1

Siem Detection Engineer Jobs (NOW HIRING)

... NG SIEM, plus emerging AI-assisted tooling * Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success * Accelerate your ...

Responsibilities : โ€ข Design, engineer, and implement security detection initiatives under the cybersecurity team lead. โ€ข Develop new detection logic for SIEM (Microsoft Sentinel) and network ...

Responsibilities : โ€ข Develop custom detection logic across SIEM, EDR, and other security tooling within a cutting-edge technology stack. โ€ข Leverage threat modeling, detection engineering ...

Support the periodic review and tuning of existing SIEM detection content, identifying ... engineers, ensuring changes are tested, documented, and implemented in accordance with change ...

Jr SIEM/UEBA Engineer

Washington, DC ยท On-site

$95K - $125K/yr

Support the periodic review and tuning of existing SIEM detection content, identifying ... engineers, ensuring changes are tested, documented, and implemented in accordance with change ...

Support the periodic review and tuning of existing SIEM detection content, identifying ... engineers, ensuring changes are tested, documented, and implemented in accordance with change ...

next page

Showing results 1-20

Siem Detection Engineer information

See salary details

$25

$53

$76

How much do siem detection engineer jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for siem detection engineer in the United States is $53.63, according to ZipRecruiter salary data. Most workers in this role earn between $43.27 and $62.26 per hour, depending on experience, location, and employer.

What is a SIEM Detection Engineer?

A SIEM Detection Engineer is a cybersecurity professional responsible for designing, implementing, and maintaining Security Information and Event Management (SIEM) systems. They create and fine-tune detection rules to identify suspicious activities and potential threats within an organization's IT environment. Their role involves analyzing security logs, developing automated alerts, and collaborating with incident response teams to ensure rapid detection and response to security incidents. By continuously updating detection mechanisms, they help protect organizations from evolving cyber threats.

What are the key skills and qualifications needed to thrive as a SIEM Detection Engineer?

To thrive as a SIEM Detection Engineer, you need a strong background in cybersecurity, expertise in threat analysis, and experience with SIEM platforms, typically supported by a degree in computer science or related field and industry certifications like CISSP or GIAC. Mastery of tools such as Splunk, QRadar, or ArcSight, and scripting languages like Python or PowerShell, is commonly required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for investigating incidents and collaborating with teams. These skills ensure proactive threat detection, rapid incident response, and the overall security of an organization's IT infrastructure.

What are some common challenges faced by SIEM Detection Engineers when tuning detection rules, and how can they address them?

SIEM Detection Engineers often face challenges such as minimizing false positives, adapting to evolving threats, and ensuring detection rules remain relevant as the organization's environment changes. To address these challenges, engineers regularly review and refine correlation rules based on incident feedback, collaborate closely with SOC analysts and threat intelligence teams, and stay updated on emerging attack techniques. Continuous testing and validation of rules, as well as leveraging automation where possible, are key practices to maintain effective and actionable alerts.

What is the difference between Siem Detection Engineer vs Security Analyst?

AspectSiem Detection EngineerSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentFocus on SIEM tools, log analysis, threat detectionBroader security monitoring, incident response, policy enforcement
Employer & Industry UsageIT security teams, cybersecurity firms, large enterprisesIT departments, security operations centers, government agencies

While both roles involve cybersecurity, a Siem Detection Engineer specializes in configuring and managing SIEM systems for threat detection, whereas a Security Analyst has a broader focus on monitoring security events, analyzing incidents, and implementing security policies. The roles often overlap but differ in scope and technical focus.

More about Siem Detection Engineer jobs

What cities are hiring for Siem Detection Engineer jobs?

Cities with the most Siem Detection Engineer job openings:

What states have the most Siem Detection Engineer jobs?

States with the most job openings for Siem Detection Engineer jobs include:

What are popular job titles related to Siem Detection Engineer jobs?

For Siem Detection Engineer jobs, the most frequently searched job titles are:

Infographic showing various Siem Detection Engineer job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 89% Full Time, 7% Part Time, and 3% Contract. Highlights an 84% Physical, 5% Hybrid, and 11% Remote job distribution, with an average salary of $111,552 per year, or $53.6 per hour.

SIEM/Detection Engineer

Reston, VA โ€ข On-site

Mantis Security Corporation
11 - 50 employees

Other

Posted 5 days ago


Job description

Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next SIEM Engineer to join our team of experts!

What Youโ€™ll Be Doing

As a SIEM / Detection Engineer at Mantis Security, youโ€™ll help improve how we identify and respond to threats by ensuring our security data is collected, correlated, and turned into effective detections. Youโ€™ll work closely with SOC analysts and engineers to continuously improve the teamโ€™s visibility and detection capabilities.

  • Develop, tune, and maintain Splunk searches, alerts, correlation rules, and dashboards
  • Build and improve detection logic to identify suspicious and malicious activity while reducing false positives
  • Support the onboarding, parsing, normalization, and validation of security log sources
  • Identify gaps in logging, telemetry, and detection coverage and help implement improvements
  • Translate emerging threats and attacker techniques into actionable detections using frameworks such as MITRE ATT&CK
  • Support SOC investigations and threat hunting by developing queries and correlating activity across multiple data sources
  • Troubleshoot SIEM data ingestion, search, alerting, and performance issues
  • Document detection logic, configurations, processes, and recommended improvements
What Weโ€™re Looking For
  • 10+ years of cybersecurity experience, including hands-on experience with SIEM or security monitoring technologies
  • Strong Splunk experience, including SPL searches, correlation searches, dashboards, and alert development
  • Experience developing and tuning security detections in a SOC environment
  • Understanding of security logging across Windows, Linux, network, endpoint, identity, and cloud environments
  • Experience onboarding and troubleshooting security data sources within a SIEM
  • Strong understanding of common attack techniques and how to translate them into detection logic
  • Familiarity with MITRE ATT&CK, incident response, and threat hunting
  • Relevant cybersecurity or SIEM certification such as Security+, CySA+, GIAC, or Splunk certification
Nice to Have
  • Previous SOC Analyst or incident response experience
  • Experience supporting DoD, Intelligence Community, or other federal environments
  • Experience with AWS and cloud-based security telemetry
  • Experience with Python, PowerShell, or other scripting languages
#J-18808-Ljbffr