1

Siem Detection Engineer Jobs in Utah (NOW HIRING)

You are proficient in SIEM detection engineering (Splunk) and scripting (Python, PowerShell, or Bash), with a proven ability to integrate secrets scanning and automated remediation workflows directly ...

Security Operations Engineer

Lehi, UT ยท On-site

$120K - $180K/yr

You are proficient in SIEM detection engineering (Splunk) and scripting (Python, PowerShell, or Bash), with a proven ability to integrate secrets scanning and automated remediation workflows directly ...

Senior Security Automation Engineer

Lehi, UT ยท On-site

$97K - $128K/yr

You'll partner with Detection Engineering to turn new detection rules into working response ... Experience integrating systems with detection/SIEM tooling, identity/access systems, and ticketing ...

You'll partner with Detection Engineering to turn new detection rules into working response ... Experience integrating systems with detection/SIEM tooling, identity/access systems, and ticketing ...

Senior Security Engineer

American Fork, UT ยท On-site

$102K - $140K/yr

Proven experience in detection engineering and security data pipelines, including managing detections as code and operating SIEM or logging systems at scale. * Strong software engineering skills in ...

Senior Security Engineer, IAM

Salt Lake City, UT ยท On-site

$110K - $151K/yr

This engineer owns the architecture, strategy, and operational maturity of AI-enabled identity ... Lead integration of identity telemetry into the detection stack (SIEM/SOAR, UEBA) to detect ...

Tune SIEM rules, log sources, and alerting to widen detection coverage while reducing false ... engineering, security architecture, or security operations.Demonstrated experience designing ...

New

Security Engineer III

Lehi, UT ยท On-site

$113K - $149K/yr

Tune SIEM rules, log sources, and alerting to widen detection coverage while reducing false ... engineering, security architecture, or security operations.Demonstrated experience designing ...

next page

Showing results 1-20

Siem Detection Engineer information

What is a SIEM Detection Engineer?

A SIEM Detection Engineer is a cybersecurity professional responsible for designing, implementing, and maintaining Security Information and Event Management (SIEM) systems. They create and fine-tune detection rules to identify suspicious activities and potential threats within an organization's IT environment. Their role involves analyzing security logs, developing automated alerts, and collaborating with incident response teams to ensure rapid detection and response to security incidents. By continuously updating detection mechanisms, they help protect organizations from evolving cyber threats.

What are the key skills and qualifications needed to thrive as a SIEM Detection Engineer?

To thrive as a SIEM Detection Engineer, you need a strong background in cybersecurity, expertise in threat analysis, and experience with SIEM platforms, typically supported by a degree in computer science or related field and industry certifications like CISSP or GIAC. Mastery of tools such as Splunk, QRadar, or ArcSight, and scripting languages like Python or PowerShell, is commonly required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for investigating incidents and collaborating with teams. These skills ensure proactive threat detection, rapid incident response, and the overall security of an organization's IT infrastructure.

What are some common challenges faced by SIEM Detection Engineers when tuning detection rules, and how can they address them?

SIEM Detection Engineers often face challenges such as minimizing false positives, adapting to evolving threats, and ensuring detection rules remain relevant as the organization's environment changes. To address these challenges, engineers regularly review and refine correlation rules based on incident feedback, collaborate closely with SOC analysts and threat intelligence teams, and stay updated on emerging attack techniques. Continuous testing and validation of rules, as well as leveraging automation where possible, are key practices to maintain effective and actionable alerts.

What is the difference between Siem Detection Engineer vs Security Analyst?

AspectSiem Detection EngineerSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentFocus on SIEM tools, log analysis, threat detectionBroader security monitoring, incident response, policy enforcement
Employer & Industry UsageIT security teams, cybersecurity firms, large enterprisesIT departments, security operations centers, government agencies

While both roles involve cybersecurity, a Siem Detection Engineer specializes in configuring and managing SIEM systems for threat detection, whereas a Security Analyst has a broader focus on monitoring security events, analyzing incidents, and implementing security policies. The roles often overlap but differ in scope and technical focus.

What cities in Utah are hiring for Siem Detection Engineer jobs?

Cities in Utah with the most Siem Detection Engineer job openings:

Infographic showing various Siem Detection Engineer job openings in Utah as of August 2026, with employment types broken down into 89% Full Time, 6% Part Time, and 5% Contract. Highlights an 86% Physical, 5% Hybrid, and 9% Remote job distribution.

Threat Detection Engineer (Cloud Security)

Dark Wolf Solutions, LLC

Ogden, UT โ€ข On-site

$100 - $160/hr

Other

Posted 4 days ago


Job description

Dark Wolfis looking for a Threat Detection Engineer to design, build, test, and deploy detection logic using a \"Detection-as-Code\" methodology across on-premise and AWS GovCloud environments. Moving beyond traditional monitoring, this role focuses on proactively engineering high-fidelity alerts, threat hunting against advanced adversary techniques, and automating response workflows to reduce alert fatigue. This position leverages Artificial Intelligence (AI) and Machine Learning (ML) capabilities to accelerate detection engineering, optimize query generation, and streamline incident response. This role will be fully on-site at Hill AFB in Ogden, Utah.

Key Responsibilities:
  • Designing, building, testing, and deploying robust detection logic using a \"Detection-as-Code\" methodology across on-prem and cloud-hosted AWS GovCloud environments
  • Writing and maintaining custom detection signatures targeting cloud-native vectors, container security, and host-level behavior
  • Ingesting, normalizing, and analyzing AWS security logs (CloudTrail, VPC Flow Logs, GuardDuty, AWS Config, EKS Audit Logs) and on-prem telemetry into SIEM and data lake environments
  • Proactively hunt for undetected malicious activity, insider threats, and novel adversary TTPs mapped against the MITRE ATT&CK Cloud Matrix
  • Partnering with NOSC operators and AWS Engineers to develop automated remediation and incident response playbooks within GitLab pipelines
  • Conducting root-cause analysis on false positives/negatives to continuously improve alert fidelity, reduce noise, and optimize detection rules
  • Utilizing AI-assisted analysis and ML features to enhance query generation, automate threat intelligence correlation, and streamline detection development
  • Participating in the development of DCO concept of operations, processes, and procedures
  • Supporting vulnerability management mitigations, adhere to defined policies and schedules, and complete all required training and disclosures as outlined by BSTG.
  • Participating in the development of DCO tactics, techniques, and procedures (TTPs), threat models, and supporting technical documentation.
Required Qualifications:
  • 4+ years of relevant experience
  • 2+ years of handsโ€‘on experience authoring and tuning detection logic in Splunk Enterprise and the ELK Stack (Elasticsearch, Logstash, Kibana).
  • 2+ years of experience with employment of DoD cybersecurity requirements, policies, and procedures to include assessment and authorization activities.
  • Experience within a vSOC, SOC, or CSSP responding to cyber incidents.
  • Direct experience ingesting, normalizing, and engineering detections for AWS GovCloud security telemetry (CloudTrail, VPC Flow Logs, GuardDuty, EKS Audit Logs).
  • Demonstrated experience using GitLab for Detection-as-Code, CI/CD pipelines, version control, and DevSecOps workflows.
  • Department of Defense Directive (DoDD) 8140 (formerly DoDD 8570) IAT CSSP Certification must be obtained prior to hire (CEH, CCNA Security, GCIH, CySA+ or Equivalent).
  • Bachelorโ€™s degree in Computer Science, Information Technology, or a related field.
  • US Citizenship and an active Top Secret/SCI security clearance required.
Desired Qualifications:
  • Experience managing detections as code using Infrastructure as Code (IaC) tools like Terraform or CloudFormation.
  • Familiarity with container runtime security (e.g., Falco, eBPF, Docker security) and Kubernetes threat modeling.
  • Experience with RHEL
  • Experience in performing post-incident computer forensics without destruction of critical data
  • Ability to provide guidance on DoD Cyber regulations and requirements to engineering and software development staff

The salary range for this position is estimated to be between $100,000.00 - $160,000.00, commensurate on experience and technical skillset.

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.

We are strictly looking for direct, full-time W2 employees.

#J-18808-Ljbffr