Skip to content

Open nowPosted 34 days ago

Jr SIEM/UEBA Engineer

kgs404 open roles

Where
Washington, DC, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowJr SIEM/UEBA Engineerkgs · Washington, DC, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on kgs's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 34 days ago

The posting

This position may be filled prior to the posted deadline.  Interested candidates are encouraged to apply as soon as possible.   Koniag Operations Services, LLC (KOS), a Koniag Government Services company, is seeking a motivated and technically developing Junior SIEM/UEBA Engineer to support cybersecurity operations for a federal government client. This position requires the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.   Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits and tuition reimbursement.    This role serves as an important technical contributor responsible for supporting the administration, configuration, and optimization of Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA) platforms across a complex federal enterprise IT environment in support of continuous monitoring, threat detection, and incident response activities.   The ideal candidate is an early-career cybersecurity professional with foundational knowledge of SIEM and UEBA technologies, log management, security event analysis, and enterprise cybersecurity operations who is eager to grow their technical skills and contribute meaningfully to a high-performing federal cybersecurity team. This individual must demonstrate strong analytical curiosity, attention to detail, a commitment to continuous learning, and the professional maturity required to operate within a highly regulated federal IT environment.   The Junior SIEM/UEBA Engineer will serve as a developing technical contributor within the program's cybersecurity operations team, supporting the administration, tuning, and optimization of enterprise SIEM and UEBA platforms under the guidance of senior engineers and cybersecurity leadership. This individual assists with log source onboarding, detection rule development and tuning, alert triage and analysis, platform health monitoring, and the development of dashboards and reports that support continuous monitoring, threat detection, and compliance reporting activities across the federal enterprise IT environment.   Principal responsibilities will include but are not limited to: SIEM Platform Support & Administration Assist with the day-to-day administration, configuration, and maintenance of the enterprise SIEM platform, including user management, data source configurations, retention policy management, and platform health monitoring.Support the onboarding of new log sources into the SIEM platform, assisting with log collection configuration, parsing rule development, field normalization, and data validation to ensure accurate and complete ingestion of security-relevant event data.Assist with the development, testing, tuning, and documentation of SIEM detection rules, correlation rules, and alert logic to improve detection fidelity, reduce false positive rates, and ensure coverage of relevant threat scenarios and compliance requirements.Monitor SIEM platform health, performance, and data ingestion status, identifying and escalating anomalies, collection failures, and performance degradation to senior engineers for investigation and resolution.Assist with the development and maintenance of SIEM dashboards, saved searches, and reports that support security operations, continuous monitoring, SLA tracking, and compliance reporting requirements.Support the periodic review and tuning of existing SIEM detection content, identifying opportunities to improve detection accuracy, reduce alert fatigue, and align detection coverage with current threat intelligence and operational requirements.Assist with SIEM platform upgrades, patch applications, and configuration changes under the supervision of senior engineers, ensuring changes are tested, documented, and implemented in accordance with change management procedures. UEBA Platform Support & Administration Assist with the administration and configuration of the enterprise UEBA platform, supporting the establishment and maintenance of behavioral baselines, risk scoring models, and anomaly detection capabilities across user and entity populations.Support the onboarding of data sources into the UEBA platform, assisting with integration configuration, data mapping, and validation activities to ensure the platform has complete and accurate visibility into relevant user and entity activity.Assist with the review, tuning, and documentation of UEBA behavioral models, risk scoring rules, and anomaly detection thresholds to reduce false positives and improve the quality and actionability of UEBA-generated alerts and risk scores.Monitor UEBA platform health, data ingestion status, and behavioral model performance, identifying and escalating anomalies and performance issues to senior engineers for investigation and resolution.Support the development and maintenance of UEBA dashboards and reports that provide visibility into user and entity risk posture, behavioral anomalies, and insider threat indicators for security operations and program leadership.Assist with periodic reviews of UEBA risk scoring outputs, collaborating with senior engineers and security analysts to identify false positive patterns, emerging risk trends, and tuning opportunities. Log Management & Data Ingestion Assist with the management and maintenance of the enterprise log management infrastructure, supporting log collection, forwarding, parsing, normalization, indexing, and retention activities across diverse log source types and environments.Support the development and maintenance of log parsing rules, field extraction configurations, and data normalization mappings for new and existing log sources, ensuring consistent and accurate data representation within the SIEM platform.Assist with log source health monitoring, identifying collection gaps, parsing errors, and data quality issues, and escalating findings to senior engineers with supporting documentation.Support the development and maintenance of log source inventory documentation, ensuring accurate records of all onboarded log sources, collection methods, data volumes, and retention configurations.Assist with the onboarding of cloud platform log sources, including Microsoft 365 audit logs, Azure Monitor logs, AWS CloudTrail, and other cloud-native security log sources, under the guidance of senior engineers. Alert Triage & Security Event Analysis Perform initial triage and analysis of SIEM and UEBA-generated alerts, reviewing event data, log sources, and contextual information to assess alert validity, severity, and recommended disposition.Document alert triage findings accurately and completely in the ITSM or case management platform, ensuring all relevant event data, analysis steps, and disposition rationale are captured for audit and investigation purposes.Escalate confirmed or suspected security incidents, high-priority alerts, and complex analytical findings to senior engineers and incident response personnel in a timely and well-documented manner.Assist with security event correlation and timeline reconstruction activities, aggregating and analyzing event data across multiple log sources to support incident investigation and root cause analysis efforts.Support the development and maintenance of alert triage procedures, runbooks, and analysis playbooks, contributing documentation based on recurring alert scenarios and lessons learned from completed triage activities. Threat Intelligence Integration Assist with the integration and operationalization of threat intelligence feeds within the SIEM platform, supporting the configuration of indicator of compromise (IOC) matching rules, threat intelligence enrichment workflows, and automated alert enrichment capabilities.Support the development and maintenance of threat intelligence-driven detection rules and watchlists within the SIEM platform, ensuring detection coverage is aligned with current and emerging threat actor tactics, techniques, and procedures (TTPs).Contribute to the program's threat intelligence repository by documenting indicators of compromise, attacker TTPs, and detection insights identified through alert triage and security event analysis activities.Develop familiarity with the MITRE ATT&CK framework and its application to detection rule development, alert triage, and threat hunting activities under the guidance of senior engineers. Reporting & Documentation Assist with the development and maintenance of SIEM and UEBA operational reports, metrics dashboards, and compliance reporting outputs that support program leadership, Government stakeholders, and continuous monitoring requirements.Develop and maintain technical documentation for SIEM and UEBA platform configurations, detection rules, log source integrations, tuning activities, and operational procedures, ensuring documentation is accurate, current, and accessible.Contribute to the preparation of recurring security operations reports and briefings, compiling and organizing security event data, detection metrics, platform health information, and notable findings for inclusion in program reporting deliverables.Support the development of after-action documentation for significant security events, SIEM/UEBA tuning activities, and platform changes, capturing lessons learned and improvement recommendations. Compliance & Continuous Monitoring Support Support the program's continuous monitoring activities, assisting with the collection, analysis, and reporting of security-relevant event data in support of FISMA, NIST SP 800-53, and client-specific continuous monitoring requirements.Assist with the development and maintenance of SIEM-based compliance reporting content, including dashboards, saved searches, and automated reports that support audit readiness and regulatory compliance activities.Ensure all SIEM and UEBA platform activities are conducted in compliance with applicable Federal security frameworks, including FISMA, NIST SP 800-53, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, and client-specific cybersecurity policies.Support vulnerability management and security compliance activities by assisting with the development and maintenance of SIEM-based vulnerability tracking dashboards and compliance posture reporting.   Education and Experience: Required: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant technical experience or military service may be considered.Minimum of 1–3 years of experience in cybersecurity operations, SIEM administration, log management, or a closely related technical discipline.Foundational hands-on experience with at least one enterprise SIEM platform, such as Splunk, Microsoft Sentinel, IBM QRadar, Elastic SIEM, or equivalent.Basic understanding of log management concepts, including log collection, parsing, normalization, and retention, across Windows, Linux, and network device log source types.Ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Preferred: Prior experience supporting cybersecurity operations in a federal government IT contracting environment.Hands-on experience or academic/lab exposure to UEBA platforms such as Splunk UBA, Microsoft Sentinel UEBA, Securonix, or equivalent.Experience or coursework related to cloud platform log sources, including Microsoft 365, Azure, or AWS.   Required Skills and Competencies: Foundational knowledge of SIEM platform concepts, including log ingestion, parsing, normalization, correlation rule development, alert management, and dashboard development, with demonstrated hands-on experience or equivalent academic/lab exposure.Basic understanding of UEBA concepts, including behavioral baseline establishment, anomaly detection, risk scoring, and insider threat detection use cases.Foundational understanding of enterprise security log sources and the security-relevant events generated by Windows endpoints, Linux systems, network devices, firewalls, web proxies, Active Directory/Azure AD, and cloud platforms.Basic proficiency with SIEM query languages, such as Splunk SPL, Microsoft KQL, or equivalent, for security event analysis, alert triage, and report development.Foundational knowledge of cybersecurity concepts, including the cyber kill chain, common attack techniques, indicators of compromise, and network and endpoint security fundamentals.Strong analytical and critical thinking skills with demonstrated ability to perform methodical, detail-oriented analysis of security event data and document findings accurately and completely.Eagerness to learn and develop technical skills in SIEM and UEBA engineering, with demonstrated commitment to continuous professional development and knowledge growth.Strong written and verbal communication skills with the ability to document technical findings, triage activities, and platform configurations clearly and accurately.Basic familiarity with Federal cybersecurity frameworks and compliance requirements, including NIST SP 800-53, FISMA, and continuous monitoring concepts.Ability to work effectively as part of a collaborative team under the direction of senior engineers and cybersecurity leadership, taking direction, accepting feedback, and contributing positively to team operations.Strong organizational skills with the ability to manage multiple concurrent tasks, triage activities, and documentation responsibilities with accuracy and attention to detail.Proficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams and SharePoint.   Desired Skills and Competencies: CompTIA Security+, CompTIA CySA+, or equivalent entry-level cybersecurity certification demonstrating foundational security knowledge and professional development commitment.Splunk Core Certified User, Splunk Core Certified Power User, Microsoft SC-200 (Security Operations Analyst), or equivalent SIEM platform certification or training credential.GIAC Security Essentials (GSEC), GIAC Certified Intrusion Analyst (GCIA), or equivalent entry-level GIAC certification.Familiarity with the MITRE ATT&CK framework and its application to threat detection, alert triage, and security event analysis.Basic experience with scripting or query languages, including Python, PowerShell, Bash, or equivalent, for log analysis automation and security operations support tasks.Familiarity with cloud security concepts and cloud-native log sources across Microsoft 365, Azure, or AWS environments.Basic familiarity with network security concepts, including TCP/IP fundamentals, common network protocols, firewall log analysis, and network traffic analysis.Familiarity with Zero Trust Architecture principles (NIST SP 800-207, OMB M-22-09) and their application to continuous monitoring and security operations within a federal enterprise IT environment.Familiarity with incident response processes and ITIL-based IT service management concepts as they relate to security event triage, escalation, and case management activities.Experience with threat intelligence concepts, including indicator of compromise types, threat actor TTPs, and the practical application of threat intelligence to SIEM detection and alert enrichment.Familiarity with log management and SIEM data pipeline concepts, including syslog, Windows Event Forwarding, Beats/agents, API-based collection, and cloud-native log forwarding mechanisms.Prior internship, academic project, Capture the Flag (CTF) competition experience, or home lab work demonstrating hands-on engagement with SIEM, log analysis, or cybersecurity operations tools and concepts.   Our Equal Employment Opportunity Policy: The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.   The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at [email protected] or by calling 703-488-9377 to request accommodations.   Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.   Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against kgs's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on kgs's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    kgs's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.