

SOC SIEM/Cloud Engineer
β - Featured Role | Apply direct with Data Freelance Hub
This role is for a SOC SIEM/Cloud Engineer, remotely based in TN, with a contract length of more than 6 months and a pay rate of $80,001 - $120,000. Requires 3-5+ years in SIEM engineering, Microsoft Sentinel, AWS, and Splunk expertise.
π - Country
United States
π± - Currency
$ USD
-
π° - Day rate
545.4545454545
-
ποΈ - Date discovered
August 7, 2025
π - Project duration
More than 6 months
-
ποΈ - Location type
Remote
-
π - Contract type
Unknown
-
π - Security clearance
Yes
-
π - Location detailed
United States
-
π§ - Skills detailed
#KQL (Kusto Query Language) #Cybersecurity #Lambda (AWS Lambda) #AWS Lambda #EC2 #Splunk #Cloud #JSON (JavaScript Object Notation) #Compliance #Monitoring #Python #AWS (Amazon Web Services) #Azure Logic Apps #Security #Bash #AI (Artificial Intelligence) #Azure #Logic Apps #Kubernetes #Logging #Scala #Scripting #Computer Science #Automation
Role description
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Job ID: 2508288
Location: REMOTE WORK, TN, US
Date Posted: 2025-08-05
Category: Cyber
Subcategory: Cybersecurity Spec
Schedule: Full-time
Shift: Day Job
Travel: No
Minimum Clearance Required: None
Clearance Level Must Be Able to Obtain: Secret
Potential for Remote Work: Yes
Description
We provide advanced cybersecurity monitoring and engineering support to a wide range of government agencies through a multi-tenant MSS model. Our Security Operations Center (SOC) operates 24/7, leveraging Microsoft Sentinel as the core SIEM platform. However, we increasingly support hybrid and multi-cloud environments including AWS and Splunk, and we are seeking a cloud-savvy SIEM engineer to help us grow and maintain secure, scalable monitoring capabilities.
As a SOC SIEM/Cloud Engineer, you will serve as one of the primary engineers for multi-cloud SIEM operations in a managed security services environment. While Microsoft Sentinel remains our core SIEM platform, you will also support AWS-native security tooling and Splunk-based environments. This role emphasizes cross-cloud log ingestion, automation, and security detection engineering. Candidates must be self-directed, security-minded, and comfortable designing scalable monitoring strategies across diverse architectures.
This is a remote position, but Secret clearance eligibility is required to support future classified operations, as needed.
KEY RESPONSIBILITIES:
SIEM Operations & Cloud Integration
β’ Administer and optimize SIEM platforms including Microsoft Sentinel, Splunk, and AWS-native tools such as CloudWatch, CloudTrail, GuardDuty, and Security Hub.
β’ Manage log ingestion pipelines from hybrid, cloud, and containerized environments.
β’ Design alert rules, detection use cases, and enrichment pipelines using KQL, SPL, and JSON-based event structures.
Security Automation
β’ Build and maintain automation workflows using Azure Logic Apps, Splunk SOAR, and AWS Lambda/Step Functions.
β’ Integrate threat intelligence, reputation feeds, and context enrichment across cloud platforms.
β’ Partner with SOC analysts to streamline Tier 1-2 response efforts through smart automation.
Multi-Cloud Design & Support
β’ Act as the subject matter expert on cloud security logging and architecture for Azure, AWS, and hybrid environments.
β’ Advise customers and internal teams on best practices for telemetry, logging policy, and compliance alignment (e.g., FedRAMP, CJIS, NIST 800-53).
β’ Lead or support onboarding of cloud workloads including EC2, EKS, Lambda, Azure VMs, Kubernetes, and M365C environments.
Qualifications
Required Qualifications
β’ Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field
β’ 3-5+ years of SIEM engineering experience across multi-cloud environments (Azure, AWS)
β’ Hands-on experience with Microsoft Sentinel, AWS Security Services, and Splunk
β’ Experience creating alerts and detection rules in KQL, SPL, and JSON-based formats
β’ Familiarity with automation tools such as Logic Apps, Splunk SOAR, AWS Lambda, or Step Functions
β’ Strong scripting knowledge (PowerShell, Python, or Bash)
Preferred Qualifications
β’ Active Secret clearance or higher
β’ Microsoft Certifications: SC-200, AZ-500
β’ AWS Certifications: Security Specialty, Solutions Architect Associate or Pro
β’ Splunk Certifications: Admin, Power User
β’ Experience with cloud container security (EKS, AKS, Kubernetes auditing)
β’ Experience in multi-tenant MSSP environments or government contracts
β’ Familiarity with large language models (LLMs), GenAI, or agentic AI frameworks for use in cybersecurity operations
What We Offer
β’ Fully remote work with flexibility and work-life balance
β’ Opportunity to contribute to classified operations with additional clearance
β’ Competitive compensation and benefits
β’ Training and certification assistance
β’ Stable, mission-driven cybersecurity work supporting state and federal government agencies
Target salary range: $80,001 - $120,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.
SAIC is a premier technology integrator providing full life cycle services and solutions in the technical, engineering, intelligence, and enterprise information technology markets. SAIC is Redefining Ingenuity through its deep customer and domain knowledge to enable the delivery of systems engineering and integration offerings for large, complex projects. SAIC's approximately 15,000 employees are driven by integrity and mission focus to serve customers in the U.S. federal government. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $4.5 billion. For more information, visit saic.com. For information on the benefits SAIC offers, see .