SIEM Engineer

AnaVationWashington, DC
1dOnsite

About The Position

AnaVation is seeking an experienced SIEM (Security Information and Event Management) Engineer to provide support to a mission critical customer. The selected candidate will be responsible for the design, deployment, configuration, and maintenance of SIEM systems across multiple classification enclaves. This position is on site with the customer in Washington, DC and cannot be supported remotely. The selected candidate must possess an active TS clearance with the ability to obtain SCI accesses. Candidates without an active TS cannot be considered.

Requirements

  • 6+ years of cybersecurity experience, with at least 5 years focused on SIEM engineering in enterprise environments.
  • Experience supporting federal government systems at multiple security levels, strong knowledge of federal cybersecurity frameworks, and the ability to provide technical support within a secure environment.
  • Hands-on experience with one or more enterprise SIEM platforms.
  • Experience engineering and sustaining SIEM solutions in classified or air-gapped environments.
  • Familiarity with cross-domain solutions and secure data transfer controls.
  • Strong expertise in: Log normalization and parsing, Advanced correlation rule development, Threat detection engineering, Network protocols and traffic analysis, Windows and Linux security logging
  • Active TS clearance with the ability to obtain SCI accesses.

Nice To Haves

  • Bachelor’s degree in Information Technology, Computer Science, Information Systems or related field
  • Proficiency in scripting/automation (Python, PowerShell, Bash).
  • Deep understanding of MITRE ATT&CK and threat detection methodologies.
  • Demonstrated ability to work independently and lead technical initiatives in highly regulated environments.
  • Knowledge of Zero Trust architecture principles.
  • Relevant certifications such as GIAC (GCIA, GCIH, GCED) or CISSP a plus, but not required.

Responsibilities

  • Support the architecture, engineering, optimization, and sustainment of Security Information and Event Management (SIEM) platforms supporting defensive cyber operations, advanced threat detection, incident response, and compliance initiatives
  • Perform configuration, management and maintenance of network firewalls, security and encryption devices, including IDS, NAC and SIEM systems.
  • Integrate diverse log sources including firewalls, IDS/IPS, EDR, servers, network devices, security appliances, and cloud environments.
  • Optimize SIEM performance, storage architecture, data retention policies, and system scalability.

Benefits

  • Generous cost sharing for medical insurance for the employee and dependents
  • 100% company paid dental insurance for employees and dependents
  • 100% company paid long-term and short term disability insurance
  • 100% company paid vision insurance for employees and dependents
  • 401k plan with generous match and 100% immediate vesting
  • Competitive Pay
  • Generous paid leave and holiday package
  • Tuition and training reimbursement
  • Life and AD&D Insurance
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service