1

Logrhythm Siem Jobs (NOW HIRING)

$106K - $107K/yr

SIEM platforms * LogRhythm * ACAS, Nessus, and SCAP * Mandatory and role-based access control concepts (e.g., SELinux extensions to RHEL, PitBull, AppArmor, and Sentris) * Video teleconferencing (VTC ...

Hands-on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment. * Experience independently ...

... IPS, LogRhythm Enterprise Security Manager, ACAS, End-Point Security Systems (ESS)/Host-Based ... Experience with SIEM, IDS/IPS, EDR, ENS (Trellix), and ACAS. Must be detail oriented and possess ...

... IPS, LogRhythm Enterprise Security Manager, ACAS, End-Point Security Systems (ESS)/Host-Based ... Experience with SIEM, IDS/IPS, EDR, ENS (Trellix), and ACAS. Must be detail oriented and possess ...

... SIEM platforms (Splunk, Sentinel, LogRhythm, etc.), EDR suites (CrowdStrike, Defender), and network security tools. • Familiarity with cloud-security architectures (Azure, AWS, Google) and ...

... SIEM) and create/tailor complex event alarms/rules and summary reports * Assist in analyzing ... SEIMs, Logrhythm, ACAS/Nessus/SCAP, mandatory/role-based access control concepts (e.g. SE Linux ...

Showing results 21-40

Logrhythm Siem information

See salary details

$39.5K

$107.3K

$141K

How much do logrhythm siem jobs pay per year?

As of Aug 15, 2026, the average yearly pay for logrhythm siem in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What are common challenges faced by LogRhythm SIEM analysts, and how can they address them?

LogRhythm SIEM analysts often encounter challenges such as managing high volumes of alerts, fine-tuning correlation rules to reduce false positives, and keeping up with evolving cyber threats. To address these issues, analysts regularly review and update detection rules, collaborate with IT and security teams to understand the organization's risk landscape, and utilize automation features within LogRhythm to streamline repetitive tasks. Continuous professional development and staying current with threat intelligence are also essential for maintaining effective SIEM operations.

What is the difference between Logrhythm Siem vs Security Analyst?

AspectLogrhythm SiemSecurity Analyst
CertificationsSIEM-related certifications (e.g., Certified SOC Analyst)Security certifications (e.g., CompTIA Security+, CISSP)
Work EnvironmentSecurity operations centers, monitoring security alertsAnalyzing security incidents, investigating threats
Employer & IndustryIT security firms, large enterprisesCorporate security teams, government agencies

Logrhythm Siem professionals focus on managing SIEM tools like Logrhythm to monitor and analyze security data, while Security Analysts interpret security alerts, investigate incidents, and respond to threats. Both roles require security knowledge, but Logrhythm Siem specialists are more technical with SIEM platforms, whereas Security Analysts have broader security responsibilities.

What is LogRhythm SIEM?

LogRhythm SIEM (Security Information and Event Management) is a cybersecurity platform designed to collect, analyze, and manage security data from across an organization’s IT environment. It helps detect, respond to, and neutralize threats by aggregating logs and events from various sources and providing real-time monitoring and alerting. LogRhythm SIEM supports compliance, incident investigation, and threat detection through advanced analytics and automated workflows, making it a vital tool for security operations centers (SOCs).

What are the key skills and qualifications needed to thrive as a LogRhythm SIEM analyst?

To thrive as a LogRhythm SIEM Analyst, you need a solid understanding of cybersecurity principles, network protocols, and experience with security event monitoring, often supported by a degree in information security or related certifications like CompTIA Security+ or GIAC. Proficiency with the LogRhythm SIEM platform, log analysis tools, and scripting languages such as Python or PowerShell is typically required. Analytical thinking, attention to detail, and strong communication skills help analysts identify threats and collaborate with IT teams. These skills are crucial for detecting cyber threats quickly, minimizing risks, and ensuring robust organizational security.
More about Logrhythm Siem jobs

What are the most commonly searched types of Logrhythm Siem jobs?

The most popular types of Logrhythm Siem jobs are:

Infographic showing various Logrhythm Siem job openings in the United States as of August 2026, with employment types broken down into 91% Full Time, 2% Part Time, and 7% Contract. Highlights an 76% Physical, 10% Hybrid, and 14% Remote job distribution, with an average salary of $107,334 per year, or $51.6 per hour.

Detection and Response Engineer (SPLUNK)

Coalfire

Charleston, WV • Remote

$80K - $134K/yr

Full-time

Posted 25 days ago


Job description

About Coalfire
 
Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.
 
But that’s not who we are – that’s just what we do.
 
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

Why Join Us    

We are seeking a Detection and Response Engineer to join our Defensive Services team, supporting SIEM monitoring and alerting, threat hunting, and purple team activities that help our clients meet both federal compliance and commercial security requirements. If you're passionate about defending organizations against evolving threats, driven to innovate, and thrive in a collaborative, high-performing environment, we'd love to have you on our team. Join us in our mission to make the world a safer place through proactive cybersecurity and operational excellence.

What You'll Do
  • Collect, analyze, and operationalize threat intelligence to inform proactive detection and threat‑hunting activities, driving measurable security posture improvements across client environments.
  • Develop, optimize, and maintain custom detection and threat‑hunting queries across two or more SIEM platforms, tuning alerts for improved fidelity and building dashboards and saved searches that support repeatable, operational use cases.
  • Plan and lead cyclical, hypothesis‑driven threat hunts using threat intelligence and behavior‑based analytics; identify detection gaps and telemetry blind spots, and translate hunt outcomes into detection improvements, alert tuning, and updated runbooks. 
What You'll Bring
  • 2–4 years of experience operating within large‑scale enterprise security environments, including exposure to cloud‑hosted or hybrid infrastructures.
  • Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations.
  • Hands‑on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment.
  • Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds.
  • Proven ability to independently investigate and respond to security alerts, performing deep‑dive analysis across multiple log sources to determine scope, root cause, and impact.
  • Experience escalating confirmed or high‑confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers.
  • Experience conducting structured and cyclical threat‑hunting activities using hypothesis‑driven and behavior‑based methodologies.
  • Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts.
  • Hands‑on experience developing, optimizing, and maintaining custom detection and threat‑hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic.
  • Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs.
  • Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly.
  • Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials.
  • Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor.
  • Critical thinking skills to balance robust security requirements against mission objectives.
  • Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments.
  • Experience utilizing a Detection-as-Code framework
  • Experience working with NIST 800-53 environments 

REQUIRED CERTIFICATIONS: 

At least one of the following:  

  • Splunk Enterprise Certified Administrator 
  • Splunk Enterprise Security Certified Administrator 
  • SumoLogic Administrator 
  • Microsoft Security Operations Associate 
  • Elastic Stack Certified Administrator 
Bonus Points
  • Professional services background: Prior experience supporting external clients from within a consulting or professional services organization. 
  • Automation capabilities: Experience automating workflows in GitLab or GitHub with Terraform and Ansible. 
  • Compliance frameworks: Understanding of FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards.
The salary range listed is a reasonable estimate of the compensation range for this role based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs.
 
Why You’ll Want to Join Us
 
At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.
 
Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.
 
At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at HumanResourcesMB@coalfire.com.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.