← All verified jobs

SIEM Engineer

idb bank 1114 Avenue of the Americas, NYC, NY, 10036

See all open roles at idb bank

Ghost-risk verdict

Likely real

  • 21 open roles at this company in 30 days (mass-hiring blitz)

How we score ghost risk →

See your fit for this role and apply with a truthfully tailored résumé.

See my fit, free

About the role

SIEM Engineer – Job Description

Role Overview

The SIEM Engineer is responsible for designing, implementing, maintaining, and optimizing the organization's Security Information and Event Management (SIEM) platform. This role supports Security Operations by developing detection use cases, integrating log sources, improving threat visibility, and enhancing incident response capabilities across on-premises, cloud, and hybrid environments. The SIEM Engineer works closely with SOC analysts, incident responders, threat intelligence teams, infrastructure teams, and security leadership to strengthen the organization's cyber defense posture.

Key Responsibilities

SIEM Administration & Engineering

Manage and maintain enterprise SIEM platforms.

Configure and optimize log ingestion, normalization, parsing, and retention.

Integrate security data sources including:

Firewalls

IDS/IPS

EDR/XDR

Active Directory / Entra ID

Cloud platforms (Azure, AWS, GCP)

Network and endpoint security solutions

Ensure availability, scalability, and performance of SIEM infrastructure.

Detection Engineering & Use Case Development

Develop and maintain correlation rules, analytics, and detection content.

Create use cases aligned with MITRE ATT&CK techniques.

Tune detection rules to reduce false positives and improve alert fidelity.

Work with Purple Team, Red Team, and Threat Intelligence teams to improve detection coverage.

Implement new monitoring capabilities for emerging threats.

Security Monitoring & Incident Support

Support SOC operations through advanced threat detection and alert analysis.

Assist incident responders during investigations.

Correlate events across multiple technologies to identify malicious activity.

Perform root cause analysis and recommend containment improvements.

Develop dashboards and reporting for operational visibility.

Threat Hunting & Threat Intelligence Integration

Develop hunting queries to identify malicious behavior not detected by automated alerts.

Integrate threat intelligence feeds into the SIEM platform.

Create indicators of compromise (IOC) monitoring and enrichment processes.

Identify suspicious trends and emerging attack patterns.

Automation & Optimization

Automate SIEM administration and monitoring tasks using scripting.

Integrate SIEM with SOAR platforms and ticketing systems.

Develop workflows for alert enrichment, escalation, and incident response.

Improve operational efficiency through automation and orchestration.

Governance, Compliance & Reporting

Support regulatory and audit requirements.

Maintain SIEM documentation, runbooks, and standards.

Produce security metrics and executive reporting.

Ensure log retention and monitoring practices meet compliance requirements.

Required Qualifications

Experience

5+ years of cybersecurity experience.

3+ years managing and engineering SIEM platforms.

Experience supporting SOC operations and incident response.

Experience in financial services or regulated industries preferred.

Technical Skills

Expertise in platforms such as:

Microsoft Sentinel

Splunk

QRadar

LogRhythm

Elastic Security

CrowdStrike NG-SIEM

Cribl

Strong knowledge of:

Windows and Linux security logs

Network security monitoring

EDR/XDR technologies

Threat hunting methodologies

MITRE ATT&CK framework

Data ingestion pipelines

Scripting experience:

KQL

PowerShell

Python

SQL

Security Knowledge

Log management and event correlation.

Detection engineering.

Threat intelligence.

Incident response processes.

Vulnerability management concepts.

Zero Trust security principles.

Preferred Certifications

Microsoft Certified: Security Operations Analyst (SC-200)

Microsoft Sentinel Specialty

Splunk Enterprise Security Certified Admin

Stop applying to ghosts.

OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.