
Senior SIEM Engineer
Rockwell Automation
full-time
Posted on:
Location Type: Hybrid
Location: Milwaukee • Ohio • Texas • United States
Visit company websiteExplore more
Job Level
About the role
- Administer, enhance, and maintain the SIEM platform, including agent/app/add‑on upgrades and log source onboarding.
- Build and optimize correlation rules, detection use cases, dashboards, and reporting content.
- Integrate threat intelligence feeds to strengthen detection capabilities.
- Analyze logs and security events to identify anomalies or advanced attack patterns.
- Partner with SOC/IR teams on investigations, tuning, enrichment, and automation workflows.
- Create and maintain runbooks, documentation, and SIEM best practices.
- Lead SIEM improvements, scaling efforts, and cross‑functional enablement.
Requirements
- Bachelor's Degree or Equivalent Years of Relevant Work Experience
- Legal authorization to work in the U.S. We will not sponsor individuals for employment visas, now or in the future, for this job opening.
- 5+ years of experience with SIEM platforms (e.g., Sentinel, Splunk, QRadar, LogRhythm).
- Strong knowledge of detection engineering, log parsing, and data normalization.
- Proficiency with KQL, SQL, or similar query languages.
- Understanding of incident response, SOC workflows, and security operations.
- Experience with SOAR, automation workflows, or Logic Apps.
- Cloud security experience (Azure, AWS, GCP).
- Scripting (Python, PowerShell).
- Familiarity with MITRE ATT&CK, NIST, or ISO frameworks.
- Relevant certifications: AZ-500, AZ-104, AZ-900, AZ-303/304, DP-900, AI-900, Splunk certifications, etc.
Benefits
- Health Insurance including Medical, Dental and Vision
- 401k
- Paid Time off
- Parental and Caregiver Leave
- Flexible Work Schedule where you will work with your manager to enjoy a work schedule that can be flexible with your personal life.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
SIEM platformsdetection engineeringlog parsingdata normalizationKQLSQLSOARscriptingcloud securityautomation workflows
Soft Skills
leadershipcollaborationdocumentationproblem-solvingcommunication
Certifications
AZ-500AZ-104AZ-900AZ-303AZ-304DP-900AI-900Splunk certifications