Information Security Engineer
Indexed description
Job Description:
- Seeking an early to mid-career Information Security Systems Engineer (ISSE) to support Security Information and Event Management (SIEM) platforms and related security tools in a managed enterprise environment for federal government customers.
- This role is primarily focused on SIEM engineering, including platform administration, log and data flow support, content development, and system troubleshooting across Windows and Linux environments.
- The selected candidate will also provide secondary support for related security tools and applications as needed.
- The ideal candidate will have hands-on experience with SIEM or centralized logging platforms, a solid foundation in Linux system administration, and a working understanding of networking, log analysis, and enterprise security operations.
- This role offers the opportunity to build hands-on expertise with enterprise SIEM and security monitoring technologies while supporting mission-critical environments for federal customers.
Essential Functions:
- Administer, maintain, and support SIEM platforms and associated application components in Windows and Linux environments
- Develop, tune, and maintain SIEM content, including dashboards, reports, alerts, rules, filters, queries, and data views
- Support log ingestion, onboarding of new log sources, data normalization, and data flow optimization to improve visibility and use case performance
- Troubleshoot SIEM platform issues, log collection problems, data flow interruptions, and system performance concerns
- Perform system administration activities for servers hosting SIEM and related security applications
- Use Linux command-line tools to perform routine administration, troubleshooting, and support tasks
- Assist with SIEM platform upgrades, patching, configuration changes, and general lifecycle maintenance
- Apply configuration management and change control practices to maintain system integrity, documentation, and version control
- Develop and maintain technical documentation for system configurations, support procedures, and operational changes in accordance with engineering processes
- Collaborate with internal teams and customers to resolve technical issues and support mission and operational requirements
- Provide secondary administration and support for related security tools and applications as assigned
- Participate in routine operational support activities, including maintenance, troubleshooting, and after-hours support when required.
Qualifications:
- Bachelor’s degree in computer engineering, Cybersecurity, Information Technology, Computer Science, or a related field with a minimum of 2 years of relevant experience; or a graduate degree in a related field with 0-2 years of relevant experience; or an equivalent combination of education and related experience
- Minimum of 2 years of experience supporting or administering SIEM, log management, or similar security monitoring platforms
- Hands-on experience using Linux command-line tools to perform system administration or troubleshooting tasks
- Basic understanding of TCP/IP communications, the OSI model, enterprise data flow concepts, log analysis, event monitoring, and troubleshooting in enterprise IT environments
- Experience following standard engineering, configuration management, or change management practices
- Ability to develop and maintain clear technical documentation, including system configurations, procedures, and updates, in accordance with established engineering processes
- Strong written and verbal communication skills
- Ability to work effectively with internal teams, customers, and other technical stakeholders.
Preferred Additional Skills:
- Experience with SIEM platforms such as ArcSight, Splunk, LogRhythm, Exabeam, or similar technologies
- Experience supporting security tools or applications in Windows and Linux server environments
- Familiarity with log parsing, data normalization, filtering, or regular expressions
- Experience with scripting or automation using Shell, Python, or similar languages
- Experience with Windows system administration in an enterprise environment
- Familiarity with security operations workflows, incident triage, or threat detection concepts
- Familiarity with network security monitoring, intrusion detection, or event correlation concepts
- Experience supporting government customers in a regulated or security-focused environment
- Familiarity with NIST SP 800-53, NIST SP 800-171, or similar security control frameworks
- Relevant certifications such as Security+, Linux+, Network+, SIEM vendor certifications, or similar credentials.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search