1

Siem Detection Engineer Jobs in Wisconsin (NOW HIRING)

If you don't have QRADAR experience, Good SIEM Experience will also work The SIEM Engineer is ... tools to detect and respond to IT security incidents. o Perform routine equipment checks and ...

WI · On-site

$150 - $190/hr

... detection on a modern, cloud-native security operations / SIEM platform is a strong added value ... Demonstrated success engineering and securing hybrid IT environments that combine on-premises ...

WI · On-site

$90 - $120/hr

Proven experience in **threat detection engineering** and/or **threat hunting*** Experience with **SIEM platforms**, preferably **Splunk*** Ability to work in a **multicultural, international ...

Hands-on exposure to SIEM content or detection engineering, and to asset or SaaS discovery tooling, preferred * Experience in a regulated, manufacturing, or critical-infrastructure environment ...

WI · On-site

$70 - $95/hr

Experience in Security Engineering, Incident Response, or related fields ... Experience with security detection and response technology (SOAR & SIEM) products * Experience with ...

WI · On-site

$70 - $95/hr

Experience in Security Engineering, Incident Response, or related fields ... Experience with security detection and response technology (SOAR & SIEM) products * Experience with ...

New

... detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response OR Bachelor's Degree in Statistics, Mathematics, Computer ...

The Information Security Engineer owns two of the security program's most operationally critical ... Develop, tune, and maintain detection rules and correlation logic across SIEM and EDR platforms to ...

Sr. Security Engineer

Madison, WI · On-site

$108K - $170K/yr

Build and tune detections and automations (SIEM rules, SOAR/runbooks, detection-as-code) to reduce ... Partner with DevOps and Engineering teams to evolve identity & access, endpoint/EDR posture. b.

Cybersecurity Engineer

Kenosha, WI · On-site

$48 - $60/hr

Threat Detection and Response * Governance, Risk, and Compliance (GRC) * Cybersecurity Frameworks (CSF) Required Skills * Cybersecurity Engineering * Incident Response * SIEM Platforms

Cybersecurity Engineer

Milwaukee, WI · On-site

$70 - $100/hr

Configure, deploy, and manage security tools such as intrusion detection/prevention systems, anti ... Experience with security tools such as SIEM, IDS/IPS, antivirus, endpoint security, and ...

next page

Showing results 1-20

Siem Detection Engineer information

What is a SIEM Detection Engineer?

A SIEM Detection Engineer is a cybersecurity professional responsible for designing, implementing, and maintaining Security Information and Event Management (SIEM) systems. They create and fine-tune detection rules to identify suspicious activities and potential threats within an organization's IT environment. Their role involves analyzing security logs, developing automated alerts, and collaborating with incident response teams to ensure rapid detection and response to security incidents. By continuously updating detection mechanisms, they help protect organizations from evolving cyber threats.

What are the key skills and qualifications needed to thrive as a SIEM Detection Engineer?

To thrive as a SIEM Detection Engineer, you need a strong background in cybersecurity, expertise in threat analysis, and experience with SIEM platforms, typically supported by a degree in computer science or related field and industry certifications like CISSP or GIAC. Mastery of tools such as Splunk, QRadar, or ArcSight, and scripting languages like Python or PowerShell, is commonly required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for investigating incidents and collaborating with teams. These skills ensure proactive threat detection, rapid incident response, and the overall security of an organization's IT infrastructure.

What are some common challenges faced by SIEM Detection Engineers when tuning detection rules, and how can they address them?

SIEM Detection Engineers often face challenges such as minimizing false positives, adapting to evolving threats, and ensuring detection rules remain relevant as the organization's environment changes. To address these challenges, engineers regularly review and refine correlation rules based on incident feedback, collaborate closely with SOC analysts and threat intelligence teams, and stay updated on emerging attack techniques. Continuous testing and validation of rules, as well as leveraging automation where possible, are key practices to maintain effective and actionable alerts.

What is the difference between Siem Detection Engineer vs Security Analyst?

AspectSiem Detection EngineerSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentFocus on SIEM tools, log analysis, threat detectionBroader security monitoring, incident response, policy enforcement
Employer & Industry UsageIT security teams, cybersecurity firms, large enterprisesIT departments, security operations centers, government agencies

While both roles involve cybersecurity, a Siem Detection Engineer specializes in configuring and managing SIEM systems for threat detection, whereas a Security Analyst has a broader focus on monitoring security events, analyzing incidents, and implementing security policies. The roles often overlap but differ in scope and technical focus.

What are popular job titles related to Siem Detection Engineer jobs in Wisconsin?

For Siem Detection Engineer jobs in Wisconsin, the most frequently searched job titles are:

What job categories do people searching Siem Detection Engineer jobs in Wisconsin look for?

The top searched job categories for Siem Detection Engineer jobs in Wisconsin are:

Infographic showing various Siem Detection Engineer job openings in Wisconsin as of August 2026, with employment types broken down into 92% Full Time, 5% Part Time, and 3% Contract. Highlights an 84% Physical, 5% Hybrid, and 11% Remote job distribution.

Sr Threat Hunt Engineer

Milwaukee, WI • On-site


Northwestern Mutual Life Insurance Company
Finance and Insurance • 5 - 10K employees

8.0

Company rating: 8.0 out of 10

Based on 76 frontline employees who took The Breakroom Quiz

168th of 312 rated insurance

People enjoy working here

Good employer

Recommended by students


$112K - $154K/yr

Full-time

Re-posted 11 days ago


Job description

About the Job:

The Senior Threat Hunt Engineer is an advanced and highly trusted role supporting the enterprise cybersecurity program. As a member of Northwestern Mutual's Threat Hunting Program under theThreat Intelligenceumbrella, the Senior Threat Hunt Engineer is primarily responsible for developing andmaintainingthe operational and technical foundation of the program including automation, tooling integration, detection handoff pipelines, and AI-assisted hunt workflows. Grounded in threat intelligence and hunt experience, the Senior Threat Hunt Engineer also executes proactive and signal-driven hunts across endpoint, network, cloud, and identity telemetry, translating findings into durable detections and institutional knowledge.

This role works closely with internal technical teams - including Threat Intelligence, Detection & Response, Detection Engineering, Adversarial Simulation, Purple Team, Incident Command, and Governance, Risk & Compliance - and with peer organizations, industry-sharing groups, and law enforcement affiliations whereappropriate. The Senior Threat Hunt Engineer supports the hunt community across Cyber Defense, contributes engineering rigor to hunt artifacts, and ensures repeatable, version-controlled hunt processes as the program matures from manual to increasingly automated operations.

What You'll Do:

  • Maintain and mature the operational hunt frameworkused across Cyber Defense. Build, document, and refine the templates, integrations, andstandardshunters from multiple teams follow.
  • Design, build, andmaintainintegrations and automationacross the hunt lifecycle - spanning work-tracking, collaboration, ticketing, knowledge management, SIEM, EDR, threat intelligence platforms, and reporting.
  • Execute hunts and support the hunt community across teams. Perform proactive and signal-driven hunts, respond to hunt questions from hunters across Cyber Defense, and partner with Threat Intelligence to translate hunt-informed analysis into actionable intelligence. Synthesize hunt outcomes into cross-hunt correlations, control gap identification, and inputs to future hunts and detections.
  • Partner with detection engineering to translate hunt findingsinto production rules and analytics. Contributedetectioncandidates through the established handoff pipeline.
  • Consume and apply threat intelligence to hunt activity. Track adversary and threat cluster TTPs relevant to Northwestern Mutual, prioritize what matters, and translate intel into hunt hypotheses.
  • Mentor analysts and junior hunters. Pair on investigations, lead technical deep-dives, and grow the hunt capability across teams.
  • Report on program outcomes. Communicate findings to internal stakeholders - what was found, what wascontained, where detection coverage gaps exist, and what was changed as a result.
  • Evaluate, integrate, andmaintainsecurity toolingused by the Threat Hunting Program, including threat intelligence platforms, enrichment services, and hunt-supporting analytical tools.
  • Evaluate and integrate AIto accelerate hunt workflows, including hypothesis drafting, MITRE ATT&CK mapping suggestion, query generation, and summarization, withappropriate humanreview and tracking.
  • Researchcurrent and emerging cyber threatsfacing the business and industrysector.
  • Track threat actors, threat clusters, and associated malware families relevant to Northwestern Mutual and the financial services sector.
  • Document threats into contextual reportsoutlining severity, urgency, and impact, and ensure they can be understood by both leadership and technical teams.
  • Serve as a trusted advisortomaintaincredibility with business unit leadership and technical teams.
  • Actively inform andengage in security projectsacross the business to disrupt active or potential threats.
  • Participate incollaborative threat analysis discussionswith internal and external trusted entities.
  • Perform other dutiesas assigned.

What You'll Bring to the Role:

  • A minimum of 5-10 years in threat intelligence, threat hunting, incident response, or detection engineering, with meaningful experience across both threat intelligence and threat hunting disciplines.
  • Bachelor's degree in computer science, cybersecurity, engineering, ora relatedfield (or equivalent experience).
  • Relevant certifications such as GCTI, GCIH, GCFA, GCIA, GCDA, OSCP, CEH, or CISSP are a plus. Cloud-focused security certifications (e.g., AWS Security Specialty, GCP Professional Cloud Security Engineer) are also valued.
  • Deep hands-on experience running proactive and signal-driven hunts across SIEM, EDR, network, cloud, and identity telemetry in enterprise environments.
  • Strong scripting and automation skills; Pythonrequired, withadditionalexperience in PowerShell, Bash, or equivalenta plus.
  • Deep hands-on experience with enterprise SIEM search languages, including advanced query development, dashboard building, saved searches, alerting, and query optimization at enterprise scale.
  • Hands-on experience developing and consuming REST APIs across security tooling - including work-tracking, collaboration, ticketing, SIEM, EDR, and threat intelligence platforms.
  • Demonstrated experience building event-driven automation using webhooks or similar integration patterns.
  • Experience building, integrating, andmaintainingsecurity tooling and workflows at enterprise scale.
  • Working knowledge of version control workflows, branching strategies, and code review practices.
  • Ability to write clear technical documentation forautomationand integrations, including runbooks for maintenance and troubleshooting.
  • Ability to communicate complex findings clearly to both technical and leadership audiences.
  • Advanced analytical reasoning skills.
  • Applicable knowledge of adversary tactics, techniques, and procedures (TTPs), the MITRE ATT&CK framework, the unified kill chain, and open-source intelligence (OSINT).
  • Hands-on experience with SIEM, intrusion detection/prevention systems, threat intelligence platforms, and security orchestration and automation platforms.
  • Ability to analyze host, network, cloud, and identity telemetry; strong understanding of operating system internals; working knowledge of malware behavior, vulnerabilities, and exploitation techniques.
  • Experience with incident collaboration, adversary tooling, and threat-informed defensemethodology.
  • Capable of working with diverse teams across Cyber Defense; comfortable operating in a cross-team enablement role rather than a single-team hunt queue.
  • Demonstrated understanding of network, host, cloud, and identity cybersecurity solutions.
  • Ability tomaintaina high levelof integrity, trustworthiness, and confidence, with the highest level of professionalism.
  • Strong project management, multitasking, and organizational skills with minimum guidance.
  • Ability to preserve credibility with the team and external constituents through sustained industry knowledge.
  • Self-starter requiring minimal supervision.

Nice to Have Skills:

  • Experience with AI-assisted security workflows andappropriate operationalguardrails.
  • Familiarity with structured, version-controlled hunt methodologies.
  • Experience building andmaintainingCI/CD pipelines for security content.
  • Experience building or contributing to a new or evolving threathuntor detection engineering program, as opposed to onlyoperatingwithin an established one.
  • Experience with SOAR platforms and playbook development.
  • Experience with cloud-native security tooling and cloud API integration.
  • Experience in financial services or another regulated industry.
  • Contributions to open-source security tooling, published research, or public threat intelligence.

#LI-Remote

Compensation Range:

Pay Range - Start:

$118,960.00

Pay Range - End:

$178,440.00

Geographic Specific Pay Structure:

Structure 110:

Structure 115:

We believe in fairness and transparency. It's why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you're living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable, click here to learn more.

Job Posting End Date:


The timeline for this job posting may be shortened or extended based on organizational needs.


Grow your career with a best-in-class company that puts our clients' interests at the center of all we do. Get started now!


Northwestern Mutual is an equal opportunity employer that welcomes talented individuals of all backgrounds. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives.


Northwestern Mutual logo

About Northwestern Mutual

Sourced by ZipRecruiter

Northwestern Mutual has been helping families and businesses achieve financial security for over 160 years through a distinctive planning approach that integrates risk management with wealth accumulation, preservation, and distribution. With more than $290 billion in assets, $30 billion in revenues and more than $1.9 trillion worth of life insurance protection in force, Northwestern Mutual delivers financial security to more than 4.6 million clients. People are the power behind Northwestern Mutual, and diversity makes us better. We are committed to reflecting and serving the marketplace. We do so by attracting and improving the engagement of those who bring their outstanding perspectives, ideas, and beliefs.

Industry

Finance and insurance

Company size

5,001 - 10,000 Employees

Headquarters location

Milwaukee, WI, US


What Northwestern Mutual employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom