SIEM Modernization Security Engineer

TIAGBethesda, MD
$100,000 - $120,000Hybrid

About The Position

TIAG is now hiring a SIEM Modernization Security Engineer to support a modernization and transition initiative for a Uniformed Services University (USU) enclave. This position reports to our Bethesda, MD location in a Hybrid capacity. The Security Engineer will work support the direction of the Lead SIEM Architect & provide ground-level engineering, technical enablement, and Tier 2 support to successfully transition approximately 150 on-premise and cloud-hosted servers from a legacy Splunk Enterprise environment to a modern, Government-selected cloud-native SIEM platform. The Engineer will actively enable this transition, validate telemetry, develop technical artifacts, and assist hands-on with implementation tasks where needed to ensure the project stays on track.

Requirements

  • 3–7 years of hands-on experience in cybersecurity engineering, specifically focusing on SIEM engineering, log routing, telemetry validation, and vulnerability management.
  • Operational experience configuring and maintaining enterprise SIEM platforms such as Splunk Enterprise, Splunk Cloud, Microsoft Sentinel, or Google Chronicle.
  • Proven ability to troubleshoot log transport connectivity, parser failures, agent misconfigurations, and data normalization issues across diverse OS environments.
  • Hands-on experience developing and deploying configuration artifacts, including deployment scripts, GPOs, and hardened agent configurations.
  • Working knowledge of Federal and DoD compliance frameworks, including DISA STIGs, Risk Management Framework (RMF), and Zero Trust logging requirements.
  • Demonstrated experience assisting with POA&Ms and patching workflows.
  • Strong technical writing skills to author operational SOPs, combined with the ability to provide over-the-shoulder mentoring and practical training to Tier 1 operational personnel.
  • IAT/IAM Level III Certification
  • Secret Clearance

Responsibilities

  • Assist the Lead SIEM Architect in auditing the current USU Splunk Enterprise environment to evaluate onboarded log sources, telemetry coverage, ingestion methods, and parser configurations.
  • Compare Splunk Cloud, Microsoft Sentinel, and Google Chronicle to identify the best SIEM solution for USU’s networks, ensuring it properly protects and handles their data.
  • Implement Security Configuration Baselines on the chosen platform to ensure compliance with DoD cybersecurity requirements, DISA STIG guidance, RMF controls, and Zero Trust principles.
  • Ensure system vulnerabilities across the SIEM platform and associated infrastructure are proactively identified, tracked, and patched in a timely manner to maintain a secure operating environment.
  • Assist in navigating the Risk Management Framework (RMF) process, ensuring that the selected SIEM solution and integrated systems align with required RMF controls and USU security policies.
  • Assist with the development, management, and resolution of Plan of Action and Milestones (POA&Ms) for any identified security deficiencies or configuration gaps discovered during the transition.
  • Develop, test, and package validated Reference Implementations for all supported OS categories using templates, scripts, Group Policy Objects (GPOs), and agent profiles.
  • Work alongside GFL administrators to actively assist in the hands-on onboarding of 150+ enterprise assets into the selected cloud-native SIEM environment.
  • Provide daily Tier 2 technical troubleshooting to resolve ingestion failures, parser inconsistencies, configuration errors, and transport connectivity issues encountered during transition.
  • Perform structured telemetry validation by testing at least one representative server for each supported operating system flavor to “prove the pipe”.
  • Confirm end-to-end event generation, transport, ingestion, parsing, normalization, and visibility within the selected SIEM platform.
  • Maintain a structured Tier 2 support process, including centralized ticket tracking, root cause analysis, and issue prioritization.
  • Author clear, practical, step-by-step Standard Operating Procedures (SOPs) tailored for Tier 1 GFL SIEM administrators covering log onboarding, telemetry validation, and health monitoring.
  • Document standardized alert tuning processes, threshold configurations, and event categorization guidelines to improve the SOC’s signal-to-noise ratio.
  • Support the Lead Architect in delivering targeted "delta" training on the selected SIEM platform's specific capabilities, such as query languages (KQL or UDM), telemetry management, and search optimization.
  • Facilitate hands-on operational demonstrations, guided troubleshooting sessions, and practical exercises for GFL administrators to reinforce learning and validate operational readiness.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service