At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company’s success. As a Security Engineer (SIEM) within PNC's Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; Birmingham, AL; Dallas, TX or Lakewood, CO. The SIEM Security Engineer is responsible for designing, operating, and maintaining security information and event management (SIEM) capabilities that support enterprise security monitoring and threat detection. This role onboards and manages log data, develops content, tunes detections, and supports incident response through actionable security insights. The SIEM Security Engineer works closely with security operations, engineering, and technology teams to improve visibility across hybrid cloud and on prem environments and ensure alignment with security and regulatory requirements. As a SIEM Security Engineer, you’ll design, engineer, and operate enterprise scale SIEM platforms that support high volume log ingestion, normalization, correlation, alerting, and long term retention across hybrid cloud and on prem environments. You will architect and maintain end to end data onboarding pipelines, covering source onboarding, parsing, field extraction, normalization, enrichment, and validation to ensure telemetry is high quality, searchable, and actionable. In this role, you will develop, test, and maintain SIEM detection content, including correlation searches, analytic rules, alerts, and risk based detections aligned to real world attacker techniques and behaviors. You will write and optimize advanced search queries to support detections, investigations, dashboards, and threat hunting use cases, balancing performance, cost, and data fidelity. You will also build and maintain operational and security dashboards that provide visibility into threat activity, platform health, coverage gaps, and detection effectiveness for GSFC teams and security leadership. You will perform threat analytics and proactive hunting by leveraging SIEM telemetry to identify anomalous behavior, validate detection hypotheses, and uncover gaps in existing monitoring and content. Partnering closely with SOC and Incident Response teams, you will investigate alerts, provide deep technical analysis, enrich events with contextual data, and continuously improve signal to noise ratio and response outcomes. Additionally, you will monitor and tune SIEM platform performance, including ingest volume, indexing efficiency, search performance, data retention, and licensing utilization. You will manage the SIEM configuration and content lifecycle through version control, change management, testing, and promotion across environments. You will define and track technical metrics and KPIs for detection coverage, alert quality, data completeness, and platform reliability, mapping coverage to the MITRE ATT&CK framework. You will support broader security architecture and engineering initiatives by integrating SIEM with upstream and downstream systems such as cloud services, endpoint tooling, network telemetry, and SOAR platforms. You will author and maintain technical documentation, including onboarding standards, detection logic, architecture diagrams, and operational runbooks, and continuously evaluate new telemetry sources, detection techniques, and platform capabilities to evolve security monitoring and reduce enterprise risk.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level