SonicJobs Logo
Left arrow iconBack to search

SIEM UEBA Engineer Mid

Koniag Government Services, LLC
Posted 2 days ago, valid for 7 hours
Location

Washington, DC, US

Salary

$105,000 - $135,000 per year

Contract type

Full Time

Health Insurance
Paid Time Off
Flexible Spending Account

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced SIEM/UEBA Engineer (Mid) to support enterprise cybersecurity operations and IT administrative and operational support services for a federal government client. This position requires an active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.

 

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

 

This role serves as a critical technical function responsible for the administration, engineering, and continuous improvement of enterprise Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA) platforms across a complex, geographically distributed federal IT environment spanning on-premises infrastructure, cloud platforms, and enterprise applications.

 

The ideal candidate is a technically proficient and analytically driven cybersecurity professional with demonstrated hands-on experience engineering, administering, and tuning enterprise SIEM and UEBA platforms, developing high-fidelity detection content, and supporting threat detection and incident response operations within a federal government IT environment. This individual must possess the technical depth, analytical rigor, and operational discipline required to build and sustain robust, detection-rich security monitoring capabilities that provide the Government with accurate, timely, and actionable visibility into threats and anomalous activity across the enterprise.

 

The SIEM/UEBA Engineer (Mid) will serve as a key technical contributor responsible for the engineering, administration, and continuous improvement of the program's enterprise SIEM and UEBA platforms, detection content library, log ingestion architecture, and security analytics capabilities. This individual works closely with security engineers, SOC analysts, incident responders, infrastructure engineers, cloud operations teams, and Government stakeholders to ensure the SIEM and UEBA platforms provide comprehensive, high-fidelity, and continuously improving threat detection and behavioral analytics coverage across the full enterprise environment—supporting the Government's ability to detect, investigate, and respond to cybersecurity threats rapidly and effectively.

 

Principal responsibilities will include but are not limited to:

SIEM Platform Engineering & Administration

  • Administer, engineer, and maintain the enterprise SIEM platform, ensuring the platform is properly configured, optimized, and continuously improved to support comprehensive security monitoring, threat detection, and incident investigation across the full enterprise environment.
  • Design, implement, and maintain log ingestion architectures, ensuring all required log sources—including endpoints, servers, network devices, cloud platforms, enterprise applications, identity platforms, and security tools—are onboarded, reliably ingesting, and properly parsed into the SIEM.
  • Develop and maintain log source onboarding documentation, data ingestion runbooks, and parser configurations, ensuring all log sources are accurately documented and ingestion pipelines are well-understood and maintainable.
  • Monitor SIEM platform health, performance, and data ingestion reliability, proactively identifying and resolving ingestion failures, data gaps, parsing errors, and platform performance issues before they impact detection capability or investigation support.
  • Manage SIEM platform capacity, licensing, and storage, ensuring the platform operates within defined performance parameters and that capacity planning activities are conducted proactively to address growth in log volume and data retention requirements.
  • Implement and maintain SIEM platform access controls, ensuring role-based access is properly configured and that analyst, engineer, and administrative access privileges are aligned with least-privilege principles and applicable Federal security requirements.
  • Support SIEM platform upgrades, patches, and configuration changes, coordinating with the change management process and ensuring all changes are properly tested and documented prior to production implementation.
  • Develop and maintain SIEM platform architecture documentation, including data flow diagrams, log source inventories, ingestion pipeline configurations, and platform configuration baselines.

UEBA Platform Engineering & Administration

  • Administer, engineer, and maintain the enterprise UEBA platform, ensuring the platform is properly integrated with relevant data sources, accurately modeling user and entity behavior baselines, and generating high-fidelity risk scores and anomaly detections.
  • Design and implement UEBA data source integrations, ensuring the platform ingests relevant identity, authentication, endpoint, application, cloud, and network data necessary to build accurate and comprehensive behavioral baselines.
  • Configure and tune UEBA behavioral models, risk scoring algorithms, and anomaly detection rules, balancing detection sensitivity with alert fidelity to maximize actionable insight while minimizing false positive rates.
  • Develop and maintain UEBA use cases targeting insider threat scenarios, compromised credential activity, privilege escalation, lateral movement, data exfiltration, and other high-priority behavioral risk indicators relevant to the enterprise environment.
  • Monitor UEBA platform health, performance, and detection output quality, proactively identifying and resolving platform issues, model degradation, and detection coverage gaps.
  • Develop and maintain UEBA platform documentation, including use case specifications, risk scoring configurations, behavioral model descriptions, and integration architecture documentation.

Detection Engineering & Content Development

  • Design, develop, implement, and continuously improve a comprehensive library of SIEM detection rules, correlation queries, behavioral analytics models, and alerting configurations aligned with the MITRE ATT&CK framework, covering the full spectrum of relevant adversary tactics, techniques, and procedures (TTPs) targeting the enterprise environment.
  • Conduct regular detection coverage assessments, mapping existing detection content against the MITRE ATT&CK framework to identify coverage gaps, prioritize new detection development, and ensure detection capabilities keep pace with the evolving threat landscape.
  • Develop and maintain detection content for high-priority threat scenarios, including insider threats, credential theft and abuse, privilege escalation, lateral movement, command-and-control communications, data exfiltration, ransomware activity, and cloud-based attack techniques.
  • Implement and maintain detection tuning processes, regularly reviewing alert volumes, false positive rates, and detection fidelity metrics to identify and implement tuning improvements that increase alert quality and reduce analyst burden.
  • Develop and maintain threat-informed detection content based on current threat intelligence, Government-issued advisories, and observed threat actor TTPs, ensuring detection capabilities are continuously updated to address emerging threats.
  • Develop and maintain detection content documentation, including detection rule specifications, use case descriptions, alert triage guides, and expected false positive patterns, ensuring detection content is well-documented and maintainable.
  • Support purple team and detection validation activities, coordinating with threat emulation and penetration testing efforts to validate detection coverage and identify gaps requiring additional detection development.

Log Source Management & Data Normalization

  • Manage the enterprise log source inventory, maintaining an accurate and current record of all log sources onboarded to the SIEM, including source type, ingestion method, data volume, parsing status, and detection relevance.
  • Develop and maintain custom log parsers, field extraction configurations, and data normalization mappings for non-standard or custom log sources, ensuring all ingested data is accurately parsed and available for detection and investigation use.
  • Conduct regular log source quality assessments, identifying and resolving data quality issues, parsing errors, field mapping inconsistencies, and ingestion reliability problems that may impact detection fidelity or investigation capability.
  • Support the onboarding of new log sources as the enterprise environment evolves, working with infrastructure engineers, cloud operations teams, and application owners to identify, onboard, and validate new data sources relevant to security monitoring objectives.
  • Develop and maintain log ingestion and data normalization documentation, ensuring all custom parsers, field mappings, and ingestion configurations are accurately documented and version-controlled.

Security Analytics & Threat Intelligence Integration

  • Develop and maintain advanced security analytics capabilities within the SIEM and UEBA platforms, including threat hunting queries, statistical analysis models, and automated enrichment workflows that enhance detection and investigation capabilities.
  • Integrate threat intelligence feeds into the SIEM platform, developing automated indicator of compromise (IOC) matching, threat intelligence enrichment, and threat intelligence-driven alerting capabilities.
  • Develop and maintain automated alert enrichment workflows, ensuring SIEM alerts are automatically enriched with relevant contextual data—including asset information, user identity data, threat intelligence, and vulnerability context—to accelerate analyst triage and investigation.
  • Support threat hunting activities, developing and executing hypothesis-driven hunting queries across SIEM data to proactively identify indicators of compromise, anomalous activity, and undetected threats within the enterprise environment.
  • Analyze threat hunting findings and SIEM detection performance data to identify opportunities for new detection content development, platform tuning improvements, and security control enhancements.

Incident Investigation Support

  • Provide expert SIEM and UEBA platform support to security incident investigations, developing targeted queries, timeline reconstructions, and behavioral analysis outputs that help analysts and incident responders rapidly characterize the scope, nature, and impact of security incidents.
  • Support the development and maintenance of investigation playbooks and query libraries that guide analysts through structured, repeatable investigation workflows for common incident types.
  • Develop and maintain SIEM dashboards and investigation views optimized for analyst use, ensuring analysts have rapid access to the data, visualizations, and contextual information needed to efficiently triage and investigate security alerts.
  • Contribute to post-incident review activities, providing SIEM and UEBA platform perspective on detection effectiveness, investigation data availability, and opportunities to improve detection and response capabilities based on incident findings.

Reporting, Metrics & Documentation

  • Develop and maintain SIEM and UEBA performance metrics, including log ingestion volume and reliability, detection rule coverage, alert volume and fidelity, false positive rates, mean time to detect (MTTD), and analyst workload metrics.
  • Prepare and present SIEM and UEBA performance reports and briefings for program leadership and Government stakeholders, communicating platform health, detection coverage, and improvement initiative status clearly and accurately.
  • Develop and maintain comprehensive SIEM and UEBA engineering documentation, including platform architecture diagrams, log source inventories, detection content libraries, tuning records, and standard operating procedures.
  • Support the development and maintenance of the program's security metrics dashboard, ensuring SIEM and UEBA performance data is accurately reflected in program reporting deliverables.

Compliance & ATO Support

  • Ensure the SIEM and UEBA platforms are configured and maintained in compliance with applicable Federal cybersecurity frameworks and requirements, including NIST SP 800-53, FISMA, FedRAMP, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, applicable DISA STIGs, and client-specific cybersecurity policies.
  • Support ATO activities for the SIEM and UEBA platforms, including security control implementation documentation, system security plan (SSP) contribution, continuous monitoring reporting, and audit evidence collection.
  • Support continuous monitoring activities, ensuring SIEM and UEBA platform configurations are regularly assessed for compliance and that any identified deviations are promptly remediated and documented.

 

Education and Experience:

Required:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant experience may be considered.
  • Minimum of 3–5 years of hands-on experience in SIEM engineering, security operations, or a closely related cybersecurity discipline within a federal government IT contracting or enterprise security environment.
  • Demonstrated hands-on experience administering and engineering enterprise SIEM platforms, including log source onboarding, parser development, detection rule creation, alert tuning, and platform administration.
  • Experience developing detection content aligned with the MITRE ATT&CK framework, including correlation rules, behavioral analytics, and threshold-based alerting.
  • Experience with log ingestion architecture design, including the onboarding and normalization of diverse log source types across endpoint, network, application, cloud, and identity platforms.
  • Active security clearance or the ability to obtain and maintain a government background investigation and all requisite IT access authorizations. Specific clearance requirements will be confirmed at time of offer.

Preferred:

  • Prior experience serving as a SIEM or security analytics engineer on a federal IT program of comparable scale and complexity.
  • Hands-on experience with UEBA platform administration and behavioral analytics model development.
  • Experience integrating threat intelligence feeds and automated enrichment capabilities into enterprise SIEM platforms.

 

Required Skills and Competencies:

  • Deep technical proficiency with one or more enterprise SIEM platforms, with demonstrated hands-on experience in platform administration, log source onboarding, detection rule development, alert tuning, and investigation support using Splunk, Microsoft Sentinel, IBM QRadar, Elastic SIEM, or equivalent platforms.
  • Strong detection engineering skills with demonstrated ability to develop high-fidelity, low-noise detection content aligned with the MITRE ATT&CK framework across a broad range of adversary TTPs and threat scenarios.
  • Strong log source management and data normalization skills, including experience developing custom parsers, field extraction configurations, and data normalization mappings for diverse log source types.
  • Proficiency with SIEM query languages, including SPL (Splunk), KQL (Microsoft Sentinel/Elastic), or equivalent, with demonstrated ability to develop complex, optimized queries for detection, investigation, and analytics use cases.
  • Demonstrated experience with UEBA platform administration and behavioral analytics, including data source integration, behavioral model configuration, risk scoring tuning, and anomaly detection development.
  • Knowledge of Federal cybersecurity frameworks and compliance requirements, including NIST SP 800-53, FISMA, FedRAMP, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, and applicable DISA STIGs and CIS Benchmarks.
  • Strong understanding of the MITRE ATT&CK framework and its practical application to detection engineering, threat hunting, detection coverage assessment, and security analytics development.
  • Experience with threat intelligence integration, including IOC matching, automated enrichment, and threat intelligence-driven detection content development.
  • Proficiency with at least one scripting or programming language, including Python, PowerShell, Bash, or equivalent, for detection automation, log parsing, data enrichment, and operational scripting.
  • Strong analytical and problem-solving skills with demonstrated ability to analyze complex, high-volume security event data, identify meaningful patterns and anomalies, and develop actionable security insights.
  • Excellent written and verbal communication skills with demonstrated ability to document complex SIEM architectures, detection content, and platform configurations clearly and accurately, and to present security analytics findings to both technical and non-technical audiences.
  • Experience supporting security incident investigations, including the development of targeted SIEM queries, timeline reconstructions, and investigation playbooks.

 

Desired Skills and Competencies:

  • Splunk Certified Power User, Splunk Core Certified Advanced Power User, Splunk Enterprise Security Certified Admin, or equivalent Splunk certification.
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) or equivalent Microsoft Sentinel certification.
  • GIAC Continuous Monitoring Certification (GMON), GIAC Certified Enterprise Defender (GCED), GIAC Certified Incident Handler (GCIH), or equivalent GIAC cybersecurity certification.
  • Certified Information Systems Security Professional (CISSP), CompTIA Security+, CompTIA CySA+, or equivalent cybersecurity certification.
  • Experience with Security Orchestration, Automation, and Response (SOAR) platform integration with SIEM platforms, including automated playbook development and alert response workflow implementation.
  • Experience with cloud-native security monitoring capabilities, including AWS Security Hub, AWS CloudTrail, Microsoft Defender for Cloud, Microsoft Entra ID Sign-In Logs, and equivalent cloud platform log sources and detection services.
  • Familiarity with deception technology integration with SIEM platforms, including honeypot and honeytoken alert ingestion and detection content development.
  • Experience with threat hunting program development and execution, including hypothesis development, hunting query library maintenance, and hunting findings documentation and operationalization.
  • Knowledge of data science and machine learning concepts as applied to security analytics, anomaly detection, and behavioral modeling within UEBA and advanced SIEM analytics platforms.
  • Experience with network traffic analysis and network detection and response (NDR) platform integration with enterprise SIEM solutions.
  • Familiarity with privacy engineering principles and the handling of personally identifiable information (PII) within SIEM and UEBA platforms in accordance with Federal privacy requirements.
  • Experience supporting FedRAMP continuous monitoring reporting and ATO documentation activities for SIEM and security monitoring platforms.
  • Familiarity with MITRE D3FEND framework and its application to defensive countermeasure selection and security control mapping activities.
  • Experience with data pipeline technologies such as Apache Kafka, Logstash, Fluentd, or equivalent platforms for high-volume log ingestion and data stream management in enterprise SIEM environments.
  • Familiarity with Section 508 compliance requirements for security dashboards, analytics tools, and reporting products delivered under federal contracts.

 

Our Equal Employment Opportunity Policy:

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

 

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

 

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.

 

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.