Talent.com
Security Infrastructure Support SIEM & Data Pipeline Technical Lead / Subject-Matter Expert (SME)
Security Infrastructure Support SIEM & Data Pipeline Technical Lead / Subject-Matter Expert (SME)Cybervance • Bethesda, MD, United States
Security Infrastructure Support SIEM & Data Pipeline Technical Lead / Subject-Matter Expert (SME)

Security Infrastructure Support SIEM & Data Pipeline Technical Lead / Subject-Matter Expert (SME)

Cybervance • Bethesda, MD, United States
job_description.job_card.variable_hours_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Position Title : Security Infrastructure Support SIEM & Data Pipeline Technical Lead / Subject-Matter Expert (SME)

Location : Bethesda, MD | Hybrid- Not Remote

Cybervance is a rapidly growing information security and information technology company based in Washington, D.C., and we are an equal opportunity employer. We design, develop, and manage the successful execution of training programs for government and private sector organizations. Cybervance believes in creating innovative solutions to deliver measured results.

We are seeking an experienced SIEM & Data Pipeline Technical Lead / Subject-Matter Expert (SME) to provide enterprise-level leadership and hands-on expertise in the design, development, and optimization of security information and event management (SIEM) systems and data pipeline integrations. The successful candidate will oversee the ingestion, normalization, and enrichment of log data across hybrid cloud and on-premises environments to enhance threat detection, incident response, and compliance reporting.

This role requires a deep technical understanding of SIEM platforms, data architecture, and DevSecOps practices. The ideal candidate will possess strong leadership skills, technical acumen, and the ability to communicate complex data and security concepts effectively to both technical and executive stakeholders.

Responsibilities

  • Lead the design, implementation, and administration of enterprise SIEM solutions to support cybersecurity operations, compliance, and threat intelligence objectives.
  • Architect and manage data ingestion pipelines, including log routing, filtering, and transformation for on-premises and cloud environments.
  • Develop and maintain data normalization, enrichment, and correlation rules to ensure accurate and actionable security event data.
  • Implement and manage data collection tools and agents to gather logs from diverse sources, including cloud, infrastructure, endpoint, and application systems.
  • Integrate data from hybrid infrastructure environments (on-premises and cloud) using services such as AWS CloudTrail, GuardDuty, Azure Sentinel, and O365 Security & Compliance Center.
  • Apply DevOps and CI / CD tools to create reliable, repeatable, and automated data pipeline processes supporting continuous monitoring and detection.
  • Develop and maintain automation scripts and utilities in JavaScript and Python for pipeline management, log parsing, and system integration.
  • Write and optimize complex queries in Splunk Processing Language (SPL) or SQL for analytics, dashboards, and operational reporting.
  • Ensure compliance with federal cybersecurity frameworks such as FISMA, NIST SP 800-53, NIST SP 800-92, OMB M-21-31, and CDM.
  • Collaborate with cybersecurity operations, infrastructure, and DevOps teams to ensure comprehensive coverage and efficient performance of data collection and SIEM operations.
  • Develop and maintain data dictionaries, documentation, and standard operating procedures (SOPs) for SIEM and data pipeline management.
  • Provide technical leadership and mentorship, ensuring consistency in implementation, monitoring, and troubleshooting across teams.
  • Communicate complex technical information and security concepts to both technical staff and executive stakeholders in clear, actionable terms.
  • Apply data governance principles to ensure data accuracy, completeness, and protection throughout the security pipeline.
  • Leverage the MITRE ATT&CK framework to align event data correlation with real-world adversarial behaviors and threat models.
  • Collaborate with third-party vendors and cross-functional teams to support integrations, resolve technical challenges, and ensure enterprise interoperability.

Experience

  • 10+ years of experience designing, installing, maintaining, and supporting enterprise IT systems.
  • 5+ years of experience at the Senior Engineer level or higher.
  • 3+ years of specific experience implementing and administering SIEM platforms or related cybersecurity tools.
  • Proven experience supporting hybrid infrastructures (on-premises and cloud) including AWS, Azure, and Microsoft 365.
  • In-depth experience with SIEM platforms (e.g., Splunk, QRadar, Sentinel) and data collection tools (e.g., Cribl, Logstash, Fluentd).
  • Proficiency with log routing, filtering, and transformation tools.
  • Strong understanding of log formats (CEF, LEEF, JSON, XML) and data normalization, enrichment, and correlation techniques.
  • Hands-on experience implementing CI / CD pipelines and DevOps automation to support data ingestion and SIEM configuration management.
  • Strong scripting skills in JavaScript and Python for pipeline automation, API integration, and data parsing.
  • Proficiency in query languages such as SPL (Splunk) and SQL for building analytics, dashboards, and reports.
  • Experience with data governance, data lifecycle management, and event taxonomy design.
  • Familiarity with the MITRE ATT&CK framework and its application to SIEM rule development and event correlation.
  • Experience with federal compliance frameworks including FISMA, NIST 800-53, NIST 800-92, OMB M-21-31, and CDM.
  • Strong analytical and troubleshooting abilities to identify and resolve SIEM data flow, parsing, and correlation issues.
  • Proven ability to diagnose complex data pipeline failures and optimize performance across systems.
  • Excellent verbal and written communication skills, capable of translating complex data architecture and cybersecurity concepts to both technical and executive audiences.
  • Demonstrated ability to lead multidisciplinary teams, coordinate with vendors, and manage large-scale SIEM deployments.
  • Strong documentation skills, with experience producing SOPs, risk assessments, and technical reports.
  • Required Skills & Qualifications

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field (preferred).
  • Required Clearances

  • Current government security clearance : Public Trust.
  • Preferred Qualifications

  • Certifications such as CISSP, CISM, Splunk Enterprise Certified Architect, AWS Certified Security Specialty, or Microsoft Certified : Azure Security Engineer Associate.
  • Experience with data streaming technologies (Kafka, Kinesis, or similar) and data lake integrations.
  • Knowledge of Zero Trust Architecture and continuous monitoring methodologies.
  • Familiarity with automation frameworks (Ansible, Terraform, or CloudFormation) for infrastructure-as-code deployments.
  • #J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Data Infrastructure • Bethesda, MD, United States

    Job_description.internal_linking.related_jobs
    Director, Infrastructure and Network Engineering (A01097)

    Director, Infrastructure and Network Engineering (A01097)

    InsideHigherEd • Germantown, Maryland, United States
    serp_jobs.job_card.full_time
    Montgomery College, Central Services Campus, has an immediate need for a FT Director, Infrastructure and Network Engineering in the Office of Information Technology. The work schedule is 5 days / 40 h...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Senior Manager, Information Security Office (ISO) Consultant

    Senior Manager, Information Security Office (ISO) Consultant

    Capital One • Baltimore, MD, US
    serp_jobs.job_card.full_time +1
    Senior Manager, Information Security Office (ISO) Consultant.At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security.You are pragmat...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Information Security Specialist II

    Information Security Specialist II

    Oceaneering International, Inc. • Hanover, MD, United States
    serp_jobs.job_card.full_time
    Oceaneering Technologies (OTECH) develops, manufactures, and operates customized marine systems, shipboard equipment, subsea vehicles, and engineered solutions for commercial and U.Oceaneering Aero...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Deputy Director, NBFAC (#1877)

    Deputy Director, NBFAC (#1877)

    BNBI • Fort Detrick, MD, United States
    serp_jobs.job_card.temporary
    The National Biodefense Analysis and Countermeasures Center (NBACC) is a one-of-a-kind facility located on Fort Detrick in Frederick MD and is dedicated to defending the nation against biological t...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Security Infrastructure Support SIEM & Data Pipeline Tech Lead - NIH

    Security Infrastructure Support SIEM & Data Pipeline Tech Lead - NIH

    cFocus Software Incorporated • Rockville, MD, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Security Infrastructure Support SIEM & Data Pipeline Technical Lead / Subject-Matter Expert (SME) Overview cFocus Software is seeking a Security Infrastructure Support SIEM & Data Pipeline ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days
    Network Security Engineer

    Network Security Engineer

    Shimadzu Scientific Instruments • Columbia, MD, United States
    serp_jobs.job_card.full_time
    Established in 1975, Shimadzu Scientific Instruments is one of the largest suppliers of analytical instrumentation, physical testing, and environmental monitoring systems in the world.Ground-breaki...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Information System Security Manager (ISSM)

    Information System Security Manager (ISSM)

    The Johns Hopkins University Applied Physics Laboratory • Laurel, MD, United States
    serp_jobs.job_card.full_time
    Do you love solving problems while enabling impactful research to operate securely?.Are you passionate about making meaningful contributions to national security cyber missions?.Do you like collabo...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior ISSO Security Manager

    Senior ISSO Security Manager

    Leidos Inc • Baltimore, MD, United States
    serp_jobs.job_card.full_time
    At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, an...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Manager, Network Security, Tech & Data Risk Management

    Manager, Network Security, Tech & Data Risk Management

    Capital One • BALTIMORE, Maryland, United States
    serp_jobs.job_card.full_time +1
    Manager, Network Security, Tech & Data Risk Management.Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers.We are serious about tech...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Equipment Certification Specialist I (#1874)

    Equipment Certification Specialist I (#1874)

    BNBI • Fort Detrick, MD, United States
    serp_jobs.job_card.temporary
    The National Biodefense Analysis and Countermeasures Center (NBACC) is a one-of-a-kind facility located on Fort Detrick in Frederick MD and is dedicated to defending the nation against biological t...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    LEAD INFORMATION SECURITY ENGINEER

    LEAD INFORMATION SECURITY ENGINEER

    Lumen Technologies • Herndon, VA, United States
    serp_jobs.job_card.full_time
    We are igniting business growth by connecting people, data and applications - quickly, securely, and effortlessly.Together, we are building a culture and company from the people up - committed to t...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    Legal & General America • Frederick, MD, United States
    serp_jobs.job_card.full_time
    At Legal & General America, we aim to make a positive difference in the lives of our customers, partners, colleagues, and the communities in which they live. As a recognized market leader of term li...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Director, Infrastructure

    Director, Infrastructure

    Legal & General America • Frederick, MD, United States
    serp_jobs.job_card.permanent
    At Legal & General America, we aim to make a positive difference in the lives of our customers, partners, colleagues, and the communities in which they live. As a recognized market leader of term li...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Insider Threat Program Systems SME

    Insider Threat Program Systems SME

    Leidos Inc • Washington, DC, United States
    serp_jobs.job_card.full_time
    The Digital Modernization Sector at Leidos currently has an opening for a Systems Management SME supporting the HEITS Contract as part of an Insider Threat Program (ITP). This is an exciting opportu...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    SIEM & Data Pipeline Technical Lead / SME

    SIEM & Data Pipeline Technical Lead / SME

    Gunnison Consulting Group, Inc. • Bethesda, MD, US
    serp_jobs.job_card.full_time
    This position is contingent upon a future opening with Gunnison.Salary : $155,000 - $185,000 / year.Hybrid, primarily remote with ad hoc on-site work, frequency TBD. This position serves as a Gunnison ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Sr. Information Security Consultant (Hiring Immediately)

    Sr. Information Security Consultant (Hiring Immediately)

    Guidehouse • RESTON, VA, US
    serp_jobs.job_card.part_time
    Active Top Secret SCI with Polygraph.Guidehouse has an opportunity for a cleared Sr.Information Security Consultant to leverage their understanding of IC / DOD Risk Management Frameworks (RMF), conti...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Senior Manager - Global Payment Network Information Security Office (ISO) Consultant

    Senior Manager - Global Payment Network Information Security Office (ISO) Consultant

    Capital One • Baltimore, Maryland, US
    serp_jobs.job_card.full_time +1
    Senior Manager - Global Payment Network Information Security Office (ISO) Consultant At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Security Infrastructure Support Team Lead

    Security Infrastructure Support Team Lead

    Cybervance • Bethesda, MD, United States
    serp_jobs.job_card.full_time
    Cybervance is a rapidly growing information security and information technology company based in Washington, D.We design, develop, and manage the successful execution of training programs for gover...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted