Position Title : Security Infrastructure Support SIEM & Data Pipeline Technical Lead / Subject-Matter Expert (SME)
Location : Bethesda, MD | Hybrid- Not Remote
Cybervance is a rapidly growing information security and information technology company based in Washington, D.C., and we are an equal opportunity employer. We design, develop, and manage the successful execution of training programs for government and private sector organizations. Cybervance believes in creating innovative solutions to deliver measured results.
We are seeking an experienced SIEM & Data Pipeline Technical Lead / Subject-Matter Expert (SME) to provide enterprise-level leadership and hands-on expertise in the design, development, and optimization of security information and event management (SIEM) systems and data pipeline integrations. The successful candidate will oversee the ingestion, normalization, and enrichment of log data across hybrid cloud and on-premises environments to enhance threat detection, incident response, and compliance reporting.
This role requires a deep technical understanding of SIEM platforms, data architecture, and DevSecOps practices. The ideal candidate will possess strong leadership skills, technical acumen, and the ability to communicate complex data and security concepts effectively to both technical and executive stakeholders.
Responsibilities
- Lead the design, implementation, and administration of enterprise SIEM solutions to support cybersecurity operations, compliance, and threat intelligence objectives.
- Architect and manage data ingestion pipelines, including log routing, filtering, and transformation for on-premises and cloud environments.
- Develop and maintain data normalization, enrichment, and correlation rules to ensure accurate and actionable security event data.
- Implement and manage data collection tools and agents to gather logs from diverse sources, including cloud, infrastructure, endpoint, and application systems.
- Integrate data from hybrid infrastructure environments (on-premises and cloud) using services such as AWS CloudTrail, GuardDuty, Azure Sentinel, and O365 Security & Compliance Center.
- Apply DevOps and CI / CD tools to create reliable, repeatable, and automated data pipeline processes supporting continuous monitoring and detection.
- Develop and maintain automation scripts and utilities in JavaScript and Python for pipeline management, log parsing, and system integration.
- Write and optimize complex queries in Splunk Processing Language (SPL) or SQL for analytics, dashboards, and operational reporting.
- Ensure compliance with federal cybersecurity frameworks such as FISMA, NIST SP 800-53, NIST SP 800-92, OMB M-21-31, and CDM.
- Collaborate with cybersecurity operations, infrastructure, and DevOps teams to ensure comprehensive coverage and efficient performance of data collection and SIEM operations.
- Develop and maintain data dictionaries, documentation, and standard operating procedures (SOPs) for SIEM and data pipeline management.
- Provide technical leadership and mentorship, ensuring consistency in implementation, monitoring, and troubleshooting across teams.
- Communicate complex technical information and security concepts to both technical staff and executive stakeholders in clear, actionable terms.
- Apply data governance principles to ensure data accuracy, completeness, and protection throughout the security pipeline.
- Leverage the MITRE ATT&CK framework to align event data correlation with real-world adversarial behaviors and threat models.
- Collaborate with third-party vendors and cross-functional teams to support integrations, resolve technical challenges, and ensure enterprise interoperability.
Experience
10+ years of experience designing, installing, maintaining, and supporting enterprise IT systems.5+ years of experience at the Senior Engineer level or higher.3+ years of specific experience implementing and administering SIEM platforms or related cybersecurity tools.Proven experience supporting hybrid infrastructures (on-premises and cloud) including AWS, Azure, and Microsoft 365.In-depth experience with SIEM platforms (e.g., Splunk, QRadar, Sentinel) and data collection tools (e.g., Cribl, Logstash, Fluentd).Proficiency with log routing, filtering, and transformation tools.Strong understanding of log formats (CEF, LEEF, JSON, XML) and data normalization, enrichment, and correlation techniques.Hands-on experience implementing CI / CD pipelines and DevOps automation to support data ingestion and SIEM configuration management.Strong scripting skills in JavaScript and Python for pipeline automation, API integration, and data parsing.Proficiency in query languages such as SPL (Splunk) and SQL for building analytics, dashboards, and reports.Experience with data governance, data lifecycle management, and event taxonomy design.Familiarity with the MITRE ATT&CK framework and its application to SIEM rule development and event correlation.Experience with federal compliance frameworks including FISMA, NIST 800-53, NIST 800-92, OMB M-21-31, and CDM.Strong analytical and troubleshooting abilities to identify and resolve SIEM data flow, parsing, and correlation issues.Proven ability to diagnose complex data pipeline failures and optimize performance across systems.Excellent verbal and written communication skills, capable of translating complex data architecture and cybersecurity concepts to both technical and executive audiences.Demonstrated ability to lead multidisciplinary teams, coordinate with vendors, and manage large-scale SIEM deployments.Strong documentation skills, with experience producing SOPs, risk assessments, and technical reports.Required Skills & Qualifications
Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field (preferred).Required Clearances
Current government security clearance : Public Trust.Preferred Qualifications
Certifications such as CISSP, CISM, Splunk Enterprise Certified Architect, AWS Certified Security Specialty, or Microsoft Certified : Azure Security Engineer Associate.Experience with data streaming technologies (Kafka, Kinesis, or similar) and data lake integrations.Knowledge of Zero Trust Architecture and continuous monitoring methodologies.Familiarity with automation frameworks (Ansible, Terraform, or CloudFormation) for infrastructure-as-code deployments.#J-18808-Ljbffr