FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Tech Stack
Tools & technologiesAWSAzureCloudCyber SecurityGoogle Cloud PlatformPythonSplunk
About the role
Key responsibilities & impact- Lead technical deliverables for SIEM implementation and operations using Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, and Devo
- Perform Proof of Concept and Proof of Value engagements
- Conduct SIEM assessments, identify gaps, recommend improvements, and align with security best practices
- Develop and maintain data pipelines for log ingestion, normalization, and enrichment across cloud and on-premises environments
- Integrate log sources using connectors, custom scripts, and parsers
- Build use cases aligned with NIST and MITRE ATT&CK frameworks
- Implement SPL/KQL detection rules with complex cross-source correlation
- Develop dashboards, alerts, and workbooks for security monitoring and reporting
- Implement SOAR workflows using Logic Apps, Phantom, Demisto, and XSOAR
- Perform SIEM health checks, tuning, and optimization
- Create and maintain SOPs, runbooks, architecture diagrams, and onboarding guides
- Collaborate with SOC, threat hunting, infrastructure, and cloud teams
- Deploy SIEM content through GitHub CI/CD pipelines and support operational readiness activities
- Develop custom SIEM integrations, including scripts, APIs, parsers, data transformation logic, and DataBahn pipeline management
- Apply AI capabilities to improve detection engineering, content optimization, operational efficiency, and analytical outcomes
Requirements
What you’ll need- Bachelor's degree in computer science, Cybersecurity, or related field
- Minimum 3 years of experience in SIEM implementation and security operations
- Hands-on experience with Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, Devo, and Splunk
- Strong understanding of SIEM architecture, implementation, integration, log management, and threat detection methodologies
- Experience developing and tuning security use cases and alerts
- Proficiency in Python, PowerShell, and Bash
- Experience with Azure, GCP, and AWS
- Knowledge of Cribl for log routing, enrichment, and deduplication
- Familiarity with REST APIs, JSON, and third-party security tool integrations
- Experience with SOAR platforms and playbook development
- Understanding of cyber-attacks, threat vectors, risk management, and incident management
- Experience deploying SIEM content through CI/CD practices using GitHub
- Experience managing security data pipelines and ingestion workflows, including DataBahn
- Strong understanding of AI concepts and tools for security-oriented use cases
- Proficiency in Microsoft Office tools, especially Excel, Word, PowerPoint, Teams, and Outlook
- Demonstrated ability to work collaboratively across teams and manage multiple client engagements
- Preferred certifications: Microsoft Certified: Security Operations Analyst Associate, SC-200, AZ-500, Google Professional Cloud Security Engineer, CISSP, CISM, GIAC
- Experience in a consulting, client delivery, or professional services environment is preferred
- No work visa sponsorship available
Benefits
Comp & perks- Variable incentive pay programs for eligible employees
- Competitive compensation package
- Inclusive benefits
- Flexibility programs
- Comprehensive total rewards package
- Inclusive, hybrid work environment
- Accommodation throughout the application, interview, and employment process
