Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations ...
Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations ...
... detection engineering, or enterprise information technology security * Experience with Google Cloud's SecOps tool stack and architecture, specifically security information and event management (SIEM ...
... detection engineering, or enterprise information technology security * Experience with Google Cloud's SecOps tool stack and architecture, specifically security information and event management (SIEM ...
Red Team - Sr Security Engineer
Overland Park, KS · On-site
$113K - $155K/yr
Detection engineering and purple team collaboration, including writing or tuning SIEM detections based on emulated adversary behavior * Malware analysis, reverse engineering, or custom payload ...
Red Team - Sr Security Engineer
Overland Park, KS · On-site
$113K - $155K/yr
Detection engineering and purple team collaboration, including writing or tuning SIEM detections based on emulated adversary behavior * Malware analysis, reverse engineering, or custom payload ...
Red Team - Sr Security Engineer
Overland Park, KS · On-site
$2.5K/yr
Detection engineering and purple team collaboration, including writing or tuning SIEM detections based on emulated adversary behavior * Malware analysis, reverse engineering, or custom payload ...
New
Red Team - Sr Security Engineer
Overland Park, KS · On-site
$2.5K/yr
Detection engineering and purple team collaboration, including writing or tuning SIEM detections based on emulated adversary behavior * Malware analysis, reverse engineering, or custom payload ...
New
... management (SIEM) technologies * 3+ years of Security Operations Center experience in detection engineering, automation and playbook development, SOC maturity, log source management, data ...
... management (SIEM) technologies * 3+ years of Security Operations Center experience in detection engineering, automation and playbook development, SOC maturity, log source management, data ...
Senior Security Engineer, IAM
Wichita, KS · On-site
$113K - $155K/yr
This engineer owns the architecture, strategy, and operational maturity of AI-enabled identity ... Lead integration of identity telemetry into the detection stack (SIEM/SOAR, UEBA) to detect ...
New
Senior Security Engineer, IAM
Wichita, KS · On-site
$113K - $155K/yr
This engineer owns the architecture, strategy, and operational maturity of AI-enabled identity ... Lead integration of identity telemetry into the detection stack (SIEM/SOAR, UEBA) to detect ...
New
$108K - $143K/yr
In this role, you will bring your in-depth knowledge of the XDR, endpoint, SIEM, and SOAR markets ... detection, and prevention technologies. You will work closely with engineering, researchers ...
$108K - $143K/yr
In this role, you will bring your in-depth knowledge of the XDR, endpoint, SIEM, and SOAR markets ... detection, and prevention technologies. You will work closely with engineering, researchers ...
The work involves SIEM/SOC operations, endpoint protection, network security, and privileged access ... Collaborate with SOC and monitoring teams to strengthen visibility, detection, and security control ...
The work involves SIEM/SOC operations, endpoint protection, network security, and privileged access ... Collaborate with SOC and monitoring teams to strengthen visibility, detection, and security control ...
The work involves SIEM/SOC operations, endpoint protection, network security, and privileged access ... Collaborate with SOC and monitoring teams to strengthen visibility, detection, and security control ...
The work involves SIEM/SOC operations, endpoint protection, network security, and privileged access ... Collaborate with SOC and monitoring teams to strengthen visibility, detection, and security control ...
Posting Type Remote Job Overview The Advanced IAM Engineer is a technically deep, hands-on ... Feed identity telemetry into the detection stack (SIEM/SOAR, UEBA) to support detection of ...
Posting Type Remote Job Overview The Advanced IAM Engineer is a technically deep, hands-on ... Feed identity telemetry into the detection stack (SIEM/SOAR, UEBA) to support detection of ...
Senior Security Engineer
Leawood, KS · On-site +1
$111K - $152K/yr
... SIEM, etc. * Designs, builds, and maintains custom Indicators of Attack (IOAs) aligned to evolving ... Documents engineering decisions, detection logic, workflows, and best practices to ensure ...
Senior Security Engineer
Leawood, KS · On-site +1
$111K - $152K/yr
... SIEM, etc. * Designs, builds, and maintains custom Indicators of Attack (IOAs) aligned to evolving ... Documents engineering decisions, detection logic, workflows, and best practices to ensure ...
Manager, Security Operations (Sentinel)
Overland Park, KS · On-site +1
$150K - $178K/yr
... detection engineering, incident response, and continuous improvement using Microsoft Sentinel as the primary SIEM and SOAR platform. The role operates in a client-facing, delivery-focused environment ...
Manager, Security Operations (Sentinel)
Overland Park, KS · On-site +1
$150K - $178K/yr
... detection engineering, incident response, and continuous improvement using Microsoft Sentinel as the primary SIEM and SOAR platform. The role operates in a client-facing, delivery-focused environment ...
$98K - $134K/yr
Drive vulnerability management end-to-end, from detection to remediation, working closely with ... Experience designing or improving SIEM, logging, and alerting pipelines * Familiarity with ...
$98K - $134K/yr
Drive vulnerability management end-to-end, from detection to remediation, working closely with ... Experience designing or improving SIEM, logging, and alerting pipelines * Familiarity with ...
This includes Security Incident and Event Management (SIEM), Security Orchestration, Automation and ... Detection and Response (EDR), secure email gateways, and data loss prevention (DLP) solutions ...
This includes Security Incident and Event Management (SIEM), Security Orchestration, Automation and ... Detection and Response (EDR), secure email gateways, and data loss prevention (DLP) solutions ...
Senior Security Engineer
Mission, KS · On-site
$120 - $170/hr
Own Rapid7 InsightVM and InsightIDR as our primary vulnerability and SIEM platform. * Run ... Maintain detection coverage mapped to MITRE ATT&CK. * Handle forensic collection in a way that ...
Senior Security Engineer
Mission, KS · On-site
$120 - $170/hr
Own Rapid7 InsightVM and InsightIDR as our primary vulnerability and SIEM platform. * Run ... Maintain detection coverage mapped to MITRE ATT&CK. * Handle forensic collection in a way that ...
Cyber Security Analyst I
Chapman, KS · On-site
... systems engineering Skills: * SIEM analysis * Next Gen Endpoint detection management and analysis * Proficiency with Active Directory and Microsoft Exchange 365 * Knowledge of Electronic mail ...
Cyber Security Analyst I
Chapman, KS · On-site
... systems engineering Skills: * SIEM analysis * Next Gen Endpoint detection management and analysis * Proficiency with Active Directory and Microsoft Exchange 365 * Knowledge of Electronic mail ...
Team Leader (People Manager) Cyber Security (Endpoint)
Olathe, KS · On-site
$107K - $145K/yr
This role requires both deep technical expertise and the ability to guide engineers through complex ... Drive automation initiatives to reduce manual effort and improve detection and response ...
Team Leader (People Manager) Cyber Security (Endpoint)
Olathe, KS · On-site
$107K - $145K/yr
This role requires both deep technical expertise and the ability to guide engineers through complex ... Drive automation initiatives to reduce manual effort and improve detection and response ...
Sr Engineer, Cybersecurity - SOC Process and AI Enablement
Overland Park, KS · On-site
$118K - $214K/yr
... with SIEM and detection tooling (for example, Splunk or Microsoft Sentinel) and translating ... Security Engineering and Testing * Security Incident and Escalation Management * Security ...
Sr Engineer, Cybersecurity - SOC Process and AI Enablement
Overland Park, KS · On-site
$118K - $214K/yr
... with SIEM and detection tooling (for example, Splunk or Microsoft Sentinel) and translating ... Security Engineering and Testing * Security Incident and Escalation Management * Security ...
We engineer and design solutions that improve the world around us. As a company, we promise to ... Support security monitoring, incident response, threat detection, and continuous improvement ...
Quick apply
We engineer and design solutions that improve the world around us. As a company, we promise to ... Support security monitoring, incident response, threat detection, and continuous improvement ...
Security Analyst III
Olathe, KS · Hybrid
... SIEM/SOAR platforms. * Lead and execute web application penetration tests, identifying ... Promote secure development practices and provide guidance to developers on secure coding. * Work ...
Security Analyst III
Olathe, KS · Hybrid
... SIEM/SOAR platforms. * Lead and execute web application penetration tests, identifying ... Promote secure development practices and provide guidance to developers on secure coding. * Work ...
Siem Detection Engineer information
What is a SIEM Detection Engineer?
What are the key skills and qualifications needed to thrive as a SIEM Detection Engineer?
What are some common challenges faced by SIEM Detection Engineers when tuning detection rules, and how can they address them?
What is the difference between Siem Detection Engineer vs Security Analyst?
| Aspect | Siem Detection Engineer | Security Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CEH, CISSP (preferred) | CompTIA Security+, CEH, CISSP (preferred) |
| Work Environment | Focus on SIEM tools, log analysis, threat detection | Broader security monitoring, incident response, policy enforcement |
| Employer & Industry Usage | IT security teams, cybersecurity firms, large enterprises | IT departments, security operations centers, government agencies |
While both roles involve cybersecurity, a Siem Detection Engineer specializes in configuring and managing SIEM systems for threat detection, whereas a Security Analyst has a broader focus on monitoring security events, analyzing incidents, and implementing security policies. The roles often overlap but differ in scope and technical focus.
What are popular job titles related to Siem Detection Engineer jobs in Kansas?
For Siem Detection Engineer jobs in Kansas, the most frequently searched job titles are:
What job categories do people searching Siem Detection Engineer jobs in Kansas look for?
The top searched job categories for Siem Detection Engineer jobs in Kansas are:
What cities in Kansas are hiring for Siem Detection Engineer jobs?
Cities in Kansas with the most Siem Detection Engineer job openings:
Deloitte rating
8.2
Based on 93 frontline employees who took The Breakroom Quiz
45th of 151 rated financial services
Job description
Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and support confident growth. As a Google SecOps Manager supporting Google SecOps engagements, you will contribute to high-visibility projects by applying advanced SOC engineering experience and knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In this role, you will also mentor practitioners and help advance modern Google SecOps methods across the team.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Google SecOps Manager on the Cyber Defense & Resilience team, you will be responsible for:
- Leading the design and implementation of secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities aligned to client security requirements and regulatory obligations such as General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
- Leading end-to-end deployment of log ingestion pipelines using data fabric technologies and integrations such as Bindplane, Cloud Feeds, and application programming interfaces (APIs)
- Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious behavior across enterprise environments
- Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert triage and response
- Developing and managing integrations across third-party platforms, security tools, and Google SecOps to support automated data ingestion, alert enrichment, response actions, and case management workflows
- Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process development
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to mentor and provide clear guidance to others
The team
Our Cyber Defense & Resilience offering helps organizations defend against advanced threats by transforming security operations, monitoring technologies, data analytics, and threat intelligence capabilities. The team supports clients in managing and protecting dynamic attack surfaces while providing rapid crisis and cyber incident response. Through this work, we help clients strengthen readiness, response, and recovery across business disruptions.
Qualifications
Required:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience
- 9+ years of experience in security operations, threat detection engineering, or enterprise information technology security
- Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations center workflows
- Experience with Python scripting and GoStash or Logstash for automation, integration development, log normalization, and parsing, as well as with extract, transform, load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, Kafka, Cloud Feeds, and APIs
- Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent Development Kit (ADK), for workflow development or integration across security information and event management (SIEM), security orchestration, automation, and response (SOAR), Google Threat Intelligence (GTI), or attack surface management (ASM)
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Certifications such as Google Cloud Professional Cloud Architect, Google Cloud Professional Security Engineer, or Certified Cloud Security Professional (CCSP)
- Experience monitoring cybersecurity threats, vulnerabilities, or compliance trends to support security operations or security engineering activities
- Experience facilitating scope or build requirement discussions with internal or external stakeholders
- Experience with threat hunting or cyber threat intelligence fundamentals
- Experience with data fabric technologies such as Bindplane or Cribl
- Experience with infrastructure and networking concepts such as internet protocol (IP) networking, virtual private networks (VPNs), domain name system (DNS), load balancing, firewall technologies, or cloud environments such as Amazon Web Services (AWS) or Microsoft Azure
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and support confident growth. As a Google SecOps Manager supporting Google SecOps engagements, you will contribute to high-visibility projects by applying advanced SOC engineering experience and knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In this role, you will also mentor practitioners and help advance modern Google SecOps methods across the team.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Google SecOps Manager on the Cyber Defense & Resilience team, you will be responsible for:
- Leading the design and implementation of secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities aligned to client security requirements and regulatory obligations such as General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
- Leading end-to-end deployment of log ingestion pipelines using data fabric technologies and integrations such as Bindplane, Cloud Feeds, and application programming interfaces (APIs)
- Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious behavior across enterprise environments
- Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert triage and response
- Developing and managing integrations across third-party platforms, security tools, and Google SecOps to support automated data ingestion, alert enrichment, response actions, and case management workflows
- Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process development
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to mentor and provide clear guidance to others
The team
Our Cyber Defense & Resilience offering helps organizations defend against advanced threats by transforming security operations, monitoring technologies, data analytics, and threat intelligence capabilities. The team supports clients in managing and protecting dynamic attack surfaces while providing rapid crisis and cyber incident response. Through this work, we help clients strengthen readiness, response, and recovery across business disruptions.
Qualifications
Required:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience
- 9+ years of experience in security operations, threat detection engineering, or enterprise information technology security
- Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations center workflows
- Experience with Python scripting and GoStash or Logstash for automation, integration development, log normalization, and parsing, as well as with extract, transform, load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, Kafka, Cloud Feeds, and APIs
- Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent Development Kit (ADK), for workflow development or integration across security information and event management (SIEM), security orchestration, automation, and response (SOAR), Google Threat Intelligence (GTI), or attack surface management (ASM)
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Certifications such as Google Cloud Professional Cloud Architect, Google Cloud Professional Security Engineer, or Certified Cloud Security Professional (CCSP)
- Experience monitoring cybersecurity threats, vulnerabilities, or compliance trends to support security operations or security engineering activities
- Experience facilitating scope or build requirement discussions with internal or external stakeholders
- Experience with threat hunting or cyber threat intelligence fundamentals
- Experience with data fabric technologies such as Bindplane or Cribl
- Experience with infrastructure and networking concepts such as internet protocol (IP) networking, virtual private networks (VPNs), domain name system (DNS), load balancing, firewall technologies, or cloud environments such as Amazon Web Services (AWS) or Microsoft Azure
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.About Deloitte
Sourced by ZipRecruiter
Industry
Finance and insurance and business management consulting
Company size
10,000+ Employees
Headquarters location
Orlando, FL, US