About this role
Description
Role Summary
The SIEM Integrator owns the end-to-end integration of log sources, security tools, and data pipelines into the organization's SIEM platform. This role is responsible for onboarding new data sources, building and tuning correlation rules and use cases, and ensuring the SIEM ecosystem is reliable, scalable, and aligned with detection and compliance requirements. The role bridges security operations, IT infrastructure, and engineering, and is responsible for the technical roadmap of the SIEM environment.
Key Responsibilities
• Lead the design, deployment, and lifecycle management of SIEM integrations across on-prem, cloud, and hybrid environments.
• Define and prioritize the SIEM onboarding roadmap in collaboration with SOC leadership, IT, and application owners.
• Build, tune, and maintain correlation rules, parsers, use cases, and dashboards to improve detection coverage and reduce false positives.
• Ensure log source health, data quality, and pipeline reliability through monitoring, alerting, and periodic audits.
• Partner with detection engineering and SOC analysts to translate threat scenarios into actionable SIEM content.
• Own SIEM platform architecture decisions, including sizing, retention, licensing, and integration with SOAR and other security tools.
• Document integration standards, onboarding procedures, and use-case libraries; drive knowledge sharing across the team.
• Act as the primary escalation point for SIEM-related technical issues and outages.
Requirements
Requirements
• 5+ years of hands-on experience with SIEM platforms (e.g., Splunk, QRadar, Microsoft Sentinel, Elastic, or similar).
• Proven experience integrating diverse log sources (network, endpoint, cloud, identity, application) into SIEM
• Strong understanding of log formats, parsing, normalization, and correlation rule development.
• Solid knowledge of networking, operating systems, and common enterprise security tools.
• Familiarity with scripting/automation (Python, PowerShell, or similar) for integration and data enrichment tasks.
• Understanding of the MITRE ATT&CK framework and how it maps to detection use cases.
• Strong communication skills and ability to work cross-functionally with SOC, IT, and engineering teams.
Nice to Have
• Experience with SOAR platforms and security automation/orchestration.
• Relevant certifications (e.g., Splunk Certified, Microsoft SC-200, GIAC/GCIA/GCDA).
• Experience in regulated environments requiring compliance-driven logging (SOX, PCI-DSS, ISO 27001).