Haystack
← Back to Jobs
Technology
DE

SIEM Engineer (TS/SCI or TS )

Delviom LLCAlexandria, VA🇺🇸United StatesPosted Sep 25, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Alexandria, VA, United States
Posted
4 days ago
Splunk

Job Description

We are seeking an experienced SIEM Engineer / Senior SOC Engineer to support security monitoring, detection engineering, threat hunting, incident response, and digital forensics activities. The ideal candidate will have a strong combination of hands-on SIEM engineering experience and operational SOC expertise, with the ability to investigate complex security events and improve enterprise detection capabilities.

Key Responsibilities

  • Engineer, configure, maintain, and optimize enterprise SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, ArcSight, or similar technologies.
  • Develop and tune correlation rules, detection logic, alerts, dashboards, reports, and security use cases.
  • Monitor and investigate security alerts across endpoints, networks, cloud environments, applications, and identity platforms.
  • Perform Tier 2 / Tier 3 SOC analysis, including event correlation, triage, escalation, and root cause analysis.
  • Conduct proactive threat hunting using SIEM, EDR, threat intelligence, network telemetry, and behavioral analytics.
  • Develop threat hunting hypotheses based on emerging threats, Indicators of Compromise, TTPs, and the MITRE ATT&CK framework.
  • Lead and support incident response activities including investigation, containment, eradication, recovery, and lessons learned.
  • Perform digital forensics involving endpoint, memory, disk, network, email, and log analysis to determine the scope and impact of security incidents.
  • Analyze malware activity, suspicious processes, authentication events, lateral movement, persistence mechanisms, and data exfiltration indicators.
  • Integrate SIEM platforms with security

Similar jobs