1

Siem Detection Engineer Jobs in Alabama (NOW HIRING)

SOC Analyst Tier 3

AL · On-site +1

$75K - $90K/yr

Deployment, tuning and maintenance of SIEM and Detection Engineering Platforms. * Assistance with compliance mandates related to CMMC L2 and L3 implementation * Track and understand emerging security ...

Support Cyber Incident Response Team (CIRT) for attack detection * Document incident response ... Integrate logs into SIEM/threat management platform Cloud Security (Azure) * Proficient Azure ...

next page

Showing results 1-20

People also search for

Siem Detection Engineer information

What are the key skills and qualifications needed to thrive as a SIEM Detection Engineer, and why are they important?

To thrive as a SIEM Detection Engineer, you need a strong background in cybersecurity, expertise in threat analysis, and experience with SIEM platforms, typically supported by a degree in computer science or related field and industry certifications like CISSP or GIAC. Mastery of tools such as Splunk, QRadar, or ArcSight, and scripting languages like Python or PowerShell, is commonly required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for investigating incidents and collaborating with teams. These skills ensure proactive threat detection, rapid incident response, and the overall security of an organization's IT infrastructure.

What are some common challenges faced by SIEM Detection Engineers when tuning detection rules, and how can they address them?

SIEM Detection Engineers often face challenges such as minimizing false positives, adapting to evolving threats, and ensuring detection rules remain relevant as the organization's environment changes. To address these challenges, engineers regularly review and refine correlation rules based on incident feedback, collaborate closely with SOC analysts and threat intelligence teams, and stay updated on emerging attack techniques. Continuous testing and validation of rules, as well as leveraging automation where possible, are key practices to maintain effective and actionable alerts.

What is a SIEM Detection Engineer?

A SIEM Detection Engineer is a cybersecurity professional responsible for designing, implementing, and maintaining Security Information and Event Management (SIEM) systems. They create and fine-tune detection rules to identify suspicious activities and potential threats within an organization's IT environment. Their role involves analyzing security logs, developing automated alerts, and collaborating with incident response teams to ensure rapid detection and response to security incidents. By continuously updating detection mechanisms, they help protect organizations from evolving cyber threats.

What is the difference between Siem Detection Engineer vs Security Analyst?

AspectSiem Detection EngineerSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentFocus on SIEM tools, log analysis, threat detectionBroader security monitoring, incident response, policy enforcement
Employer & Industry UsageIT security teams, cybersecurity firms, large enterprisesIT departments, security operations centers, government agencies

While both roles involve cybersecurity, a Siem Detection Engineer specializes in configuring and managing SIEM systems for threat detection, whereas a Security Analyst has a broader focus on monitoring security events, analyzing incidents, and implementing security policies. The roles often overlap but differ in scope and technical focus.

What job categories do people searching Siem Detection Engineer jobs in Alabama look for? The top searched job categories for Siem Detection Engineer jobs in Alabama are:
ASG Presales Solutions Engineer - SecOps/SIEM

ASG Presales Solutions Engineer - SecOps/SIEM

SHI GmbH

Montgomery, AL • Remote

Full-time

Medical, Dental, Vision, Retirement

Posted 12 days ago


Job description

About Us

Since 1989, SHI International Corp. has helped organizations change the world through technology. We've grown every year since, and today we're proud to be a $16 billion global provider of IT solutions and services.

Over 17,000 organizations worldwide rely on SHI's concierge approach to help them solve what's next. But the heartbeat of SHI is our employees – all 7,000 of them. If you join our team, you'll enjoy:

  • Our commitment to diversity, as the largest minority- and woman-owned enterprise in the U.S.
  • Continuous professional growth and leadership opportunities.
  • Health, wellness, and financial benefits to offer peace of mind to you and your family.
  • World-class facilities and the technology you need to thrive – in our offices or yours.

Job Summary

The Presales Solutions Engineer – SecOps/SIEM is a customer-facing security expert who takes a consultative approach to helping customers design and implement effective security operations solutions. This role requires a strong understanding of how SIEM and SecOps technologies support broader business and security goals.

At SHI International, the engineer serves as a subject matter expert in SIEM platform engineering, including log source onboarding, detection and correlation rule development, content management, performance tuning, and integration with the broader security operations ecosystem such as SOAR, EDR/XDR, threat intelligence, and ticketing platforms. The role also includes contributing to the development and delivery of security services offerings based on customer needs.

This is a remote position that may be required to reside in the Central or Northeast region of the US as required for business needs and as determined by SHI management.

Role Description

  • Collaborate with account teams to evaluate and understand customers' cybersecurity technologies and needs.
  • Collaboration with multiple layers of contacts within client organizations, including but not limited to CIO, CSO, CISO, Security Engineers, and procurement to strengthen our overall customer relationship and better understand the goals and objectives they are trying to achieve.
  • Understand the company's services offerings in all solution practice areas by attending company training and expanding knowledge through self-study.
  • Educate sales teams on cybersecurity solution selling and key technologies through 1x1, team, and company training.
  • Staying current on new technology, trends, and market behavior by studying market trends and the industry landscape
  • Engaging in self-study and independent work in lab facilities to increase job-related knowledge and skills
  • Developing collateral to assist with cybersecurity sales engagements
  • Developing use cases in the SHI lab to support sales engagements

Behaviors and Competencies

  • Presenting: Can design and deliver engaging presentations, adapting the content and style to suit the audience, context, and medium.
  • Negotiation: Can proactively seek out negotiation opportunities, initiate discussions, and contribute to conflict resolution.
  • Communication: Can effectively communicate complex ideas and information to diverse audiences and can facilitate effective communication between others.
  • Detail-Oriented: Can manage complex tasks or projects, identifying errors or inconsistencies, and ensuring all details are addressed, necessary corrections are made, and quality is maintained.
  • Organization: Can effectively coordinate multiple projects, delegate tasks where appropriate, and employ advanced organizational tools and methods.
  • Follow-Up: Can proactively identify tasks that require follow-up, initiate necessary actions, and contribute to efficient workflow management.
  • Problem-Solving: Can proactively identify potential problems, initiate preventive measures, and propose and contribute to innovative solutions.
  • Relationship Building: Can proactively seek out opportunities to expand networks, initiate collaborations, and contribute to team cohesion.
  • Documentation: Can develop comprehensive documentation standards, implement best practices, and ensure documentation supports operational efficiency.
  • Results Orientation: Can set challenging goals for their team and lead them to achieve these goals, demonstrating a consistent track record of results.

Skill Level Requirements

  • Experience working in identity management and security solutions.
  • Deep technical identity governance and security knowledge, including but not limited to Security Operations, SIEM, SOAR, TIP, Dark Web scanning, CLM/PKI, and BAS controls.
  • Excellent presentation skills, including the ability to run demos on security operations products
  • Outstanding written and verbal communication.
  • Attention to detail, organization, and follow-up skills
  • Initiative to research and resolve problems with a positive attitude
  • Exceptional relationship-building acumen with a passion for technology
  • Strong documentation skills to include system/network diagrams and presentations
  • General understanding of security frameworks such as NIST, HITRUST, and CIS.
  • Expert technical knowledge of security solutions
  • Preferred Certifications: CISSP, Relevant GIAC Cert, SSCP, CISM, CCSP, CEH, CPT, CWSP, CCNP Security, CCIE Security or Relevant Professional certifications in Cyber Security OEMs

Other Requirements

  • Completed Bachelor's Degree or relevant work experience required
  • 3-5 years of experience in a similar role
  • 5+ years experience in a technical cybersecurity role
  • 3+ years experience in Security Pre-Sales Consulting
  • Ability to travel to SHI, Partner, and Customer Events

The estimated annual pay range for this position is $120,000 - $230,000 which includes a base salary and bonus. The compensation for this position is dependent on job-related knowledge, skills, experience, and market location and, therefore, will vary from individual to individual. Benefits may include, but are not limited to, medical, vision, dental, 401K, and flexible spending.

Equal Employment Opportunity – M/F/Disability/Protected Veteran Status