1

Siem Detection Engineer Jobs in Bothell, WA (NOW HIRING)

Senior Threat Detection Engineer

Bellevue, WA · On-site

$128K - $176K/yr

As a Senior Threat Detection Engineer, you will take ownership of technical areas, leading ... Preferred : • Hands on experience with any log aggregation/SIEM tool such as and not limited to ...

Senior Threat Detection Engineer

Bellevue, WA · On-site

$129K - $177K/yr

As a Senior Threat Detection Engineer, you will take on complete ownership of a technical area ... Hands on experience with any log aggregation/SIEM tool such as and not limited to Splunk , Elastic ...

Engineer, operate, and continuously improve the Microsoft Defender security stack (e.g., Defender ... Integrate Defender and PAM signals with SIEM/SOAR and ITSM workflows to improve detection fidelity ...

Integrate Defender and PAM signals with SIEM/SOAR and ITSM workflows to improve detection fidelity ... Design and implement security engineering solutions across cloud and on-prem environments ...

Engineer, operate, and continuously improve the Microsoft Defender security stack (e.g., Defender ... Integrate Defender and PAM signals with SIEM/SOAR and ITSM workflows to improve detection fidelity ...

Integrate Defender and PAM signals with SIEM/SOAR and ITSM workflows to improve detection fidelity ... Design and implement security engineering solutions across cloud and on-prem environments ...

Familiarity with the SOC tech stack - SIEM, SOAR, EDR/XDR, NDR, TIP, IAM, cloud security ... Strong enough technical grounding to have a substantive conversation with a detection engineer

Design, develop, and optimize detection engineering capabilities, including SIEM correlation rules, behavioral analytics, and custom detections to improve coverage and reduce false positives. * Drive ...

... detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response * OR Master's Degree in Statistics, Mathematics, Computer ...

Security Engineer (Blue Team)

Redmond, WA · On-site +1

$150K - $180K/yr

Build and improve existing security detection mechanisms and automation frameworks that directly ... management (SIEM) systems. * Knowledge of common Red Team and Adversarial attack trends and ...

Deep, hands-on expertise with EDR, SIEM, SOAR, and detection-as-code pipelines. * Experience ... Experience mentoring and coaching engineers, and influencing teams to act on security risk without ...

Technical Product Marketing Manager

Seattle, WA · On-site +1

$190K - $219K/yr

Familiarity with the SOC tech stack - SIEM, SOAR, EDR/XDR, NDR, TIP, IAM, cloud security ... Familiarity with detection engineering principles, telemetry requirements, detection validation ...

next page

Showing results 1-20

Siem Detection Engineer information

See Bothell, WA salary details

$28

$59

$85

How much do siem detection engineer jobs pay per hour?

As of Jul 26, 2026, the average hourly pay for siem detection engineer in Bothell, WA is $59.95, according to ZipRecruiter salary data. Most workers in this role earn between $48.37 and $69.62 per hour, depending on experience, location, and employer.

What is the difference between Siem Detection Engineer vs Security Analyst?

AspectSiem Detection EngineerSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentFocus on SIEM tools, log analysis, threat detectionBroader security monitoring, incident response, policy enforcement
Employer & Industry UsageIT security teams, cybersecurity firms, large enterprisesIT departments, security operations centers, government agencies

While both roles involve cybersecurity, a Siem Detection Engineer specializes in configuring and managing SIEM systems for threat detection, whereas a Security Analyst has a broader focus on monitoring security events, analyzing incidents, and implementing security policies. The roles often overlap but differ in scope and technical focus.

What are some common challenges faced by SIEM Detection Engineers when tuning detection rules, and how can they address them?

SIEM Detection Engineers often face challenges such as minimizing false positives, adapting to evolving threats, and ensuring detection rules remain relevant as the organization's environment changes. To address these challenges, engineers regularly review and refine correlation rules based on incident feedback, collaborate closely with SOC analysts and threat intelligence teams, and stay updated on emerging attack techniques. Continuous testing and validation of rules, as well as leveraging automation where possible, are key practices to maintain effective and actionable alerts.

What is a SIEM Detection Engineer?

A SIEM Detection Engineer is a cybersecurity professional responsible for designing, implementing, and maintaining Security Information and Event Management (SIEM) systems. They create and fine-tune detection rules to identify suspicious activities and potential threats within an organization's IT environment. Their role involves analyzing security logs, developing automated alerts, and collaborating with incident response teams to ensure rapid detection and response to security incidents. By continuously updating detection mechanisms, they help protect organizations from evolving cyber threats.

What are the key skills and qualifications needed to thrive as a SIEM Detection Engineer, and why are they important?

To thrive as a SIEM Detection Engineer, you need a strong background in cybersecurity, expertise in threat analysis, and experience with SIEM platforms, typically supported by a degree in computer science or related field and industry certifications like CISSP or GIAC. Mastery of tools such as Splunk, QRadar, or ArcSight, and scripting languages like Python or PowerShell, is commonly required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for investigating incidents and collaborating with teams. These skills ensure proactive threat detection, rapid incident response, and the overall security of an organization's IT infrastructure.
What are popular job titles related to Siem Detection Engineer jobs in Bothell, WA? For Siem Detection Engineer jobs in Bothell, WA, the most frequently searched job titles are:
What job categories do people searching Siem Detection Engineer jobs in Bothell, WA look for? The top searched job categories for Siem Detection Engineer jobs in Bothell, WA are:
Senior Threat Detection Engineer

Senior Threat Detection Engineer

Salesforce

Bellevue, WA • On-site

$128K - $176K/yr

Full-time

Posted 24 days ago


Salesforce rating

8.0

Company rating: 8.0 out of 10

Based on 57 frontline employees who took The Breakroom Quiz

121st of 245 rated software companies


Job description

Job Summary:
Salesforce is the #1 AI CRM, where innovation and customer success are at the forefront. As a Senior Threat Detection Engineer, you will take ownership of technical areas, leading initiatives to enhance threat detection and collaborate across teams to ensure security for Salesforce's infrastructure and customers.
Responsibilities:
• The Threat Detection team is responsible for detecting attacks against Salesforce's infrastructure, products, employees, and customers.
• The team collaborates with CSIRT and engineering teams to enhance detection effectiveness.
• The role involves writing logic on security platforms to detect malicious activity, building attack simulation scenarios, and testing logic effectiveness.
• Collaboration with the incident response team is essential to improve alert reliability and quality.
• As a Senior Threat Detection Engineer,, you will be responsible to lead a project end to end owning a technical area, and delivering research and features.
• In this role you will be working security organization wide initiatives and cross-team collaboration are expected working with multiple engineering teams is required.
Qualifications:
Required:
• 6 to 8 years of experience in relevant areas like in Threat Detection, Threat Hunting, Security Incident Response, and managing significant security incidents and breaches.
• Experience and expertise in developing and refining threat detection methodologies is a prerequisite.
• Proficiency in leveraging security logs from multiple log source types which includes network infrastructure, endpoint devices, public and private cloud substrates and SaaS.
• A comprehensive grasp of log structure, data normalization techniques, and the capacity to isolate critical security incidents is imperative.
• Strong proficiency and experience in log correlation techniques to identify patterns and anomalies indicative of malicious activity.
• Demonstrate expertise in constructing complex search queries using languages such as SPL, YARAL and other query languages to analyze large volumes of data.
• Possess strong data analysis skills to interpret query results, identify false positives, and fine-tune detection rules for optimal efficacy.
• Demonstrate in-depth knowledge of fundamental security principles, common attack vectors employed by threat actors, Tactics, Techniques, and Procedures (TTPs) used throughout the cyber kill chain, and relevant security frameworks such as the MITRE ATT&CK framework.
• Possess practical experience in working with a variety of security tools and technologies, including Security Information and Event Management (SIEM) systems for centralized log analysis and alerting, Endpoint Detection and Response (EDR) solutions for endpoint visibility and threat mitigation, Network Detection and Response (NDR) tools for network traffic analysis and anomaly detection, and Security Orchestration, Automation and Response (SOAR) platforms for automating incident response workflows.
• Demonstrate the ability to effectively handle and analyze large and complex datasets, identifying meaningful security insights and trends from vast amounts of information.
• Knowledge of writing detections based on network, host, OS, and other logs.
• Experience with correlation and complex log analytic queries.
• Coding experience with Python or other languages for automation.
• Ability to correlate multiple log sources for effective adversary detection.
• Demonstrated experience collaborating across global, cross-functional teams with members in multiple time zones, with the ability to communicate and coordinate effectively across geographically distributed environments.
• A related technical degree required.
Preferred:
• Hands on experience with any log aggregation/SIEM tool such as and not limited to Splunk, Elastic (ELK), FLINK, Chronicle etc
• Hands on Experience with public cloud, such as AWS or Azure or GCP, especially Public cloud security.
• Undergraduate degree in cyber security, computer science, information technology, or similar subjects.
• Experience working in a globally distributed team leveraging documentation and async communications as needed
• Prior experience or basic knowledge on DS algorithms and methodologies
• Experience on automation platform such as SOAR
Company:
Salesforce is a cloud-based software company that provides customer relationship management software and applications. Founded in 1999, the company is headquartered in San Francisco, USA, with a team of 10001+ employees. The company is currently Late Stage.

What Salesforce employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom