1

Siem Detection Engineer Jobs in Oregon (NOW HIRING)

Liftoff has a mature security information and event management platform (SIEM), established ... Detection and response is a critical capability for Liftoff. * Security-conscious engineering ...

Security Operations Analyst

OR · On-site +1

$70K - $90K/yr

SIEM & Detection Engineering Integrate and set up the ingestion of log sources to a SIEM tool, including the normalization of fields and data. Create timely monitoring solutions for relevant threats ...

Principal Software Engineer, AI SIEM

OR · On-site +1

$134K - $180K/yr

Our AI SIEM ingests petabytes of data per day, powers the analyst workflows that turn that data ... Partner with the engineering leads of each pillar (data platform, analyst experience, detection ...

Design, develop, and optimize detection engineering capabilities, including SIEM correlation rules, behavioral analytics, and custom detections to improve coverage and reduce false positives. * Drive ...

Design, develop, and optimize detection engineering capabilities, including SIEM correlation rules, behavioral analytics, and custom detections to improve coverage and reduce false positives. * Drive ...

Senior Security Engineer, IAM

Portland, OR · On-site

$121K - $166K/yr

This engineer owns the architecture, strategy, and operational maturity of AI-enabled identity ... Lead integration of identity telemetry into the detection stack (SIEM/SOAR, UEBA) to detect ...

Senior Security Engineer

Clackamas, OR · On-site

$120K - $165K/yr

Support endpoint detection and response, antivirus tools, server/endpoint security controls 4: ... Threat hunting and SIEM rule development experience (Sentinel, LogRhythm, etc.) * Security ...

Senior Security Engineer

Clackamas, OR

$120K - $165K/yr

Support endpoint detection and response, antivirus tools, server/endpoint security controls 4: ... Experience with centralized logging solutions, SIEM tools, and vulnerability scanners * Ability to ...

Senior Security Engineer

Clackamas, OR

$120K - $165K/yr

Support endpoint detection and response, antivirus tools, server/endpoint security controls 4: ... Experience with centralized logging solutions, SIEM tools, and vulnerability scanners * Ability to ...

Technically lead a team of security engineers and analysts who hunt, detect, and respond to ... SIEM, Static Inspection, Vulnerability Assessment, Web Proxies, WAF and Zero Trust). * Adept at ...

Network-based Intrusion Detection/Prevention Systems (IDS/IPS) * Host-based Intrusion Detection ... Security Information & Event Management (SIEM) platform * Web Application Firewall * Network Access ...

Network-based Intrusion Detection/Prevention Systems (IDS/IPS) * Host-based Intrusion Detection ... Security Information & Event Management (SIEM) platform * Web Application Firewall * Network Access ...

Develop requirements for detection models and enhancements to existing systems * Collect, transform ... SIEM), security orchestration automation and response (SOAR), or data loss prevention (DLP)

... Detection Investigation and Response (TDIR) and SIEM tools price by ingest volume, so every ... Work with Engineering to scope product investments -- from small experiments to full feature bets ...

next page

Showing results 1-20

Siem Detection Engineer information

What is a SIEM Detection Engineer?

A SIEM Detection Engineer is a cybersecurity professional responsible for designing, implementing, and maintaining Security Information and Event Management (SIEM) systems. They create and fine-tune detection rules to identify suspicious activities and potential threats within an organization's IT environment. Their role involves analyzing security logs, developing automated alerts, and collaborating with incident response teams to ensure rapid detection and response to security incidents. By continuously updating detection mechanisms, they help protect organizations from evolving cyber threats.

What are the key skills and qualifications needed to thrive as a SIEM Detection Engineer?

To thrive as a SIEM Detection Engineer, you need a strong background in cybersecurity, expertise in threat analysis, and experience with SIEM platforms, typically supported by a degree in computer science or related field and industry certifications like CISSP or GIAC. Mastery of tools such as Splunk, QRadar, or ArcSight, and scripting languages like Python or PowerShell, is commonly required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for investigating incidents and collaborating with teams. These skills ensure proactive threat detection, rapid incident response, and the overall security of an organization's IT infrastructure.

What are some common challenges faced by SIEM Detection Engineers when tuning detection rules, and how can they address them?

SIEM Detection Engineers often face challenges such as minimizing false positives, adapting to evolving threats, and ensuring detection rules remain relevant as the organization's environment changes. To address these challenges, engineers regularly review and refine correlation rules based on incident feedback, collaborate closely with SOC analysts and threat intelligence teams, and stay updated on emerging attack techniques. Continuous testing and validation of rules, as well as leveraging automation where possible, are key practices to maintain effective and actionable alerts.

What is the difference between Siem Detection Engineer vs Security Analyst?

AspectSiem Detection EngineerSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentFocus on SIEM tools, log analysis, threat detectionBroader security monitoring, incident response, policy enforcement
Employer & Industry UsageIT security teams, cybersecurity firms, large enterprisesIT departments, security operations centers, government agencies

While both roles involve cybersecurity, a Siem Detection Engineer specializes in configuring and managing SIEM systems for threat detection, whereas a Security Analyst has a broader focus on monitoring security events, analyzing incidents, and implementing security policies. The roles often overlap but differ in scope and technical focus.

What are popular job titles related to Siem Detection Engineer jobs in Oregon?

For Siem Detection Engineer jobs in Oregon, the most frequently searched job titles are:

What job categories do people searching Siem Detection Engineer jobs in Oregon look for?

The top searched job categories for Siem Detection Engineer jobs in Oregon are:

What cities in Oregon are hiring for Siem Detection Engineer jobs?

Cities in Oregon with the most Siem Detection Engineer job openings:

Security Engineer, Detection & Response

Liftoff

OR • On-site, Remote

Full-time

Re-posted 21 days ago


Job description

The Liftoff Security team protects Liftoff's customers, users, and employees. We architect Liftoff's security posture, build the tools and systems that defend it, and partner with engineering teams as they ship new products and features. Our work spans the entire stack - infrastructure, web, mobile, and IT - and we approach security from a software engineering standpoint, scaling our impact through automation and well-designed tools.

Now is the time to join! Here's why:
  • Build out our detection and response function. Liftoff has a mature security information and event management platform (SIEM), established detection content, and a working incident response program. Your charter is to take it to the next level - including leading our investment in AI-augmented SOC tooling.
  • High visibility, high impact. Detection and response is a critical capability for Liftoff.
  • Security-conscious engineering culture. Liftoff's engineering org is a willing and capable partner on security work.
  • Hands-on technical work. Stay deep in code, detections, and incidents.
  • Breadth of work. Detection and response is the primary focus, but you'll partner across the security team on cloud, infrastructure, and application security where the work demands it.
  • Large-scale, interesting systems. Liftoff processes millions of requests per second across its demand-side platform (DSP), mobile software development kit (SDK), and ad exchange.
Responsibilities:
  • Own day-to-day operation of Liftoff's SIEM (Panther) - log source ingestion, detection content, and the alert investigation pipeline.
  • Lead Liftoff's adoption of AI-augmented SOC tooling (e.g. Prophet, Dropzone, or equivalent) as a multi-year modernization investment.
  • Triage incoming security alerts and drive timely investigation and remediation with stakeholders across Engineering and IT.
  • Lead incident response - investigation, containment, and post-incident review - and mature processes and runbooks so response becomes predictable and repeatable.
  • Build tooling and automation that detects active threats, enriches alerts, and reduces manual investigation toil.
  • Partner with Engineering and IT to make detection and response self-service where possible - clear log-onboarding paths, documented detection proposals, accessible runbooks - so security scales without becoming a bottleneck.
  • Close the feedback loop between the team's offensive and proactive findings and detection coverage.
  • Partner across the security team on cloud, infrastructure, and application security work alongside your detection and response focus - every engineer on this team covers breadth beyond their primary focus.
  • Participate in the Security team's on-call rotation and incident response.
Minimum Qualifications:
  • 5+ years in security engineering, security operations, detection engineering, or software engineering with a security focus.
  • Hands-on production SIEM operation - onboarding log sources, writing and maintaining detection content, and triaging alerts.
  • Write production-quality code for security automation and detection-as-code.
  • Experience leading or substantially contributing to security incident response.
  • Strong technical writing - design docs, runbooks, and post-incident reviews.
  • Demonstrated judgment in prioritizing security work using a risk-based approach.
  • Ability to quickly navigate large, unfamiliar codebases and reason about complex engineering systems.
  • Excellent verbal communication.
  • Willing to participate in an on-call rotation.
Desirable Qualifications:
  • Hands-on experience with an AI-augmented SOC platform (Prophet Security, Dropzone AI, or equivalent), or with building large language model (LLM) augmented investigation and runbook tooling.
  • Experience operating in cloud environments at scale.
  • Cloud incident response experience, particularly in AWS.
  • Endpoint forensics for incident response on Mac and/or Linux.
  • Detection-as-code workflows in continuous integration and deployment (CI/CD) pipelines.
  • Mobile adtech or high-volume SaaS background.

Compensation:

The following are our base salary ranges for this role:

  • SF Bay Area, Los Angeles/Orange County, NYC, Seattle: $200,000 - $240,000 
  • All other California and Washington state locations, Austin, Boston, Denver, Portland: $184,000 - $220,000 
  • All other cities and towns in our approved states: $172,000 - $206,000

Location:

This role is eligible for full-time remote work in one of our entities: CA, CO, ID, IL, FL, GA, MA, MI, MN, MO, NJ, NV, NY, OR, PA, TX, UT, and WA.

We are a remote-first company with US hubs in Redwood City, Los Angeles, and New York City.

Travel Expectations:

We offer several opportunities for in-person team gatherings, including but not limited to project meetings, regional meetups, and company-wide events. We expect our employees to attend these gatherings at least once per quarter. These gatherings provide essential opportunities for collaboration, communication, and team building.


#LI-REMOTE
#LI-EL1