SIEM Engineer

National Association of Insurance Commissioners•Kansas City, KS
•Remote

About The Position

The Information Technology division of the National Association of Insurance Commissioners (NAIC) has an exciting opportunity for a SIEM Engineer. This position defines, implements, and maintains the organization’s security monitoring and detection capabilities within the Google SecOps platform. Partners closely with Incident Response, and Security Architecture teams to ensure security telemetry is effectively collected, normalized, and monitored, enabling the detection, investigation, and response to cybersecurity threats across the enterprise. This is a full-time remote position. Residency within a 100-mile radius of the Kansas City, MO office is required.

Requirements

  • Bachelor’s degree from four-year college or university in a computer related field and 5+ years of experience in information security, with significant focus on security operations, or equivalent combination of education and technical experience.
  • Hands-on experience administering Google SecOps (Chronicle) or an equivalent enterprise SIEM platform.
  • Hands-on Experience with cloud security monitoring across AWS, Azure, or Google Cloud Platform.
  • Familiarity with security operations, threat hunting, and detection engineering practices.
  • Strong working knowledge of: Security telemetry collection, log parsing, and data normalization
  • Threat detection, alert triage, and incident response
  • MITRE ATT&CK and modern adversary tactics, techniques, and procedures
  • Ability to communicate complex security concepts clearly to technical and non-technical audiences.
  • Familiarity with developing detection content using YARA-L and Unified Data Model (UDM) and investigating security incidents.
  • Hands-on experience with Endpoint Detection & Response (EDR/XDR) and Threat Intelligence Platforms.

Nice To Haves

  • Experience with the Unified Data Model (UDM) and custom parser development.
  • Familiarity with the NIST Cybersecurity Framework.
  • Relevant certifications (e.g., CISSP, GCIH, GCIA, and Security+)
  • Experience with Google SecOps SOAR and playbook development
  • Experience managing and implementing OpenTelemtry Collectors.
  • Experience with Windows Event Logging and Sysmon.

Responsibilities

  • Design, implement, and maintain the Google SecOps platform, including log ingestion, parsing, normalization, and enrichment across cloud, on-premises, SaaS, and security data sources.
  • Onboard, validate and monitor new log sources within Google SecOps, ensuring proper mapping to the Unified Data Model (UDM) and maintaining telemetry coverage, parser performance, and platform health.
  • Develop Google SecOps dashboards, operational metrics, and reporting to support security monitoring, compliance, audit, and executive reporting requirements.
  • Develop and maintain automated investigation and response workflows using Google SecOps capabilities to streamline triage, enrichment, and response actions.
  • Assist with the development, tuning, and maintenance of detection content using YARA-L, aligned to MITRE ATT&CK techniques, and continuously reduce false positives to improve detection fidelity.

Benefits

  • The NAIC offers amazing benefits.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service