1

Siem Consultant Jobs (NOW HIRING)

Content Developer (SIEM Cyber Security)

San Antonio, TX ยท On-site

$110K - $115K/yr

STS Systems Defense, LLC (SSD) is a government consulting and contracting firm supporting federal agencies and military installations across the U.S. We are seeking a Content Developer (SIEM ...

Senior SIEM Engineer

Chandler, AZ ยท On-site

$116K - $160K/yr

Job#: 3049131 Senior SIEM Engineer Location: Chandler, Arizona (Onsite) Employment Type: Contract ... Everforth Apex has a dedicated customer service team for our Consultants that can address questions ...

$140 - $230/hr

... SIEM and MDR Enablement practice, and we are seeking a proven technical leader to help shape and ... As a Senior Manager / Principal Consultant, you will oversee a team of detection engineers and ...

... Consulting and Planning, Network design, Implementation&Administration * Website * Industry ... Founded 2009 SIEM intelligence analyst to provide ongoing knowledge sharing and information flow ...

Showing results 21-40

Siem Consultant information

See salary details

$10

$49

$118

How much do siem consultant jobs pay per hour?

As of Sep 5, 2026, the average hourly pay for siem consultant in the United States is $49.72, according to ZipRecruiter salary data. Most workers in this role earn between $24.28 and $62.50 per hour, depending on experience, location, and employer.

What is a SIEM consultant?

A SIEM Consultant is a cybersecurity professional who specializes in the implementation, configuration, and optimization of Security Information and Event Management (SIEM) systems. These experts help organizations detect, analyze, and respond to security threats by setting up and managing SIEM tools that collect and analyze log data from various sources across the network. SIEM Consultants often assess security requirements, design solutions tailored to client needs, and provide ongoing support to ensure the effectiveness of security monitoring. Their goal is to enhance an organization's ability to identify and mitigate cyber threats in real time.

What are the key skills and qualifications needed to thrive as a SIEM consultant?

To thrive as a SIEM Consultant, you need a strong understanding of cybersecurity principles, log analysis, incident response, and experience with security information and event management (SIEM) platforms, typically backed by a relevant degree or certifications like CompTIA Security+ or CISSP. Familiarity with SIEM tools such as Splunk, IBM QRadar, or ArcSight, as well as scripting languages and threat intelligence systems, is commonly required. Analytical thinking, problem-solving abilities, and effective communication are essential soft skills for translating technical findings into actionable recommendations. These skills and qualifications are crucial for effectively detecting, analyzing, and responding to security threats, helping organizations strengthen their cyber defenses.

What are some common challenges faced by SIEM consultants when integrating SIEM solutions into existing IT environments?

SIEM Consultants often encounter challenges such as managing data normalization from diverse log sources, ensuring compatibility with legacy systems, and fine-tuning correlation rules to minimize false positives. Effective integration requires close collaboration with IT and security teams to understand existing workflows and infrastructure. Consultants must also prioritize continuous monitoring and tuning post-deployment to adapt to evolving security threats and maintain optimal system performance.

What is the difference between Siem Consultant vs Security Analyst?

AspectSiem ConsultantSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, GIAC certifications
Work EnvironmentConsulting firms, IT security companies, client sitesIn-house security teams, cybersecurity departments
Primary FocusImplementing and configuring SIEM solutions, advising clientsMonitoring security alerts, incident response, threat analysis
Employer & Industry UsageIT consulting firms, cybersecurity service providersLarge corporations, government agencies, financial institutions

While both roles involve cybersecurity, a Siem Consultant primarily focuses on deploying and customizing SIEM systems for clients, whereas a Security Analyst concentrates on monitoring security events and responding to threats within an organization. The roles often overlap in certifications and work environments but differ in daily responsibilities and objectives.

More about Siem Consultant jobs
Infographic showing various Siem Consultant job openings in the United States as of August 2026, with employment types broken down into 90% Full Time, 6% Part Time, and 4% Contract. Highlights an 85% Physical, 4% Hybrid, and 11% Remote job distribution, with an average salary of $103,425 per year, or $49.7 per hour.

Content Developer (SIEM Cyber Security)

Bristol Bay Native Corporation

San Antonio, TX โ€ข On-site

$110K - $115K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 5 days ago


Job description

STS Systems Defense, LLC (SSD) is a government consulting and contracting firm supporting federal agencies and military installations across the U.S. We are seeking a Content Developer (SIEM Cyber Security) at Lackland AFB in San Antonio, TX.
What You'll Do:
  • Analyze DCO events.
  • Apply current industry SIEM best-practices.
  • Use security alerts correlated with log enrichment data to enhance the operator's ability to identify real attacks.
  • Establish security control effectiveness and monitor for unauthorized outbound connections
  • Create detections by analyzing log data across the enterprise. (CDRL A007)
  • Develop dashboards and visualizations to identify adversarial activity. (CDRL A007)
  • Use log data to establish and implement virtual tripwires for early detection.
  • Analyze and ingest security logs into the SIEM in order to optimize for performance of the SIEM.
  • Conduct designing, implementing, and testing of various SIEM solutions. (CDRL A007)
  • Create and support the creation of SIEM Use Cases and understand what alerts and log enrichment is necessary to meet the required acceptable false positive rate. (CDRL A008)
  • Create, test, and validate filters and rules. (CDRL A007)
  • Build and implement event correlation rules, logic, and content in the SIEM. (CDRL A007)
  • Tune SIEM event correlation rules and logic to filter out security events associated with known and well established network behavior, known false positives and/or known errors.
  • Analyze malware threats to develop behavior based detections that alert and/or prevent malicious activity.
  • Automate tasks in the SIEM using a common programming or scripting language.
  • Create scheduled and ad-hoc reporting with SEIM tools. (CDRL A007 and A008)
  • Create and maintain SIEM documentation. (CDRL A008)
  • Develop and execute a process to review and maintain SIEM resources such as rules, filters, lists, trends and reports.
  • Utilize SIEM to develop metrics collection, analysis, and create reports upon request.
  • Provide training to government personnel as requested.
  • Provide knowledge transfer of tools, processes and procedures to government personnel as requested.
  • Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.
  • Maintain currency on latest industry trends and provide operational reports/assessments for development of tactics, techniques, and procedures. (CDRL A002)
  • Create, document, and report metrics for analysis to improve weapon system processes and mission execution. (CDRL A009).
  • Support operational leaderships tasking as it relates to Content Development functions and responsibilities

What You Bring:
Requirements:
  • DoDD 8570.01-M/8140.01 I AT Level III CND
  • Active TS/SCI
  • GMLE Certification (GIAC Machine Learning Engineer) OR Degree in Computer Science
  • More than 5 years of SIEM technology such as ArcSight, Splunk, and/or ELK.
  • More than 3 years with network traffic analysis, ports, and protocols. BA/BS or MA/MS
  • More than five (5) years of SIEM technology such as Arcsight, Splunk and/or ELK. Including, but not limited to, log handling, reports, filters, rule creation.
  • Extensive knowledge with IDS/IPS systems currently in use by the Department of Defense (DoD), Services, and Agencies (i.e., Air Force, Navy, Army, DC3, DISA).
  • More than three (3) years of experience with Network Traffic Analysis; ports and protocols. SANS GCDA or equivalent certification(s).
  • Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects)

Desired:
  • Additionally, more than one (1) year of experience with Security, Orchestration, Automation, and Response (SOAR) platforms such as Phantom and/or Demisto. Proficient in Python and PowerShell.

What We Offer:
STS Systems Defense, LLC offers a competitive benefits package to include: paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.
SSD is an Equal Opportunity Employer. Employment decisions are made without regard to any protected category. Hiring preference will be given to BBNC shareholders, their spouses and descendants and Alaska Natives in accordance with Public Law 93-638.