Point your AI agent at freehire and let it find you a job.

Get the CLI →

TIAG

NewBe an early applicant

SIEM Modernization Security Engineer

Posted Updated 1 view
Discussion

Summary

Hybrid (Bethesda, MD) security engineer at TIAG supporting a Uniformed Services University enclave: migrating ~150 on-prem and cloud servers from legacy Splunk Enterprise to a government-selected cloud-native SIEM (Splunk Cloud, Microsoft Sentinel, or Google Chronicle), with hands-on telemetry validation, DISA STIG/RMF/Zero Trust compliance, Tier 2 troubleshooting, and SOP/training documentation.

TIAG is now hiring a SIEM Modernization Security Engineer to support a modernization and transition initiative for a Uniformed Services University (USU) enclave. This position reports to our Bethesda, MD location in a Hybrid capacity.

The Security Engineer will work support the direction of the Lead SIEM Architect & provide ground-level engineering, technical enablement, and Tier 2 support to successfully transition approximately 150 on-premise and cloud-hosted servers from a legacy Splunk Enterprise environment to a modern, Government-selected cloud-native SIEM platform. The Engineer will actively enable this transition, validate telemetry, develop technical artifacts, and assist hands-on with implementation tasks where needed to ensure the project stays on track.

Primary Responsibilities

  • Assist the Lead SIEM Architect in auditing the current USU Splunk Enterprise environment to evaluate onboarded log sources, telemetry coverage, ingestion methods, and parser configurations.
  • Compare Splunk Cloud, Microsoft Sentinel, and Google Chronicle to identify the best SIEM solution for USU’s networks, ensuring it properly protects and handles their data.
  • Implement Security Configuration Baselines on the chosen platform to ensure compliance with DoD cybersecurity requirements, DISA STIG guidance, RMF controls, and Zero Trust principles.
  • Ensure system vulnerabilities across the SIEM platform and associated infrastructure are proactively identified, tracked, and patched in a timely manner to maintain a secure operating environment.
  • Assist in navigating the Risk Management Framework (RMF) process, ensuring that the selected SIEM solution and integrated systems align with required RMF controls and USU security policies.
  • Assist with the development, management, and resolution of Plan of Action and Milestones (POA&Ms) for any identified security deficiencies or configuration gaps discovered during the transition.
  • Develop, test, and package validated Reference Implementations for all supported OS categories using templates, scripts, Group Policy Objects (GPOs), and agent profiles.
  • Work alongside GFL administrators to actively assist in the hands-on onboarding of 150+ enterprise assets into the selected cloud-native SIEM environment.
  • Provide daily Tier 2 technical troubleshooting to resolve ingestion failures, parser inconsistencies, configuration errors, and transport connectivity issues encountered during transition.
  • Perform structured telemetry validation by testing at least one representative server for each supported operating system flavor to “prove the pipe”.
  • Confirm end-to-end event generation, transport, ingestion, parsing, normalization, and visibility within the selected SIEM platform.
  • Maintain a structured Tier 2 support process, including centralized ticket tracking, root cause analysis, and issue prioritization.
  • Author clear, practical, step-by-step Standard Operating Procedures (SOPs) tailored for Tier 1 GFL SIEM administrators covering log onboarding, telemetry validation, and health monitoring.
  • Document standardized alert tuning processes, threshold configurations, and event categorization guidelines to improve the SOC’s signal-to-noise ratio.
  • Support the Lead Architect in delivering targeted "delta" training on the selected SIEM platform's specific capabilities, such as query languages (KQL or UDM), telemetry management, and search optimization.
  • Facilitate hands-on operational demonstrations, guided troubleshooting sessions, and practical exercises for GFL administrators to reinforce learning and validate operational readiness.

Skills

Apply

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available