • Technical Foundation – Exposure to scripting or query languages (e.g., SPL, KQL, Python, Regex) and cloud platforms (Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (Google Cloud Platform)) is a plus. 
  • Problem Solving & Growth Mindset – Strong analytical skills, attention to detail, and a proactive approach to learning and improvement.

Skills

Python
AWS
Azure
Google Cloud
Splunk

Similar jobs