FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

SIEM Engineer
National Association of Insurance Commissioners (NAIC). Define, implement, and maintain the organization’s security monitoring and detection capabilities within Google SecOps .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security operations, including the implementation and maintenance of Google SecOps platforms, log ingestion, and threat detection. Proficient in developing automated workflows and dashboards for security monitoring and compliance.
Highest-signal resume keywords
Google SecOps AdministrationCloud Security MonitoringThreat Detection and Incident ResponseYARA-L Detection Content DevelopmentMITRE ATT&CK Framework Knowledge
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Log ParsingData NormalizationSecurity Telemetry CollectionDetection EngineeringAutomated Investigation WorkflowsEndpoint Detection & Response (EDR/XDR)OpenTelemetry Collector ManagementCustom Parser DevelopmentSecurity MonitoringIncident Response
Soft Skills
Clear Communication of Security Concepts
Tools & Technologies
Google SecOps (Chronicle)AWSAzureGoogle Cloud PlatformSlackAtlassian JiraWindowsLinuxMacOSMicrosoft Suite
Certifications & Qualifications
CISSPGCIHGCIASecurity+
Industry Keywords
Unified Data Model (UDM)NIST Cybersecurity FrameworkCybersecurity ThreatsSecurity OperationsThreat Hunting
Tech Stack
Tools & technologiesAWSAzureCloudCyber SecurityGoogle Cloud PlatformLinuxMacOS
About the role
Key responsibilities & impact- Define, implement, and maintain the organization’s security monitoring and detection capabilities within Google SecOps
- Design, implement, and maintain the Google SecOps platform, including log ingestion, parsing, normalization, and enrichment across cloud, on-premises, SaaS, and security data sources
- Onboard, validate, and monitor new log sources within Google SecOps
- Ensure proper mapping to the Unified Data Model (UDM), telemetry coverage, parser performance, and platform health
- Develop Google SecOps dashboards, operational metrics, and reporting for security monitoring, compliance, audit, and executive reporting
- Develop and maintain automated investigation and response workflows using Google SecOps
- Assist with developing, tuning, and maintaining YARA-L detection content aligned to MITRE ATT&CK techniques
- Reduce false positives to improve detection fidelity
- Partner with Incident Response and Security Architecture teams to support detection, investigation, and response to cybersecurity threats across the enterprise
- Employees are responsible for personal transportation to and from the home and office, including required events, meetings, and training
Requirements
What you’ll need- Bachelor’s degree from four-year college or university in a computer related field and 5+ years of experience in information security, with significant focus on security operations, or equivalent combination of education and technical experience
- Hands-on experience administering Google SecOps (Chronicle) or an equivalent enterprise SIEM platform
- Hands-on experience with cloud security monitoring across AWS, Azure, or Google Cloud Platform
- Familiarity with security operations, threat hunting, and detection engineering practices
- Strong working knowledge of security telemetry collection, log parsing, and data normalization
- Strong working knowledge of threat detection, alert triage, and incident response
- Strong working knowledge of MITRE ATT&CK and modern adversary tactics, techniques, and procedures
- Ability to communicate complex security concepts clearly to technical and non-technical audiences
- Familiarity with developing detection content using YARA-L and Unified Data Model (UDM) and investigating security incidents
- Hands-on experience with Endpoint Detection & Response (EDR/XDR) and Threat Intelligence Platforms
- Residency within a 100-mile radius of the Kansas City, MO office is required
- Applicants must be authorized to work for any employer in the U.S.
- Relevant certifications such as CISSP, GCIH, GCIA, and Security+ are preferred
- Experience with UDM and custom parser development is preferred
- Familiarity with the NIST Cybersecurity Framework is preferred
- Experience with Google SecOps SOAR and playbook development is preferred
- Experience managing and implementing OpenTelemetry Collectors is preferred
- Experience with Windows Event Logging and Sysmon is preferred
- Systems and technology experience with Slack, Atlassian Jira, AWS, Microsoft Azure, Windows, Linux, MacOS endpoints, and Microsoft Suite
Benefits
Comp & perks- Full-time remote position
- No overnight business travel required
- Equal Opportunity Employer