Search for More Jobs
Get alerts for jobs like this Get jobs like this tweeted to you
Company: SAIC
Location: Colorado Springs, CO
Career Level: Mid-Senior Level
Industries: Technology, Software, IT, Electronics

Description

Description

Join SAIC's team and play a pivotal role in defending North America. We are seeking an experienced Log Data Engineer onsite in Colorado Springs, CO to manage the scaling, performance, ingestion pipelines, and analytical detection rules of N&NC's multi-enclave Security Information and Event Management (SIEM) and monitoring architectures for the critical North American Aerospace Defense Command and United States Northern Command (N&NC) Information Technology (IT) Enterprise Services (NITES) contract.

In this role, you will streamline security operations by decoupling complex cyber-data engineering, such as parser creation, index policy management, data routing, and telemetry forwarding, from front-line SIEM security analysts. Your highly specialized work ensures that the team operates with optimal, high-fidelity log feeds, lightning-fast search capabilities, and stable, compliant log forwarding to the DoD Big Data Platform (BDP), providing N&NC leadership with reliable, real-time cyber situational awareness.

Responsibilities 

  • Design, deploy, and maintain custom data parsers and ingestion pipelines within the Security Onion architecture to normalize and ingest-route security telemetry across five separate security networks (NIPRNet, SIPRNet, SIPR-REL, NEN, and CENTRIXS-Mex), preventing data corruption or ingestion gaps.
  • Engineer and implement indexing policies, lifecycle management rules, and cluster configurations to handle massive volumes of incoming events, maximizing local storage retention and guaranteeing optimal database performance during high-urgency security incident queries.
  • Configure and optimize high-throughput forwarding pipelines to securely transmit cyber telemetry to the DoD Big Data Platform (BDP) and other DoD-approved Enterprise services without disrupting local network operations.
  • Engineer, test, and refine automated alarm rules and Intrusion Detection System (IDS) signatures to counter emerging threats and active adversary tactics.
  • Continuously calibrate the SIEM to ensure it captures advanced threats while filtering out noisy, irrelevant alerts.

Qualifications

Required Qualifications:

  • Active TS/SCI security clearance
  • Certification required per DoDD 8140.03, Intermediate Level (ISC2 SSCP or GIAC GSEC) or Advanced Level (ISACA CISM, ISC2 CISSP, or GIAC GSLC)
  • BS or equivalent work experience in Data Engineering, Information Assurance, Cybersecurity, or Systems Administration field
  • 9+ years of overall IT, cybersecurity, or data engineering experience
  • Demonstrated experience in cyber-data engineering, including log parser creation, index policy management, data routing, and telemetry forwarding

Desired Qualifications:

  • Extensive experience configuring and maintaining Security Onion architectures.
  • Familiarity with engineering data pipelines for the DoD Big Data Platform (BDP) or similar enterprise data lakes.
  • Knowledge of adversary tactics, techniques, and procedures (TTPs) and experience translating them into IDS rules and SIEM alerts.
  • Previous experience operating in a highly complex, metrics-driven DoD cybersecurity environment.

 

Target salary range: $120,001 - $160,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.


 Apply on company website