1

Siem Security Jobs (NOW HIRING)

CLOUD SECURITY & SIEM ENGINEER Job Title: Cloud Security & SIEM Engineer Location: Remote Position Type: Full-Time / Contract-to-Hire Work Schedule: Standard Business Hours (PST Alignment) 1. Role ...

SIEM - Security information and event management * PYTHON Job Summary: We are seeking a skilled Security Engineer to monitor, detect, analyze, and respond to security incidents affecting our SPC ...

Showing results 41-60

Siem Security information

See salary details

$39.5K

$107.3K

$141K

How much do siem security jobs pay per year?

As of Sep 13, 2026, the average yearly pay for siem security in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is a SIEM Security?

A SIEM Security job involves managing and monitoring a Security Information and Event Management (SIEM) system to detect, analyze, and respond to security threats. Professionals in this role collect and correlate log data from various sources to identify suspicious activities. They also fine-tune SIEM rules, investigate security incidents, and collaborate with cybersecurity teams to mitigate risks. SIEM analysts play a critical role in enhancing an organization's security posture by ensuring real-time threat detection and compliance with security policies.

What does a SIEM Security do?

A SIEM Security professional typically spends their day monitoring security alerts, analyzing suspicious activity, and responding to incidents using advanced SIEM tools. They work closely with IT and cybersecurity teams to investigate threats, update security configurations, and provide recommendations for addressing vulnerabilities. Documentation, creating and tuning detection rules, and regular communication with stakeholders are also key aspects of the work. This role is dynamic, often requiring quick thinking and adaptability to new and emerging threats in the cybersecurity landscape.

What are the key skills and qualifications needed to thrive in the SIEM Security position?

To thrive in SIEM Security, you'll need a strong background in cybersecurity, experience with security incident detection and response, and familiarity with monitoring tools and best practices. Proficiency with Security Information and Event Management (SIEM) platforms such as Splunk, IBM QRadar, or ArcSight, as well as certifications like CompTIA Security+, CEH, or CISSP, is highly valued. Excellent analytical thinking, attention to detail, and effective communication are crucial soft skills for this role. These skills and qualities are essential for proactively identifying threats, collaborating with other IT teams, and maintaining the organization's security posture.

More about Siem Security jobs

What cities are hiring for Siem Security jobs?

Cities with the most Siem Security job openings:

What states have the most Siem Security jobs?

States with the most job openings for Siem Security jobs include:

Infographic showing various Siem Security job openings in the United States as of September 2026, with employment types broken down into 84% Full Time, 14% Part Time, and 2% Contract. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $107,334 per year, or $51.6 per hour.

CLOUD SECURITY & SIEM ENGINEER

Folsom, CA โ€ข On-site

Other

Re-posted 12 hours ago


Key responsibilities

  • Deploy, configure, and maintain a high-availability Wazuh SIEM cluster in AWS.

  • Architect and validate centralized log ingestion pipelines from various AWS-native security services and third-party systems into the SIEM.

  • Develop and implement security monitoring, alerting, and automation for cloud security, endpoint telemetry, and third-party middleware integrations.


Job description

CLOUD SECURITY & SIEM ENGINEER
Job Title: Cloud Security & SIEM Engineer
Location: Remote
Position Type: Full-Time / Contract-to-Hire
Work Schedule: Standard Business Hours (PST Alignment)
 
1. Role Overview
Technet is seeking a hands-on Cloud Security & SIEM Engineer to deploy, configure, and maintain the cybersecurity architecture for a critical energy-sector utility billing and data platform hosted in AWS (us-west-2).
In this role, you will lead the implementation and engineering of an enterprise high-availability (HA) Wazuh SIEM cluster deployed in a dedicated, tenant-isolated AWS management VPC. You will be responsible for telemetry pipelines across AWS-native security services, CrowdStrike Falcon EDR integration, containerized Prowler Cloud Security Posture Management (CSPM), and security monitoring for third-party middleware and data transfer tiers.
2. Technical Stack & Systems Managed
  • SIEM & Endpoint: Wazuh (HA Manager Cluster, Indexer, Dashboard, Agents, File Integrity Monitoring [FIM], Security Configuration Assessment [SCA]), CrowdStrike Falcon (Streaming API, Falcon Data Replicator / FDR).
  • AWS Native Security & Infrastructure: Amazon GuardDuty, AWS Security Hub, AWS WAF, AWS Config, AWS Systems Manager (SSM), CloudTrail, VPC Flow Logs, Route 53 Resolver logs, S3 Access Logs, EventBridge, SQS, Transit Gateway, AWS Directory Service.
  • CSPM & Compliance Automation: Containerized Prowler, CIS AWS Foundations Benchmark, SOC 2 Type II, NIST 800-53.
  • Middleware & Data Integration Tiers: GoAnywhere Managed File Transfer (MFT), Dell Boomi Middleware, Salesforce CRM API feeds, PG&E data exchanges.
  • Operating Systems & Databases: Windows Server (IIS Web Tier), Linux workloads, Amazon RDS (Microsoft SQL Server Audit Logs).
3. Key Responsibilities
  • Wazuh SIEM Implementation & Cluster Administration: Deploy, configure, and maintain a high-availability Wazuh SIEM manager cluster in a dedicated AWS management VPC. Deploy and tune Wazuh agents across Windows/IIS web nodes, Linux instances, middleware servers, and MFT nodes.
  • AWS Telemetry Pipeline Engineering: Architect and validate centralized log ingestion using AWS EventBridge, SQS, CloudTrail, VPC Flow Logs, Route 53 Resolver logs, and S3 server access logs into the SIEM correlation pipeline.
  • EDR Integration: Ingest CrowdStrike Falcon telemetry via Streaming API / FDR into Wazuh to correlate endpoint activity with cloud control plane logs without endpoint resource contention.
  • Integration Edge & MFT Security: Develop custom log parsers, decoders, and alerting rules for high-risk integration boundary systems, specifically GoAnywhere MFT, Dell Boomi, Salesforce integrations, and external PG&E utility feeds.
  • CSPM & Continuous Compliance: Deploy and automate containerized Prowler scans and AWS Config rules to deliver daily posture assessments mapped to SOC 2 Type II, CIS AWS Foundations Benchmark, and NIST 800-53 standards.
  • Vulnerability Management & Configuration Hardening: Operationalize automated recurring vulnerability scans and Security Configuration Assessments (SCA) using Wazuh and AWS Systems Manager (SSM); track and support infrastructure remediation.
  • Identity & Access Security: Assist with MFA deployment and continuous auditing across AWS Directory Service, VPN endpoints, and GoAnywhere MFT exchanges.
  • Encryption Validation: Continuously validate encryption-in-transit and encryption-at-rest across S3, EBS, and RDS SQL Server databases.
4. Required Qualifications & Technical Skills
  • Experience: 4+ years of hands-on experience in Cloud Security Engineering, SIEM Administration, or SecOps within AWS enterprise environments.
  • SIEM & Log Engineering: Deep practical expertise deploying and managing Wazuh (or ELK/OpenSearch-based security stacks), including writing custom XML decoders, rules, and managing agent fleets.
  • AWS Security Core: Strong hands-on experience with GuardDuty, Security Hub, AWS WAF, AWS Config, Systems Manager (SSM), IAM policy design, and multi-VPC networking (Transit Gateway).
  • Workload & Database Auditing: Experience configuring log feeds and auditing for Windows Server/IIS, Linux, and Amazon RDS SQL Server audit logs.
  • Integration Knowledge: Experience securing and ingesting logs from middleware and file-transfer systems (e.g., GoAnywhere MFT, Dell Boomi, API connectors).
  • Scripting: Proficiency in Python, Bash, and JSON/YAML for security automation and API integrations.
  • U.S. Data Residency Requirement: Must reside and work exclusively within the United States.
5. Preferred Qualifications & Certifications
  • AWS Certified Security โ€“ Specialty
  • AWS Certified Solutions Architect (Associate or Professional)
  • GIAC Cloud Security Automation (GCSA), GCED, or CISSP
  • Experience with utility, energy-sector, or NERC/CIP-adjacent regulated cloud environments.