Analyze current and historical traffic entering the Air Force network using ArcSight (SIEM technology), Centaur, Noesis, Splunk, ELK, Fidelis, Solera, Niksun, Wireshark and other available tools ...
Analyze current and historical traffic entering the Air Force network using ArcSight (SIEM technology), Centaur, Noesis, Splunk, ELK, Fidelis, Solera, Niksun, Wireshark and other available tools ...
Security Engineer
Reston, VA · On-site
Perform analytical work using IT security technology such as SIEM Products (Q1 Radar, Arcsight, etc} * Asses existing network topology and identify key system flaws * Develop detailed supporting ...
Security Engineer
Reston, VA · On-site
Perform analytical work using IT security technology such as SIEM Products (Q1 Radar, Arcsight, etc} * Asses existing network topology and identify key system flaws * Develop detailed supporting ...
Cyber Security Analyst
New York, NY · On-site
... ArcSight, we'd prefer to have someone with extensive knowledge with those tools but can train you up if your proficient with other tools. You should be well-versed with SIEM, IDS/IPS, firewalls ...
Cyber Security Analyst
New York, NY · On-site
... ArcSight, we'd prefer to have someone with extensive knowledge with those tools but can train you up if your proficient with other tools. You should be well-versed with SIEM, IDS/IPS, firewalls ...
Senior Security Operations Engineer
$125K - $171K/yr
Experience with Security Information and Event Management (SIEM) tools like ArcSight, QRadar, Splunk, etc. * Experience with Vulnerability scanners like Nessus, MVM, Qualys , etc. * Knowledge of ...
Quick apply
Senior Security Operations Engineer
$125K - $171K/yr
Experience with Security Information and Event Management (SIEM) tools like ArcSight, QRadar, Splunk, etc. * Experience with Vulnerability scanners like Nessus, MVM, Qualys , etc. * Knowledge of ...
Security Engineer
Reston, VA · On-site
Perform analytical work using IT security technology such as SIEM Products (Q1 Radar, Arcsight, etc} * Asses existing network topology and identify key system flaws * Develop detailed supporting ...
Security Engineer
Reston, VA · On-site
Perform analytical work using IT security technology such as SIEM Products (Q1 Radar, Arcsight, etc} * Asses existing network topology and identify key system flaws * Develop detailed supporting ...
... Cribl, ArcSight, Kafka, various AWS products, Linux servers, and Microsoft servers. • Design ... SIEM data collection point to the SIEM or designated long-term storage destination. • ...
... Cribl, ArcSight, Kafka, various AWS products, Linux servers, and Microsoft servers. • Design ... SIEM data collection point to the SIEM or designated long-term storage destination. • ...
Moorestown, NJ Duration: Full Time : Overall experience of 8+ years in the field of information security with 2+years of experience in handling Security Analytics/SIEM tools such as Arcsight ...
Moorestown, NJ Duration: Full Time : Overall experience of 8+ years in the field of information security with 2+years of experience in handling Security Analytics/SIEM tools such as Arcsight ...
IT SECURITY ASSOCIATE
Jacksonville, FL · On-site
$25/hr
Correlate and analyze events using Splunk and ArcSight Security Information and Event Management (SIEM) tool to detect IT security incidents. Independently follow detailed operational process and ...
IT SECURITY ASSOCIATE
Jacksonville, FL · On-site
$25/hr
Correlate and analyze events using Splunk and ArcSight Security Information and Event Management (SIEM) tool to detect IT security incidents. Independently follow detailed operational process and ...
Cyber Data Engineer
Springfield, VA · On-site
Preferred : • SIEM experience with Splunk, Elastic, or ArcSight • Familiarity with Cribl for data aggregation and normalization • Scripting in Python, Bash, or PowerShell • Public cloud ...
Cyber Data Engineer
Springfield, VA · On-site
Preferred : • SIEM experience with Splunk, Elastic, or ArcSight • Familiarity with Cribl for data aggregation and normalization • Scripting in Python, Bash, or PowerShell • Public cloud ...
Cyber Data Engineer
Springfield, VA · On-site
... SIEM experience with Splunk, Elastic, or ArcSight • Familiarity with Cribl for data aggregation and normalization • Scripting in Python, Bash, or PowerShell • Public cloud experience (AWS, GCP ...
Cyber Data Engineer
Springfield, VA · On-site
... SIEM experience with Splunk, Elastic, or ArcSight • Familiarity with Cribl for data aggregation and normalization • Scripting in Python, Bash, or PowerShell • Public cloud experience (AWS, GCP ...
Monitor security events using Azure Sentinel, ArcSight, and other SIEM tools * Perform initial triage and classification of security incidents * Analyze phishing and spam emails, reviewing headers ...
Monitor security events using Azure Sentinel, ArcSight, and other SIEM tools * Perform initial triage and classification of security incidents * Analyze phishing and spam emails, reviewing headers ...
Monitor security events using Azure Sentinel, ArcSight, and other SIEM tools * Perform initial triage and classification of security incidents * Analyze phishing and spam emails, reviewing headers ...
Monitor security events using Azure Sentinel, ArcSight, and other SIEM tools * Perform initial triage and classification of security incidents * Analyze phishing and spam emails, reviewing headers ...
Monitor security events using Azure Sentinel, ArcSight, and other SIEM tools * Perform initial triage and classification of security incidents * Analyze phishing and spam emails, reviewing headers ...
Monitor security events using Azure Sentinel, ArcSight, and other SIEM tools * Perform initial triage and classification of security incidents * Analyze phishing and spam emails, reviewing headers ...
Security Analyst
Dallas, TX · On-site
TBD Required experience with SIEM Tools at least 2: HP ArcSight Security Manager (ESM) Qradar LogRhythm SolarWinds Splunk Enterprise Required experience with Scanning Tools at least 2: Wireshark ...
Security Analyst
Dallas, TX · On-site
TBD Required experience with SIEM Tools at least 2: HP ArcSight Security Manager (ESM) Qradar LogRhythm SolarWinds Splunk Enterprise Required experience with Scanning Tools at least 2: Wireshark ...
Direct Security Information and Event Management (SIEM) engineering including Splunk, ArcSight, Microsoft Sentinel, and Azure Data Explorer (ADX) * Oversee CSSP tool suite engineering including ...
Direct Security Information and Event Management (SIEM) engineering including Splunk, ArcSight, Microsoft Sentinel, and Azure Data Explorer (ADX) * Oversee CSSP tool suite engineering including ...
Information Technology Project Manager, Senior (CSSP Engineering Team Lead) P06
Indianapolis, IN · On-site
$99K - $134K/yr
Direct Security Information and Event Management (SIEM) engineering including Splunk, ArcSight, Microsoft Sentinel, and Azure Data Explorer (ADX) * Oversee CSSP tool suite engineering including ...
Information Technology Project Manager, Senior (CSSP Engineering Team Lead) P06
Indianapolis, IN · On-site
$99K - $134K/yr
Direct Security Information and Event Management (SIEM) engineering including Splunk, ArcSight, Microsoft Sentinel, and Azure Data Explorer (ADX) * Oversee CSSP tool suite engineering including ...
Cyber Security Consultant
Sacramento, CA · On-site
In-depth knowledge of architecture, engineering, and operations of at least one enterprise SIEM platform (e.g. Nitro/McAfee Enterprise Security Manager, ArcSight, QRadar, LogLogic, Splunk)
Cyber Security Consultant
Sacramento, CA · On-site
In-depth knowledge of architecture, engineering, and operations of at least one enterprise SIEM platform (e.g. Nitro/McAfee Enterprise Security Manager, ArcSight, QRadar, LogLogic, Splunk)
Network IPS/IDS, Firewalls, SIEM. * Non vendor specific security certifications are a plus, CISSP preferred. * ArcSight Administration including creation and management of custom connectors ...
Network IPS/IDS, Firewalls, SIEM. * Non vendor specific security certifications are a plus, CISSP preferred. * ArcSight Administration including creation and management of custom connectors ...
Utilize SIEM tools such as ArcSight or Splunk for big data analytics and security monitoring Qualifications Required: * Active TS/SCI clearance with CI Poly * Bachelor's degree in IT or related field ...
Utilize SIEM tools such as ArcSight or Splunk for big data analytics and security monitoring Qualifications Required: * Active TS/SCI clearance with CI Poly * Bachelor's degree in IT or related field ...
Network Security Engineer
$107K - $146K/yr
ArcSight * Elastic SIEM Knowledge of: * SOC operations * Threat hunting * Log correlation * MITRE ATT&CK framework * Incident response * Threat intelligence integration Cloud & Infrastructure ...
Network Security Engineer
$107K - $146K/yr
ArcSight * Elastic SIEM Knowledge of: * SOC operations * Threat hunting * Log correlation * MITRE ATT&CK framework * Incident response * Threat intelligence integration Cloud & Infrastructure ...
Arcsight Siem information
See salary details
$73K - $82.5K
1% of jobs
$82.5K - $92K
2% of jobs
$92K - $101.5K
3% of jobs
$101.5K - $111K
5% of jobs
$116.9K is the 25th percentile. Wages below this are outliers.
$111K - $120.5K
21% of jobs
The median wage is $124.4K / yr.
$120.5K - $130K
41% of jobs
$130.7K is the 75th percentile. Wages above this are outliers.
$130K - $139.5K
7% of jobs
$139.5K - $149K
10% of jobs
$149K - $158.5K
3% of jobs
$158.5K - $168K
2% of jobs
$168K - $177.5K
3% of jobs
$73K
$130.4K
$177.5K
How much do arcsight siem jobs pay per year?
What does an ArcSight SIEM do?
An ArcSight SIEM professional is often responsible for monitoring and analyzing security alerts generated by the ArcSight platform, investigating suspicious activities, and responding to cyber incidents. Daily tasks may include tuning SIEM rules, creating new correlation searches, gathering threat intelligence, and documenting findings for reporting purposes. You’ll also collaborate closely with SOC analysts, IT teams, and management to ensure security best practices are followed and incidents are escalated appropriately. This role requires a detail-oriented mindset and a proactive approach to evolving cybersecurity threats.
What skills and qualifications are needed for an ArcSight SIEM?
To thrive as an ArcSight SIEM professional, you need a deep understanding of security information and event management (SIEM) principles, network protocols, and incident response, often backed by a degree in computer science or cybersecurity. Familiarity with ArcSight SIEM tools, scripting languages, and certifications like GIAC or CompTIA Security+ are commonly required. Attention to detail, strong analytical thinking, and effective communication enhance your ability to detect threats and work within security teams. These skills are crucial for maintaining robust security monitoring and successfully mitigating cyber threats in a fast-paced environment.
What is an ArcSight SIEM?
An ArcSight SIEM job involves managing and configuring Micro Focus ArcSight, a Security Information and Event Management (SIEM) solution used for threat detection, compliance, and security monitoring. Professionals in this role handle log management, event correlation, and incident response to detect and mitigate cybersecurity threats. They also fine-tune security alerts, create custom rules, and integrate ArcSight with other security tools. Strong knowledge of cybersecurity concepts, log analysis, and scripting is often required.

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 9 days ago
Job description
STS Systems Support, LLC (SSS) is a government consulting and contracting firm supporting federal agencies and military installations across the U.S. We are seeking an Emerging Threats Analyst to support our mission at Lackland AFB in San Antonio, TX.
What You'll Do:
- Analyze current and historical traffic entering the Air Force network using ArcSight (SIEM technology), Centaur, Noesis, Splunk, ELK, Fidelis, Solera, Niksun, Wireshark and other available tools (commercial and government provided), including OSINT and other classified reporting databases.
- Determine if the network traffic requires further investigation of the Air Force asset(s) in question.
- Correlate various data points using historical network traffic, operational events, reporting patterns, and other data to discern anomalies, patterns, or trends.
- Perform post intrusion correlation to ensure current incidents are contained and have not spread to other Air Force Bases, networks or enclaves.
- Provide tipper information to other organizations when required.
- Collect weekly and monthly metrics (or as required) and trend information for organizational reports (as required) and longterm analysis.
- Continuously review (24/7/365) NCTOC reports, Tippers, SIGACTS, emails and other selfreported problems and events.
- Conduct research and gather threat intelligence on advanced threat actors.
- Conduct Data Analysis for mission discovery of cyber threats and conduct characterization and attribution of those threats.
- Identify cyber threats, trends, and new developments on various cyber security topics by analyzing raw intelligence and data which includes geopolitical and transnational events.
- Present results to analysts and operators and train them how to recognize changes in operational environment likely to cause mission success or failure.
- Create visual displays conveying situational awareness and engagement effectiveness assessments to the operational crews. (CDRL A008)
- Analyze current allsource intelligence from applicable intelligence community sources concerning adversary telecommunication and computer network systems supporting adversary C4I processes. Provide analytical reports and state findings or integrate conclusions into overall squadron generated composite reports, briefings, and target profile folders.
- Provide analytic tradecraft to gathered intelligence in a consistent manner.
- Develop and refine cyber threat intelligence collection and analysis processes.
- Assist crews and analysts to determine most efficient means of execution (course of action) against malware, adversary TTPs, threat actors and the MITRE attack framework with respect to AFCERT weapons.
- Write technical operational reports associated with systems that extensively involve telecommunications and telecommunications interfaces, IT, computer network defense (CND), computer networking, and network security. (CDRL A002)
- Make analytical predictions about cyber actors and their future activities based on available data. Recognize threats by performing relevant research and data analysis using both internal and external tools and resources.
- Produce detailed intelligence analysis reports on cyber threats with a potential to impact AF networks, systems and enclaves. (CDRL A008)
- Present relevant findings to both technical and nontechnical audiences.
- Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.
What You Bring:
Requirements:
- DoDD 8570.01M/8140.01 I AT Level III CND
- Active TS/SCI
- Formal intelligence analysis training and government experience.
- BA/BS or MA/MS
- Formal Intelligence Analysis training and government experience preferred.
- Previous experience working with hunting tools and technologies.
- Understanding of Networking (including the OSI Model, TCP/IP, DNS, HTTP, SMTP).
- Experience with open source Malware Analysis platforms (Assemblyline, Cuckoo, Malboxes).
- Experience with one or more commercial Malware Analysis platforms (Joe Sandbox, VirusTotal, etc.) knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community
- (e.g., Open Source projects).
What We Offer:
STS Systems Support, LLC (SSS) offers a competitive benefits package to include paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.
SSS is an Equal Opportunity Employer. Employment decisions are made without regard to any protected category. Hiring preference will be given to BBNC shareholders, their spouses and descendants and Alaska Natives in accordance with Public Law 93-638
About BRS
Sourced by ZipRecruiter
Industry
Office supplies and stationery stores
Company size
1 - 10 Employees
Headquarters location
Brentwood, TN, US
Year founded
2001