1

Siem Detection Engineer Jobs in Bothell, WA (NOW HIRING)

Security Operations Analyst

Seattle, WA · On-site

$129K - $171K/yr

Experience in security monitoring, log analysis, and detection engineering within large data sets ... Must have experience with one or more SIEM languages (SPL, KQL, SQL) * Experience conducting ...

... SIEM) systems * As a member of the Incident Response team respond to alerts, warnings, incidents ... Endpoint Detection and Response (EDR) and management console * Web filter/proxy technologies

... SIEM) systems * As a member of the Incident Response team respond to alerts, warnings, incidents ... Endpoint Detection and Response (EDR) and management console * Web filter/proxy technologies

Collaborate with detection engineering to develop and tune AI-based detection logic to improve SOC ... Work with SIEM and SOAR platforms to optimize alert processing and incident workflows * Contribute ...

Experience developing detection use cases using a SIEM (e.g Splunk, Elastic), big data/data lake query platforms (e.g. Apache Spark), or relational database. * Programming experience with at least ...

Experience developing detection use cases using a SIEM (e.g Splunk, Elastic), big data/data lake query platforms (e.g. Apache Spark), or relational database. * Programming experience with at least ...

Experience developing detection use cases using a SIEM (e.g Splunk, Elastic), big data/data lake query platforms (e.g. Apache Spark), or relational database. * Programming experience with at least ...

... detection and response, security engineering, identity, data, and cloud security-reducing cyber ... Strong technical expertise in security tooling and infrastructure such as SIEM, EDR, log management ...

Senior Security Analyst I

Seattle, WA · On-site

$109K - $137K/yr

You will leverage deep expertise to engineer sophisticated detection capabilities, develop ... What We'll Expect From You: * 5+ years of hands-on experience with SIEM platforms and endpoint ...

You'll accomplish this with a "detection as code" engineering mindset and partner closely with ... Familiarity with EDR, SIEM, SOAR, or related security tools. * Bachelor's degree in a related ...

Showing results 41-60

Siem Detection Engineer information

See Bothell, WA salary details

$28

$59

$85

How much do siem detection engineer jobs pay per hour?

As of Sep 2, 2026, the average hourly pay for siem detection engineer in Bothell, WA is $59.95, according to ZipRecruiter salary data. Most workers in this role earn between $48.37 and $69.62 per hour, depending on experience, location, and employer.

What is a SIEM Detection Engineer?

A SIEM Detection Engineer is a cybersecurity professional responsible for designing, implementing, and maintaining Security Information and Event Management (SIEM) systems. They create and fine-tune detection rules to identify suspicious activities and potential threats within an organization's IT environment. Their role involves analyzing security logs, developing automated alerts, and collaborating with incident response teams to ensure rapid detection and response to security incidents. By continuously updating detection mechanisms, they help protect organizations from evolving cyber threats.

What are the key skills and qualifications needed to thrive as a SIEM Detection Engineer?

To thrive as a SIEM Detection Engineer, you need a strong background in cybersecurity, expertise in threat analysis, and experience with SIEM platforms, typically supported by a degree in computer science or related field and industry certifications like CISSP or GIAC. Mastery of tools such as Splunk, QRadar, or ArcSight, and scripting languages like Python or PowerShell, is commonly required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for investigating incidents and collaborating with teams. These skills ensure proactive threat detection, rapid incident response, and the overall security of an organization's IT infrastructure.

What are some common challenges faced by SIEM Detection Engineers when tuning detection rules, and how can they address them?

SIEM Detection Engineers often face challenges such as minimizing false positives, adapting to evolving threats, and ensuring detection rules remain relevant as the organization's environment changes. To address these challenges, engineers regularly review and refine correlation rules based on incident feedback, collaborate closely with SOC analysts and threat intelligence teams, and stay updated on emerging attack techniques. Continuous testing and validation of rules, as well as leveraging automation where possible, are key practices to maintain effective and actionable alerts.

What is the difference between Siem Detection Engineer vs Security Analyst?

AspectSiem Detection EngineerSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentFocus on SIEM tools, log analysis, threat detectionBroader security monitoring, incident response, policy enforcement
Employer & Industry UsageIT security teams, cybersecurity firms, large enterprisesIT departments, security operations centers, government agencies

While both roles involve cybersecurity, a Siem Detection Engineer specializes in configuring and managing SIEM systems for threat detection, whereas a Security Analyst has a broader focus on monitoring security events, analyzing incidents, and implementing security policies. The roles often overlap but differ in scope and technical focus.

What are popular job titles related to Siem Detection Engineer jobs in Bothell, WA?

For Siem Detection Engineer jobs in Bothell, WA, the most frequently searched job titles are:

What job categories do people searching Siem Detection Engineer jobs in Bothell, WA look for?

The top searched job categories for Siem Detection Engineer jobs in Bothell, WA are:

Sr Engineer, IT Security (NTD)

Nintendo of America Inc

Redmond, WA • On-site

$145.15 - $261.20/hr

Other

Medical, Dental, Vision, Retirement, PTO

Re-posted 20 days ago


Nintendo rating

7.5

Company rating: 7.5 out of 10

Based on 11 frontline employees who took The Breakroom Quiz

158th of 247 rated software companies


Job description

Nintendo Technology Development is a wholly owned subsidiary of Nintendo, based in Redmond, Washington, focused on future hardware and software technology.

Nintendo is an equal opportunity employer and offers a welcoming and inclusive environment.

Senior Engineer, IT Security

The Senior Engineer, IT Security for Nintendo Technology Development Inc. (NTD) organization will own and evolve the security for our Microsoft 365 (M365) tenant, drive Identity and Access Management (IAM) operations, and harden endpoint security at scale across Windows, macOS, and Linux devices. This role will be the technical driver for secure collaboration and device protection; designing, implementing, and operating controls using existing and emerging technologies. This role requires partnership with NTD IT Operations, IT security teams at Nintendo Co., Ltd. (NCL), and Nintendo of America Inc. (NOA) to deliver reliable, compliant, and auditable services with measurable outcomes.

Description of DutiesM365 Tenant, Identity & Access Management
  • Implement and optimize Microsoft Entra Conditional Access, tenant security defaults, privileged access policies, and MFA/SSPR at scale.
  • Operate and harden Microsoft Entra ID (Azure AD): lifecycle governance, automated provisioning/deprovisioning, privileged identities (PIM), app registrations, consent/permission reviews.
  • Build and maintain RBAC/least-privilege access models for cloud and SaaS apps; implement Just-In-Time access for admins and sensitive roles.
  • Integrate HRIS and identity sources for Joiner-Mover-Leaver flows, enforce identity proofing and MFA step‑up for high‑risk transactions.
  • Design and enforce data governance (labels, DLP, retention, eDiscovery/Legal Hold, insider risk signals) and collaboration controls (external sharing, guest access, B2B/B2C).
  • Establish monitoring/alerting/SLAs for tenant and identity‑related services; lead incident response and help develop IR playbooks in conjunction with IT Security Operations.
Endpoint Security (Windows, macOS, Linux)
  • Own the migration from an existing endpoint management system to a more robust solution, such as the CrowdStrike Falcon platform, for all endpoints: sensor deployment/coverage, policy tuning, RTR workflows, and threat hunting guardrails.
  • Lead efforts with platform engineers for OS‑specific hardening baselines (CIS/NIST) and secure configuration: BitLocker/FileVault/LUKS, kernel extension/driver policies, local admin control, application allow/deny lists.
  • Lead incident triage and response on endpoints, including containment, forensic collection, and post‑incident hardening.
Observability, Detection & Response
  • Build and operationalize Splunk detections and dashboards integrating M365, Entra, CrowdStrike, Defender, Intune, and OS logs.
  • Develop automated response playbooks to reduce MTTR.
Automation & Engineering Excellence
  • Create robust automation and self‑service tooling for identity and endpoint operations.
  • Maintain IaC for policy‑as‑code (e.g., Conditional Access, PIM role settings).
  • Document runbooks, architecture diagrams, inventories, and SOPs; mentor engineers and drive operational maturity.
Compliance & Risk
  • Map controls to regulatory frameworks (SOX, J‑SOX, etc.); support audits with evidence and narratives.
  • Lead periodic access reviews, admin entitlement recertification, and break‑glass account governance.
  • Conduct tabletop exercises, disaster recovery testing, and security drills tied to identity and endpoint scenarios.

Up to 10% travel; domestic and international.

Summary of Requirements
  • 8+ years in enterprise IT/Security engineering with deep hands‑on experience in M365 administration, IAM operations, or endpoint security.
  • Expert‑level experience with M365 & Entra ID: Conditional Access, MFA/SSPR, PIM/PAM, app registrations, service principals, identity lifecycle.
  • Expert‑level experience with Endpoint Security: CrowdStrike Falcon or equivalent (policy design, RTR, detection tuning) across Windows, macOS, Linux.
  • Expert‑level experience with Logging/SIEM: Splunk or equivalent (search, dashboards, alerting, detection engineering).
  • Strong automation skills: PowerShell (Graph modules), Python, REST/Graph APIs; CI/CD and version control (Git).
  • Proven track record delivering secure baselines at scale (Intune/Jamf/MDM); leading incident response involving identity and endpoints.
  • Deep understanding of Zero Trust, least privilege, RBAC, token flows (OAuth/OIDC), and modern auth (MSAL).
  • Experience with compliance control design and audit support.
  • Experience mentoring others and cultivating technical breadth and depth on a team.
  • Fluency in Japanese a plus.
  • Bachelor or Master of Science degree in Engineering, Information Technology, or related field; or equivalent combination of education and experience.

This position includes the base pay range listed below, potential for a semi‑annual discretionary performance bonus, and a comprehensive benefits package that includes medical, dental, vision, 401(k), and paid time off.

Pay Range: $145,150—$261,200 USD

#J-18808-Ljbffr

What Nintendo employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom