1

Siem Detection Engineer Jobs (NOW HIRING)

Responsibilities : • Design, engineer, and implement security detection initiatives under the cybersecurity team lead. • Develop new detection logic for SIEM (Microsoft Sentinel) and network ...

Our team operates detection engineering as code, and we are looking for someone who thrives in a ... Responsibilities Design and implement detections using a detection-as-code approach across SIEM (e ...

Detection Engineer The Opportunity: Are you ready to take an active role in cyber defense for a ... Experience creating, modifying, and tuning IDS signatures or SIEM correlation searches, and using ...

Responsibilities : • Develop custom detection logic across SIEM, EDR, and other security tooling within a cutting-edge technology stack. • Leverage threat modeling, detection engineering ...

As a Detection Engineer on our Joint Cyber Center (JCC) Cyberspace Warning & Operations Center ... Experience creating, modifying, and tuning IDS signatures or SIEM correlation searches, and using ...

Utilize tools such as SIEM, EDR, and custom-built solutions to enhance detection accuracy and ... Reverse-engineer malware, analyze malicious artifacts, and provide actionable guidance to mitigate ...

Our team operates detection engineering as code, and we are looking for someone who thrives in a ... Responsibilities • Design and implement detections using a detection-as-code approach across SIEM ...

next page

Showing results 1-20

Siem Detection Engineer information

See salary details

$25

$53

$76

How much do siem detection engineer jobs pay per hour?

As of Aug 23, 2026, the average hourly pay for siem detection engineer in the United States is $53.63, according to ZipRecruiter salary data. Most workers in this role earn between $43.27 and $62.26 per hour, depending on experience, location, and employer.

What is a SIEM Detection Engineer?

A SIEM Detection Engineer is a cybersecurity professional responsible for designing, implementing, and maintaining Security Information and Event Management (SIEM) systems. They create and fine-tune detection rules to identify suspicious activities and potential threats within an organization's IT environment. Their role involves analyzing security logs, developing automated alerts, and collaborating with incident response teams to ensure rapid detection and response to security incidents. By continuously updating detection mechanisms, they help protect organizations from evolving cyber threats.

What are the key skills and qualifications needed to thrive as a SIEM Detection Engineer?

To thrive as a SIEM Detection Engineer, you need a strong background in cybersecurity, expertise in threat analysis, and experience with SIEM platforms, typically supported by a degree in computer science or related field and industry certifications like CISSP or GIAC. Mastery of tools such as Splunk, QRadar, or ArcSight, and scripting languages like Python or PowerShell, is commonly required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for investigating incidents and collaborating with teams. These skills ensure proactive threat detection, rapid incident response, and the overall security of an organization's IT infrastructure.

What are some common challenges faced by SIEM Detection Engineers when tuning detection rules, and how can they address them?

SIEM Detection Engineers often face challenges such as minimizing false positives, adapting to evolving threats, and ensuring detection rules remain relevant as the organization's environment changes. To address these challenges, engineers regularly review and refine correlation rules based on incident feedback, collaborate closely with SOC analysts and threat intelligence teams, and stay updated on emerging attack techniques. Continuous testing and validation of rules, as well as leveraging automation where possible, are key practices to maintain effective and actionable alerts.

What is the difference between Siem Detection Engineer vs Security Analyst?

AspectSiem Detection EngineerSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentFocus on SIEM tools, log analysis, threat detectionBroader security monitoring, incident response, policy enforcement
Employer & Industry UsageIT security teams, cybersecurity firms, large enterprisesIT departments, security operations centers, government agencies

While both roles involve cybersecurity, a Siem Detection Engineer specializes in configuring and managing SIEM systems for threat detection, whereas a Security Analyst has a broader focus on monitoring security events, analyzing incidents, and implementing security policies. The roles often overlap but differ in scope and technical focus.

More about Siem Detection Engineer jobs

What cities are hiring for Siem Detection Engineer jobs?

Cities with the most Siem Detection Engineer job openings:

What states have the most Siem Detection Engineer jobs?

States with the most job openings for Siem Detection Engineer jobs include:

What job categories do people searching Siem Detection Engineer jobs look for?

The top searched job categories for Siem Detection Engineer jobs are:

Infographic showing various Siem Detection Engineer job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, 2% Part Time, and 4% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $111,552 per year, or $53.6 per hour.

Security Consultant (Detection Engineer) - Contract - Remote

SUNSHINE ENTERPRISE USA LLC

Columbia, SC

Contractor

Re-posted 19 days ago


Job description

Security Architect - Consultant (Detection Engineer) Location: Remote Interview Process: 1 round, Virtual/Online - potential for a 2nd round onsite as needed Duration: 12 Months Employment Type: Contract Experience Required: 08+ Years Candidate location: No SC residency required. Open to nationwide candidates. (Candidates with the ability to work onsite when needed will be given preference.) Project Scope: Seeking an experienced Detection Engineer / Security Architect Consultant to support enterprise security monitoring, threat detection, and detection engineering initiatives

The ideal candidate will be responsible for developing, tuning, and maintaining security detections, identifying monitoring gaps, and enhancing overall threat visibility across a large-scale security environment. Key Responsibilities: Review, analyze, and tune existing SIEM detection rules. Perform detection coverage gap assessments and identify areas for improvement.

Design, develop, and implement new detection rules and monitoring solutions. Monitor threat intelligence sources and translate emerging threats into actionable detections. Collaborate with SOC Analysts and Threat Hunters to improve detection capabilities.

Develop and maintain documentation, runbooks, workflows, and troubleshooting guides. Support SOAR integrations and automation initiatives. Coordinate with security engineering teams, SOC personnel, and stakeholders.

Participate in continuous improvement efforts to strengthen enterprise security monitoring. Required Skills & Experience: 5+ years of experience supporting large-scale IT environments and/or system deployments. Strong experience with detection engineering, threat detection development, and tuning.

5+ years of scripting and automation experience using: Python PowerShell Bash Similar scripting languages Experience with dashboard development and reporting. Strong understanding of: Sigma YARA Other industry-standard detection languages Familiarity with the MITRE ATT&CK Framework. Experience documenting processes, procedures, and operational workflows.

Preferred Skills: Experience with Palo Alto Cortex XSIAM. Strong knowledge of Windows and Linux artifacts. Experience working in multi-tenant security environments.

Experience supporting enterprise or multi-agency security programs. Strong customer-facing communication and stakeholder engagement skills. Education: Bachelor's Degree in Information Technology, Information Security, or related field.

Eight years of relevant experience may be substituted for the degree requirement. Certification: CISSP CISA CEH OSCP GPEN Vendor-specific Detection Engineering Certifications Other advanced cybersecurity certifications