Security Engineer (Sentinel / SIEM)
Jobgether
full-remoteseniorpermanentsecuritybackend United States 80 days ago via LinkedIn
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
Microsoft SentinelSIEMKQLAWSAzureNIST 800-53NIST 800-92NIST 800-61Incident ResponseThreat Hunting
About the role
Role overview
Security Engineer specializing in Microsoft Sentinel / SIEM to support a federal-facing program. You will strengthen security monitoring, detection, and incident response by operating and improving SIEM capabilities across complex cloud and on-prem environments.
Responsibilities
- Manage and optimize Microsoft Sentinel SIEM operations: log ingestion, normalization, monitoring, and data pipeline health
- Build and maintain detection rules, correlation logic, dashboards, and analytics to improve threat visibility
- Support incident response, threat hunting, and forensic investigations with relevant log data and analysis
- Ensure integrity, confidentiality, and availability of security logs across multiple enterprise/cloud environments
- Coordinate onboarding of new log sources from AWS, Azure, and other systems, ensuring correct configuration and monitoring
- Maintain NIST-compliant documentation and audit readiness (federal security requirements)
- Monitor SIEM performance, identify ingestion gaps/failures, and implement corrective actions
Requirements
- 6+ years in security engineering or SOC/SIEM-focused roles
- Hands-on experience with Microsoft Sentinel (and other SIEM platforms)
- Strong knowledge of log management, ingestion, normalization, and security event correlation
- KQL (Kusto Query Language) proficiency for queries, analytics, and detections
- Experience with cloud security logs/environments such as AWS and Azure
- Familiarity with NIST frameworks: 800-53, 800-92, 800-61 (and related federal compliance standards)
- Active Public Trust clearance (required)
- Strong analytical thinking and ability to support incident response in high-pressure environments
Nice-to-haves
- Certifications such as CISSP, GCIH, GCIA, Microsoft Security certifications, or equivalent
Benefits / work arrangement
- Fully remote work arrangement within Canada
- Opportunity to support high-impact federal security programs
- Competitive compensation aligned with experience and clearance level
- Professional development and certification support
About Jobgether
Jobgether is an AI-driven job matching platform that reviews candidates against role requirements and shares the best-fit shortlist with hiring partners. In this listing, Jobgether is posting on behalf of a partner company supporting a federal-facing security program.
Scraped 5/12/2026