Analytics, ArcSight SIEM, ElasticSearch, Kibana Certifications: None Experience: 6 + years of related experience US Citizenship Required: Yes GDIT is seeking a motivated, career and customer-oriented ...
Analytics, ArcSight SIEM, ElasticSearch, Kibana Certifications: None Experience: 6 + years of related experience US Citizenship Required: Yes GDIT is seeking a motivated, career and customer-oriented ...
Analytics, ArcSight SIEM, ElasticSearch, Kibana Certifications: None Experience: 6 + years of related experience US Citizenship Required: Yes GDIT is seeking a motivated, career and customer-oriented ...
Analytics, ArcSight SIEM, ElasticSearch, Kibana Certifications: None Experience: 6 + years of related experience US Citizenship Required: Yes GDIT is seeking a motivated, career and customer-oriented ...
... SIEM)/McAfee ePO monitoring On behalf of our client, Procom Services is searching for a Security Engineer with strong experience in ArcSight Security Information and Event Management and McAfee ePO ...
... SIEM)/McAfee ePO monitoring On behalf of our client, Procom Services is searching for a Security Engineer with strong experience in ArcSight Security Information and Event Management and McAfee ePO ...
SIEM ArcSight Specialist
Washington, DC · On-site
Alphalogic is looking for an ArcSight Security Systems Specialist for one of our leading clients in Washington, DC. Responsibilities: * Perform upgrades on the ArcSight components include the ...
SIEM ArcSight Specialist
Washington, DC · On-site
Alphalogic is looking for an ArcSight Security Systems Specialist for one of our leading clients in Washington, DC. Responsibilities: * Perform upgrades on the ArcSight components include the ...
SIEM ArcSight Specialist
Washington, DC · On-site
Alphalogic is looking for an ArcSight Security Systems Specialist for one of our leading clients in Washington, DC. Responsibilities: * Perform upgrades on the ArcSight components include the ...
SIEM ArcSight Specialist
Washington, DC · On-site
Alphalogic is looking for an ArcSight Security Systems Specialist for one of our leading clients in Washington, DC. Responsibilities: * Perform upgrades on the ArcSight components include the ...
ArcSight Security Engineer
Fort Knox, KY · On-site
ArcSight Security Engineer Duration: 6 months (Possibility to Hire) Location: Fort Knox, KY ... SIEM deployment, and understand methodologies, terms, concepts, and best practices within the ...
ArcSight Security Engineer
Fort Knox, KY · On-site
ArcSight Security Engineer Duration: 6 months (Possibility to Hire) Location: Fort Knox, KY ... SIEM deployment, and understand methodologies, terms, concepts, and best practices within the ...
Content Developer (SIEM Cyber Security)
San Antonio, TX · On-site
$110K - $115K/yr
More than 5 years of SIEM technology such as ArcSight, Splunk, and/or ELK. * More than 3 years with network traffic analysis, ports, and protocols. BA/BS or MA/MS * More than five (5) years of SIEM ...
Content Developer (SIEM Cyber Security)
San Antonio, TX · On-site
$110K - $115K/yr
More than 5 years of SIEM technology such as ArcSight, Splunk, and/or ELK. * More than 3 years with network traffic analysis, ports, and protocols. BA/BS or MA/MS * More than five (5) years of SIEM ...
SIEM experience with one of the following ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA) * Experience providing support to Cybersecurity Operations Cell (CSOC) in ...
SIEM experience with one of the following ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA) * Experience providing support to Cybersecurity Operations Cell (CSOC) in ...
Content Developer (SIEM Cyber Security)
San Antonio, TX · On-site
$110K - $115K/yr
More than 5 years of SIEM technology such as ArcSight, Splunk, and/or ELK. * More than 3 years with network traffic analysis, ports, and protocols. BA/BS or MA/MS * More than five (5) years of SIEM ...
Content Developer (SIEM Cyber Security)
San Antonio, TX · On-site
$110K - $115K/yr
More than 5 years of SIEM technology such as ArcSight, Splunk, and/or ELK. * More than 3 years with network traffic analysis, ports, and protocols. BA/BS or MA/MS * More than five (5) years of SIEM ...
SIEM experience with one of the following ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA) * Experience providing support to Cybersecurity Operations Cell (CSOC) in ...
SIEM experience with one of the following ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA) * Experience providing support to Cybersecurity Operations Cell (CSOC) in ...
Cyber Data Engineer
Springfield, VA · On-site
$140 - $145K/hr
SIEM Management Own Splunk, Elastic, or ArcSight deployments end-to-end - configs, patches, uptime. Host & VM Administration Linux and Windows systems, hypervisors (ESXi, Hyper-V), and cloud assets.
Cyber Data Engineer
Springfield, VA · On-site
$140 - $145K/hr
SIEM Management Own Splunk, Elastic, or ArcSight deployments end-to-end - configs, patches, uptime. Host & VM Administration Linux and Windows systems, hypervisors (ESXi, Hyper-V), and cloud assets.
More than 5 years of SIEM technology such as ArcSight, Splunk, and/or ELK. * More than 3 years with network traffic analysis, ports, and protocols. BA/BS or MA/MS * More than five (5) years of SIEM ...
More than 5 years of SIEM technology such as ArcSight, Splunk, and/or ELK. * More than 3 years with network traffic analysis, ports, and protocols. BA/BS or MA/MS * More than five (5) years of SIEM ...
... ArcSight, Kafka, various AWS products, Linux servers, and Microsoft servers. * Design, build, and ... Troubleshoot any data flow issues from the SIEM data collection point to the SIEM or designated ...
... ArcSight, Kafka, various AWS products, Linux servers, and Microsoft servers. * Design, build, and ... Troubleshoot any data flow issues from the SIEM data collection point to the SIEM or designated ...
Cyber Data Engineer
Springfield, VA · On-site
$140 - $145K/hr
SIEM Management Own Splunk, Elastic, or ArcSight deployments end-to-end - configs, patches, uptime. Host & VM Administration Linux and Windows systems, hypervisors (ESXi, Hyper-V), and cloud assets.
Cyber Data Engineer
Springfield, VA · On-site
$140 - $145K/hr
SIEM Management Own Splunk, Elastic, or ArcSight deployments end-to-end - configs, patches, uptime. Host & VM Administration Linux and Windows systems, hypervisors (ESXi, Hyper-V), and cloud assets.
... ArcSight, Kafka, various AWS products, Linux servers, and Microsoft servers. * Design, build, and ... Troubleshoot any data flow issues from the SIEM data collection point to the SIEM or designated ...
... ArcSight, Kafka, various AWS products, Linux servers, and Microsoft servers. * Design, build, and ... Troubleshoot any data flow issues from the SIEM data collection point to the SIEM or designated ...
... ArcSight (SIEM technology), Centaur, Noesis, Splunk, ELK, Fidelis, Solera, Niksun, Wireshark and other available tools (commercial and government provided), including OSINT and other classified ...
New
... ArcSight (SIEM technology), Centaur, Noesis, Splunk, ELK, Fidelis, Solera, Niksun, Wireshark and other available tools (commercial and government provided), including OSINT and other classified ...
New
Emerging Threats Analyst
San Antonio, TX · On-site
Analyze current and historical traffic entering the Air Force network using ArcSight (SIEM technology), Centaur, Noesis, Splunk, ELK, Fidelis, Solera, Niksun, Wireshark and other available tools ...
Emerging Threats Analyst
San Antonio, TX · On-site
Analyze current and historical traffic entering the Air Force network using ArcSight (SIEM technology), Centaur, Noesis, Splunk, ELK, Fidelis, Solera, Niksun, Wireshark and other available tools ...
Analyze current and historical traffic entering the Air Force network using ArcSight (SIEM technology), Centaur, Noesis, Splunk, ELK, Fidelis, Solera, Niksun, Wireshark and other available tools ...
New
Analyze current and historical traffic entering the Air Force network using ArcSight (SIEM technology), Centaur, Noesis, Splunk, ELK, Fidelis, Solera, Niksun, Wireshark and other available tools ...
New
Cyber Data Engineer with Security Clearance
Springfield, VA · On-site
$140 - $145K/hr
SIEM Management Own Splunk, Elastic, or ArcSight deployments end-to-end -- configs, patches, uptime. Host & VM Administration Linux and Windows systems, hypervisors (ESXi, Hyper-V), and cloud assets.
Cyber Data Engineer with Security Clearance
Springfield, VA · On-site
$140 - $145K/hr
SIEM Management Own Splunk, Elastic, or ArcSight deployments end-to-end -- configs, patches, uptime. Host & VM Administration Linux and Windows systems, hypervisors (ESXi, Hyper-V), and cloud assets.
Emerging Threats Analyst
San Antonio, TX · On-site
Analyze current and historical traffic entering the Air Force network using ArcSight (SIEM technology), Centaur, Noesis, Splunk, ELK, Fidelis, Solera, Niksun, Wireshark and other available tools ...
Emerging Threats Analyst
San Antonio, TX · On-site
Analyze current and historical traffic entering the Air Force network using ArcSight (SIEM technology), Centaur, Noesis, Splunk, ELK, Fidelis, Solera, Niksun, Wireshark and other available tools ...
Arcsight Siem information
See salary details
$73K - $82.5K
1% of jobs
$82.5K - $92K
2% of jobs
$92K - $101.5K
3% of jobs
$101.5K - $111K
5% of jobs
$116.9K is the 25th percentile. Wages below this are outliers.
$111K - $120.5K
21% of jobs
The median wage is $124.4K / yr.
$120.5K - $130K
41% of jobs
$130.7K is the 75th percentile. Wages above this are outliers.
$130K - $139.5K
7% of jobs
$139.5K - $149K
10% of jobs
$149K - $158.5K
3% of jobs
$158.5K - $168K
2% of jobs
$168K - $177.5K
3% of jobs
$73K
$130.4K
$177.5K
How much do arcsight siem jobs pay per year?
What does an ArcSight SIEM do?
An ArcSight SIEM professional is often responsible for monitoring and analyzing security alerts generated by the ArcSight platform, investigating suspicious activities, and responding to cyber incidents. Daily tasks may include tuning SIEM rules, creating new correlation searches, gathering threat intelligence, and documenting findings for reporting purposes. You’ll also collaborate closely with SOC analysts, IT teams, and management to ensure security best practices are followed and incidents are escalated appropriately. This role requires a detail-oriented mindset and a proactive approach to evolving cybersecurity threats.
What skills and qualifications are needed for an ArcSight SIEM?
To thrive as an ArcSight SIEM professional, you need a deep understanding of security information and event management (SIEM) principles, network protocols, and incident response, often backed by a degree in computer science or cybersecurity. Familiarity with ArcSight SIEM tools, scripting languages, and certifications like GIAC or CompTIA Security+ are commonly required. Attention to detail, strong analytical thinking, and effective communication enhance your ability to detect threats and work within security teams. These skills are crucial for maintaining robust security monitoring and successfully mitigating cyber threats in a fast-paced environment.
What is an ArcSight SIEM?
An ArcSight SIEM job involves managing and configuring Micro Focus ArcSight, a Security Information and Event Management (SIEM) solution used for threat detection, compliance, and security monitoring. Professionals in this role handle log management, event correlation, and incident response to detect and mitigate cybersecurity threats. They also fine-tune security alerts, create custom rules, and integrate ArcSight with other security tools. Strong knowledge of cybersecurity concepts, log analysis, and scripting is often required.

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 12 days ago
General Dynamics Information Technology rating
7.8
Based on 63 frontline employees who took The Breakroom Quiz
86th of 223 rated it services
Job description
Type of Requisition:
PipelineClearance Level Must Currently Possess:
Top Secret/SCIClearance Level Must Be Able to Obtain:
Top Secret SCI + PolygraphPublic Trust/Other Required:
NoneJob Family:
Cyber and IT Risk ManagementJob Qualifications:
Skills:
Analytics, ArcSight SIEM, ElasticSearch, KibanaCertifications:
NoneExperience:
6 + years of related experienceUS Citizenship Required:
YesJob Description:
GDIT is seeking a motivated, career and customer-oriented Cybersecurity Operations Specialist to perform on our Cybersecurity Data Analysis Services team in At Louis, MO.
The team member shall provide cybersecurity data analysis services, which designs, develops, builds, tests, configures, employs, operates, integrates, sustains, and refreshes the Security Information Events Management (SIEM) capability (i.e. Enterprise Audit), long-term analytics platform, log aggregation platform, and the cyber threat intelligence capability, signature development and deployment, and reputation management services. This includes the onboarding of all new and existing IT resources, and ensuring the correct routing of all audit events to mission partners in accordance with Intelligence Community Standards (ICS) 500-27.
Job Duties Include:
- Provide all preventative and corrective maintenance to ensure consistent, reliable, and secure service availability. This includes all actions required to return the service to full operational capability such as vendor RMA processes, removal and proper disposal of broken equipment/software, installation and testing of new equipment/software, and configuration of new equipment/software
- Maintain system availability and reliability with a threshold of 99.99%
- Detect and ticket degradations (volume/velocity) of all SIEM data flows within 60 minutes of the start of the degradation
- Perform day-to-day maintenance, and specific scheduled maintenance activities that result from manufacturers recommended service intervals, alerts, bulletins, available patches, and updates according to agency approved change management processes. This includes maintaining updated documentation, change logs, and service bulletin libraries for all supported equipment and software in the CSOC knowledge management platform
- Execute emergency maintenance actions with sufficient urgency to preclude unacceptable outage durations, approved by the Government prior to execution, and coordinated through and approved by CSOC and ESC government management
- Perform all development, engineering, testing, integration, and implementation actions necessary for major vendor revisions
- Perform continuous engineering assessments to improve the performance, effectiveness, coverage, and maturity of this service.
- Retain documentation regarding loss of event logs (e.g. June 5-7th DNS logs were not ingested from SBU and are lost)
- Configure all assets assigned to this service within the Government Furnished Information - Software Tools list in accordance with all Federal, DoD, IC, and NCE laws, directives, orders, polices, guidance, procedures etc.
- Perform all development, design, engineering, testing, integration, and implementation actions needed for the total integration and interoperability between all applicable assets in the Government Furnished Information - Software Tools list. This includes ensuing all data flows are properly parsed for ingestion/transmission to internal and external automated reporting systems (e.g. JFHQ DoDIN - Joint Incident Management System, DoD CIO - DoD Scorecard/Get to Green reporting, IC CIO - Cybersecurity Performance Evaluation Model reporting, etc.)
- Utilize agency approved ticketing systems to document, track, assign, update, and coordinate all engineering, integration, configuration, and maintenance actions
- Use various monitoring, analysis, and visualization tools to track effectiveness, status, performance metrics, and other information as needed or required by Government staff and contractors assigned Cybersecurity Operations Services and Cybersecurity Readiness Services
Required Skills:
- SIEM experience with one of the following ArcSight, ElasticSearch, Splunk, Event Broker, User Behavioral Analysis (UBA)
- Experience providing support to Cybersecurity Operations Cell (CSOC) in creating alerting rules
- Create SIEM playbooks
- Linux (RHEL) Expert (administration and engineering)
- Proficient in manipulating SIEM filters to better find and analyze potential malicious/atypical activity and reduce false positives
- Experience with content development within ArcSight and Kibana to facilitate Cyber Analysts ability to investigate malicious events
- Creation of ArcSight rules based on use cases of malicious events
- Tuning and aggregation of queries and filters
- Skilled in troubleshooting event flow through Enterprise Audit infrastructure
- Skilled in troubleshooting event format and parsing for ingest into data storage and into SIEM tools
- Active TS/SCI Clearance
- DoW 8570.01-M IAT Level II and CSSP Infrastructure Support certifications
- 6+ years Experience with SIEM and Development Projects
- 6+ years Experience with SIEM support for projects and technical exchange meetings
- 6+ years Experience developing and maintaining enterprise audit projects
Desired Skills:
- Kibana
- Data Analytics
Scheduled Weekly Hours:
40Travel Required:
NoneTelecommuting Options:
OnsiteWork Location:
USA MO St. LouisAdditional Work Locations:
Total Rewards at GDIT:
Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.Our Identity Verification Process:
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.About Our Work:
We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.Join our Talent Community to stay up to date on our career opportunities and events atgdit.com/tc.
Equal Opportunity Employer / Individuals with Disabilities / Protected VeteransWhat General Dynamics Information Technology employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About General Dynamics Information Technology
Sourced by ZipRecruiter
GDIT is a global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense, and intelligence community. Its 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. The company operates across 50+ countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber, and application development.
Industry
It services
Company size
10,000+ Employees
Headquarters location
Falls Church, VA, US