Valiant Solutions logo
Valiant Solutions

Protect. Defend. Comply.

Senior SIEM Engineer

EngineerEngineerFull TimeRemoteSeniorTeam 201-500Since 2005H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

3 days ago

Salary

0

Seniority

Senior

Bachelor Degree8 yrs expEnglishAWSCloudCyber SecurityPythonServiceNowSplunk

Job Description

Senior SIEM Engineer

Valiant Solutions

• Lead the architecture, deployment, upgrade, and sustainment of the SIEM environment supporting the client's SOC, including indexer and search head clusters, forwarders, and supporting infrastructure. • Monitor SIEM platform health, license usage, indexing latency, search performance, and ingest rates, and proactively address capacity, performance, and availability issues. • Onboard new data sources by defining requirements, configuring inputs and forwarders, building parsing and field extractions, and validating Common Information Model (CIM) compliance. • Develop, tune, and maintain correlation searches, notable events, dashboards, reports, and data models that support Tier 1 triage within fifteen minutes of detection and Tier 2 analysis within four hours of escalation. • Build and maintain SOC dashboards that provide real-time visibility into the client's security posture, supporting both day-to-day operations and executive reporting. • Translate detection requirements from threat hunters, CTI analysts, and engineering teams into production SIEM content mapped to the MITRE ATT&CK framework. • Integrate SIEM with SOAR, EDR, NDR, DLP, CDM, vulnerability management, and identity platforms to support automated triage, enrichment, and response. • Reduce false positive rates and alert fatigue by tuning correlation rules, refining thresholds, and applying risk-based alerting techniques. • Support incident response by building investigation queries, producing timeline reconstructions, preserving evidence, and contributing artifacts to initial incident reports within one hour of confirmation and final reports within seventy-two hours. • Author and maintain Engineering Design Documents, Standard Operating Procedures, runbooks, and configuration guides for the SIEM environment, and review them on the cadence required by the SOC CONOPS. • Partner with the Security Architect and engineering leads to align SIEM design with Zero Trust principles, the client's Technology Standards, and the agency's broader cybersecurity reference architecture. • Manage SIEM-related changes through the client's change control process, including impact assessments, back-out plans, and presentations to the Engineering Review Board and Change Control Board. • Provide knowledge transfer and informal training to SOC analysts, engineers, and system owners on SIEM usage, search development, and dashboard interpretation. • Apply secure configuration baselines, role-based access controls, and audit logging to the SIEM environment to meet federal compliance requirements. • Track and report on SIEM-related metrics, including ingest volume by source, detection coverage by MITRE technique, mean time to detect, and platform availability. • Stay current on SIEM product roadmap items, new applications and add-ons, and emerging detection techniques, and recommend improvements to the client's SIEM strategy.

Job Requirements

  • Eight or more years of cybersecurity engineering experience, with at least five years dedicated to SIEM architecture, administration, and content development.
  • Hands-on experience designing and operating distributed SIEM deployments at enterprise scale, including indexer clusters, search head clusters, heavy and universal forwarders, deployment servers, and license management.
  • Demonstrated experience writing, tuning, and optimizing queries, correlation searches, data models, accelerated summaries, lookups, and macros.
  • Working knowledge of security focused SIEM components, including notable event framework, risk-based alerting, asset and identity frameworks, and adaptive response actions.
  • Experience in onboarding diverse data sources at scale, including operating system logs, network flow and packet data, cloud platform logs (AWS CloudTrail, GuardDuty, VPC Flow, Config), endpoint telemetry, application logs, and identity provider logs.
  • Experience integrating SIEM with SOAR platforms, Endpoint Detection and Response tools, Continuous Diagnostics and Mitigation (CDM) data feeds, vulnerability management platforms, and ticketing systems such as ServiceNow.
  • Working knowledge of AWS GovCloud services and the design patterns used to forward, normalize, and secure log data from cloud-native sources.
  • Familiarity with the MITRE ATT&CK framework and experience translating adversary techniques into SIEM detection content.
  • Working knowledge of NIST SP 800-53, NIST SP 800-61, and NIST SP 800-137, and the ability to map SIEM controls and continuous monitoring practices to those frameworks.
  • Experience supporting incident response activities, including building investigation dashboards, preserving log evidence, and producing artifacts for post-incident reporting.
  • Strong scripting and automation skills in at least one of Python, Bash, or PowerShell, and comfort with version control using Git.
  • Beneficial Splunk certifications: Splunk Core Certified Power User and Splunk Enterprise Certified Admin. Splunk Certified Architect, Splunk Enterprise Security Certified Admin, or Splunk Core Certified Consultant is strongly preferred.
  • Required to obtain and maintain a Non-Sensitive / High Risk (Public Trust) security clearance at the Tier 4/6c level.
  • Strong written and verbal communication skills, with the ability to brief technical findings to SOC leadership, ISSOs, and senior Government officials.

Benefits

  • Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees
  • Valiant contributes 25% towards Health Coverage for Family and Dependents
  • 100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees
  • 100% Paid Certifications
  • 401K Matching up to 4%
  • Paid Time Off
  • Paid Federal Holidays
  • Wellness & Fitness Program
  • Valiant University – Online Education and Training Portal
  • FSA programs for: Medical Costs, Dependent Care, Transit, and Parking
  • Referral Bonuses

Related Categories

Related Job Pages

More Engineer Jobs

CoreWeave logo

Supplier Quality Engineer (OEM/ODM, Thermal & Cooling)

CoreWeave

CoreWeave is a specialized cloud provider, delivering a massive range of GPU compute resources on demand and at scale.

Engineer3 days ago
Full TimeRemoteTeam 11-50Since 2017H1B No Sponsor

CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at www.coreweave.com. What You’ll Do:The Supply Chain & Supplier Quality team at CoreWeave is responsible for ensuring the quality, reliability, and scalability of the hardware infrastructure powering our AI cloud platform. The team partners closely with OEM/ODM manufacturers, thermal solution providers, and engineering teams across the US and APAC to drive world-class supplier quality standards and operational excellence across our global hardware supply chain. About the RoleCoreWeave is seeking a Supplier Quality Engineer based in Taiwan to serve as our on-the-ground quality representative within the APAC hardware manufacturing ecosystem. In this role, you will work directly with OEM/ODM server integrators and thermal/cooling suppliers to drive supplier quality execution across new product introductions, manufacturing readiness, and field performance improvement initiatives. You will lead APQP and PPAP activities, conduct supplier process and quality audits, oversee thermal validation and corrective actions, and act as the primary bridge between Taiwan-based suppliers and CoreWeave’s US engineering and supply chain teams. This is a highly collaborative, field-based role requiring frequent supplier engagement, strong technical expertise in server hardware and thermal systems, and the ability to independently manage complex supplier quality programs across multiple time zones. Who You Are: - Bachelor’s degree in Mechanical Engineering, Thermal Engineering, Electrical Engineering, or a related technical field - 5+ years of Supplier Quality Engineering or manufacturing quality experience within the Taiwan hardware manufacturing ecosystem - Experience working directly with Taiwan-based ODMs - Hands-on experience with thermal component manufacturing and qualification including heat sinks, TIMs, cold plates, fans, and/or CDUs - Demonstrated experience leading APQP and PPAP processes for electromechanical or thermal assemblies - Experience conducting ISO 9001 and/or IATF 16949 quality management system audits - Proficiency with statistical quality tools including SPC, Cpk/Ppk, and MSA/Gage R&R using Minitab or equivalent software - Experience leading structured problem-solving methodologies such as 8D and DMAIC - Native or near-native Mandarin Chinese proficiency with business-level English communication skills - Ability to independently manage supplier quality activities, field-based work, and frequent supplier site visits across APAC - Experience developing and reviewing DFMEA/PFMEA, Control Plans, and supplier corrective action documentation - Experience leading First Article Inspections (FAI), supplier qualification audits, and CAPA closure activities - Ability to define and validate thermal test protocols and acceptance criteria for GPU server assemblies and cooling systems Preferred: - Experience working with cooling and thermal vendors such as Delta Electronics, AVC, Auras Technology, Jetcool, CoolIT, or Vertiv - Hands-on experience qualifying thermal solutions for NVIDIA HGX H100/H200 or Blackwell GB200 NVL72 platforms - Familiarity with NVIDIA Taiwan partner engineering and thermal validation ecosystems - Knowledge of liquid cooling loop design including pressure drop analysis, coolant compatibility, and flow rate requirements - CQE (ASQ Certified Quality Engineer) or Six Sigma Green Belt/Black Belt certification - Experience with OpenCompute Project (OCP) hardware standards - Experience supporting high-density GPU rack deployments in hyperscale or AI infrastructure environments - Experience using Jira, ServiceNow, or Arena PLM for supplier quality management and NCR/CAPA tracking Wondering if you’re a good fit?We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams, even if you aren't a 100% skill or experience match. Here are a few qualities we’ve found compatible with our team. If some of this describes you, we’d love to talk. - You love solving complex manufacturing and supplier quality challenges in fast-paced hardware environments - You’re curious about next-generation AI infrastructure, GPU thermal management, and scalable data center technologies - You’re an expert in supplier quality methodologies, APQP/PPAP execution, and driving operational excellence across global manufacturing partners Why CoreWeave?At CoreWeave, we work hard, have fun, and move fast! We’re in an exciting stage of hyper-growth that you will not want to miss out on. We’re not afraid of a little chaos, and we’re constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values: - Be Curious at Your Core - Act Like an Owner - Empower Employees - Deliver Best-in-Class Client Experiences - Achieve More Together The base salary range for this role is TWD 2,175,000 - TWD 2,901,000. The starting salary will be determined by job-related knowledge, skills, experience, and the market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility). What We Offer The range we’ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location. In addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings; for roles in other locations, benefits vary and are shared during the hiring process. These include: - Medical, dental, and vision insurance - 100% paid for by CoreWeave - Company-paid Life Insurance - Voluntary supplemental life insurance - Short and long-term disability insurance - Flexible Spending Account - Health Savings Account - Tuition Reimbursement - Ability to Participate in Employee Stock Purchase Program (ESPP) - Mental Wellness Benefits through Spring Health - Family-Forming support provided by Carrot - Paid Parental Leave - Flexible, full-service childcare support with Kinside - 401(k) with a generous employer match - Flexible PTO - Catered lunch each day in our office and data center locations - A casual work environment - A work culture focused on innovative disruption California Applicants California Consumer Privacy Act Equal Opportunity & Accommodations CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: careers@coreweave.com. Export Control Compliance This position requires access to export controlled information. To conform to U.S. Government export regulations applicable to that information, applicant must either be (A) a U.S. person, defined as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C. § 1158, (B) eligible to access the export controlled information without a required export authorization, or (C) eligible and reasonably likely to obtain the required export authorization from the applicable U.S. government agency. CoreWeave may, for legitimate business reasons, decline to pursue any export licensing process.

Taiwan
Group 1001 logo

Senior DWX Microsoft Engineer

Group 1001

We are a financial services enterprise creating useful and intuitive solutions and products for everyone.

Engineer3 days ago
Full TimeRemoteTeam 501-1,000H1B Sponsor

• You will be the platform owner for endpoint at our firm — the engineer accountable for how every device is provisioned, secured, managed, and retired. • Intune, Autopilot, Defender for Endpoint, Entra ID, Configuration Manager where it still matters, and the full M365 suite (Teams, Exchange Online, SharePoint, OneDrive, Purview) all fall within your scope. • You'll set the standard for how we deploy, patch, harden, and evolve these platforms. • You'll embed AI and automation into the fabric of how DWX operates.

United States
$180K - $230K / year

Role Description Nous sommes à la recherche d'un·e ingénieur·e en fiabilité des sites (SRE) pour aider nos clients à concevoir et exploiter des systèmes de production fiables, observables et sécurisés. Dans ce rôle, vous travaillerez aux côtés des équipes d'ingénierie et d'exploitation de nos clients pour : - Améliorer la fiabilité des systèmes - Réduire les tâches manuelles répétitives - Bâtir les fondations opérationnelles — pipelines de déploiement, surveillance, gestion des incidents, infrastructure Veuillez noter que, bien que nous soyons spécialisés dans le secteur de la santé et les industries réglementées, tous nos projets ne relèvent pas de ces domaines. Vous pourriez donc être amené·e à travailler sur des projets variés dans différents secteurs, selon les besoins. Qualifications - 5 ans ou plus d'expérience en infrastructure, DevOps ou ingénierie de la fiabilité des sites - Expérience pratique avec des infrastructures AWS ou Azure et des outils d'infrastructure-as-code (Terraform, CloudFormation ou équivalents) - Solide expérience avec les pipelines CI/CD (GitHub Actions, ArgoCD, Jenkins ou équivalents) et l'automatisation des déploiements - Expérience avec des outils d'observabilité (Prometheus, Grafana, Datadog, CloudWatch ou équivalents) et les processus de gestion des incidents - Familiarité avec les bonnes pratiques de sécurité pour l'infrastructure infonuagique, incluant la sécurité réseau, l'IAM, le chiffrement et la gestion des vulnérabilités - Excellentes compétences en communication et capacité d'expliquer des concepts d'infrastructure et de fiabilité à des parties prenantes variées - Adaptabilité, autonomie et aisance dans des environnements clients dynamiques - Capacité à expliquer les compromis entre fiabilité et sécurité et les relier aux besoins d'affaires Requirements - Expérience dans des rôles orientés client (consultation, ingénierie d'implantation, services-conseils) - Expérience dans le secteur de la santé ou d'autres industries fortement réglementées - Expérience en développement logiciel au-delà du simple scripting (développement de fonctionnalités, d'API ou d'applications) - Expérience avec l'orchestration de conteneurs (Kubernetes, ECS) et les outils de sécurité cloud-native - Expérience en automatisation d'infrastructure à l'aide de scripts (Python, Bash) ou d'outils de workflow - Détention de certifications pertinentes (AWS DevOps Professional, AWS Solutions Architect, CKA ou équivalentes) Benefits - Budget pour le bureau à domicile et la technologie - Budget annuel de développement professionnel - REER avec contribution de l'employeur après 1 an - Dès le premier jour : Assurance santé et dentaire payée à 100 % par l'employeur, incluant un montant annuel pour les soins complémentaires (acupuncture, ostéopathie, massothérapie, naturopathie, psychologie, etc.) - Assurance vie et assurance invalidité de courte et de longue durée - Complément de congé parental (8 semaines), disponible pour les employés ayant plus d'un an d'ancienneté, quel que soit le chemin vers la parentalité

Canada
Engineer3 days ago
Full TimeRemoteTeam 201-500Since 2005H1B No Sponsor

• Provide engineering and technical expertise in PQC, PKI, and Automated Cryptographic Discovery and Inventory (ACDI) implementation. • Collaborate with stakeholders to define and refine PQC solution requirements. • Deliver analyses, recommendations, and staffing support to advance PQC program goals. • Develop engineering, implementation, and operations technical documents, schedules, and roadmaps. • Support modernization of cryptographic inventory management from manual to automated processes using COTS/GOTS ACDI tools. • Evaluate emerging technologies and provide recommendations to leadership. • Implement and operationalize the client's PQC technical solution in line with Department requirements. • Deploy ACDI capabilities to generate cryptographic inventories of quantum-vulnerable systems. • Conduct and document post-implementation evaluations to validate PQC solution effectiveness. • Securely integrate PQC and ACDI with existing Department services (CDM, VM, Zero Trust, etc.). • Prototype and test NIST-approved PQC algorithms and discovery tools. • Install and configure hardware/software replacements and upgrades for PQC transition. • Provide operations and maintenance (O&M) of the PQC solution (COTS, GOTS, SaaS). • Monitor solution health, performance, and availability; manage patching, upgrades, and optimization. • Maintain accurate solution inventories, secure configuration baselines, and user account validation. • Develop operational documentation including SOPs, playbooks, checklists, and user guides. • Provide after-hours technical support for planned and emergency maintenance. • Collaborate with SOC and other technical teams on incident response, process optimization, and integration. • Support PQC compliance with FISMA, NIST, and federal cybersecurity mandates. • Drive Risk Management Framework (RMF) activities, including POA&M management and A&A processes. • Prepare and maintain system security documentation (SSP, IRP, DRP, BIA, CP, etc.). • Support audits by providing evidence, coordination, tracking, and corrective actions. • Ensure ongoing risk management, continuous monitoring, and compliance with privacy and records management requirements.

United States
$145K - $165K / year