ECS

SIEM Infrastructure and Detection Engineer

ECS  •  Portland, OR (Hybrid)  •  7 days ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Everforth ECS is seeking an SIEM Infrastructure and Detection Engineer to join our team in our Portland, OR (Hybrid) office.

The SIEM Infrastructure and Detection Engineer supports a federal energy sector cybersecurity program by engineering, maintaining, and optimizing the SIEM infrastructure and security monitoring platform, including detections, visualizations, dashboards, and reporting. This role ensures the reliability and effectiveness of SIEM and related monitoring tools to meet Information Security Continuous Monitoring (ISCM) and Department of Homeland Security (DHS) Continuous Diagnostics and Mitigation (CDM) requirements. The engineer works directly with security analysts, system owners, and DHS CDM teams to ensure continuous visibility, timely detection, and compliance with federal cybersecurity standards.

Core Capabilities

  • Lead the design, deployment, and monitoring of enterprise SIEM platforms (e.g., Splunk, Elastic Stack)
  • Architect, implement, and maintain integrations with enterprise systems, cloud environments, and security tools (e.g., EDR, IDS/IPS, firewalls, TIP)
  • Develop and optimize dashboards, alerts, and data pipelines
  • Automate platform tasks and SIEM processes using scripting (e.g., Python, PowerShell, bash)
  • Monitor and tune platform performance to ensure high availability and accuracy of security data
  • Troubleshoot and resolve platform-related issues in coordination with analysts and engineers
  • Collaborate with federal stakeholders to align SIEM capabilities with ISCM and CDM reporting requirements
  • Maintain documentation of platform configurations, standard operating procedures, and system baselines

Qualifications

  • U.S. Citizenship with ability to obtain and maintain a DOE “L” clearance
  • Hands-on experience with at least one enterprise SIEM platform (Splunk, Elastic, QRadar, or LogRhythm)
  • Experience integrating SIEM with enterprise IT systems, cloud platforms, or endpoint detection tools
  • Experience onboarding diverse log sources (network, endpoint, cloud, SaaS) and tuning correlation rules
  • Proficiency in scripting (Python, PowerShell, or Bash) for automation and data integration
  • Experience with configuration management tools (e.g., Ansible, Terraform, Chef, Puppet)
  • Experience with Application Control (Carbon Black) and Endpoint Detection and Response platforms (Microsoft Defender, CrowdStrike, Trend Micro)
  • Minimum 5 years of experience in cybersecurity engineering and security monitoring, including 3+ years dedicated to SIEM engineering
ECS

About ECS

ECS is a fast-growing 4,000-person, $1.2B provider of advanced technology solutions for federal civilian, defense, intelligence, and commercial customers. We tackle complex client challenges with smart, scalable solutions in data and AI, cybersecurity, and digital transformation. Our collective work empowers customers’ missions, strengthens our partners, inspires our employees, and grows our company.

To achieve our purpose — to tackle the missions that matter most and create a lasting impact on our customers, employees, and community — we are committed to excellence in growth, customer delivery, technology innovation, and employee engagement.  

We believe in:

• Attracting, developing, and retaining top talent

• Building high-performing teams

• Creating an engaging employee environment

• Acting with social responsibility

• Having a positive impact on our community

Our core values: Excellence, Drive, Grit, and Community. We keep these values at the heart of all we do. We’re looking for driven individuals who want to solve meaningful challenges and help shape the future of national security and public service. If you’re ready to make a difference, you’ll find your team here.

Industry
IT & Software
Company Size
1,001-5,000 employees
Headquarters
Fairfax, VA
Year Founded
1993
Social Media