← Back to results

siem jobs in San Diego

Posted 1 day ago

Lead detection operations, incident response, and security operations maturation for a growing security team. Operate SIEM/XDR across endpoint, cloud, identity, network, and SaaS telemetry; conduct complex investigations; tune detections; and drive root-cause analysis and post-incident improvements. Require 6+ years of hands-on security operations, detection engineering, or incident response experience with deep proficiency in SIEM/XDR query languages, EDR platforms, scripting (Python, PowerShell, Bash), and MITRE ATT&CK framework application. Mentor analysts, define playbooks and runbooks, lead threat hunts, and own SecOps metrics and operational-readiness reporting.

San DiegoLast seen today
Posted 1 day ago

The Cybersecurity Engineer II will design, engineer, and deploy cybersecurity and network defense solutions across complex DoD environments, with hands-on responsibility for SIEM, IDS/IPS, firewalls, and vulnerability management platforms. The role involves configuring Splunk Enterprise, conducting network and security analysis with tools like Wireshark and Tenable, and leveraging automation and APIs to improve security operations. The engineer will support DoD Computer Network Defense requirements, integrate solutions across Windows, Linux, and network infrastructure, and collaborate with government and vendor teams throughout acquisition, testing, and deployment. The position requires 5–7+ years of hands-on cybersecurity and network defense experience, a Bachelor's degree in a related technical field, and an active U.S. national security clearance.

San DiegoLast seen 1 day ago
$110,000 – $130,000 · Posted 2 days ago

This Cybersecurity Engineer II role involves designing, engineering, integrating, testing, and deploying cybersecurity and network defense solutions across complex DoD environments. The position requires planning and executing National Security and Cybersecurity assessments, configuring enterprise tools such as Splunk Enterprise, IDS/IPS, firewalls, and vulnerability management platforms, and conducting network and security analysis using tools like Wireshark and Tenable. The engineer will leverage automation, scripting, APIs, and generative AI to improve cybersecurity operations while supporting the full acquisition, integration, deployment, and sustainment lifecycle for DoD Computer Network Defense requirements.

San DiegoLast seen today
$70,000 – $85,000 · Posted 2 days ago

Support the implementation, monitoring, and maintenance of security controls across endpoint, identity, and Microsoft 365 environments at a pharmaceutical company. Responsibilities include monitoring security alerts, managing endpoint security in Microsoft Intune, maintaining device compliance policies, investigating security issues, and automating tasks with PowerShell. The role requires a foundational background in IT support, system administration, or security operations, with 1+ years of experience and hands-on exposure to Microsoft Defender Portal, MDM/MAM policies, and security investigation.

San DiegoLast seen today
$80,000 – $110,000 · Posted 3 days ago

This cybersecurity engineer role focuses on securing cloud infrastructure (AWS, Azure, GCP), containerized environments (Docker, Kubernetes), and applications through vulnerability management, risk assessment, and security architecture review. The position requires hands-on experience with SIEM, EDR, WAF configuration, and embedding security scanning (SAST, DAST, SCA) into CI/CD pipelines. The engineer will conduct threat modeling, manage IAM policies, perform penetration testing coordination, support incident response and post-incident reviews, and partner with engineering teams to balance security with delivery. The role also includes compliance support, vendor risk assessments, and serving in an on-call rotation for after-hours security incidents.

San DiegoLast seen 3 days ago
$80,000 – $110,000 · Posted 4 days ago

This role is a hands-on cybersecurity engineer responsible for securing cloud infrastructure (AWS, Azure, GCP), containerized environments (Docker, Kubernetes), and applications. Key duties include vulnerability scanning and penetration testing, threat modeling, Web Application Firewall (WAF) deployment and tuning, CI/CD security integration (SAST, DAST, SCA), incident response, and compliance support. The engineer will work closely with DevOps and application teams to embed security controls, conduct code and architecture reviews, and provide risk-based guidance. Required experience includes 3–5+ years in cybersecurity or security engineering, hands-on SIEM/EDR/vulnerability management tools, cloud platforms, WAF configuration, and scripting (Python, Bash, PowerShell).

San DiegoLast seen 1 day ago
Posted 4 days ago

Serve as a primary administrator for core security technologies including Microsoft Defender Suite, Entra ID, Conditional Access, and endpoint protection, while also administering enterprise infrastructure across Microsoft 365, Azure, AWS, VMware, and hybrid platforms. Troubleshoot complex infrastructure and security issues, manage cloud backup and disaster recovery, monitor alerts through LogicMonitor and SIEM/MDR/SOCaaS services, and coordinate with security operations teams on investigations and remediation. Requires 8+ years of hands-on experience in cybersecurity and infrastructure engineering in business-critical environments, with deep expertise in Microsoft identity and security technologies, cloud platforms, vulnerability management, and enterprise backup solutions. Participate in after-hours support and escalation activities as needed.

San DiegoLast seen 2 days ago
Posted 8 days ago

This is a hands-on security engineering role focused on running Saronic's cyber threat intelligence program. The engineer will track nation-state and advanced criminal adversaries targeting the defense industrial base, operationalize indicators and TTPs into detections and hunts, produce finished intelligence products, and fuse external threat feeds with internal telemetry to prioritize real exposures. The role requires 4+ years in cyber threat intelligence, threat hunting, detection engineering, or intrusion analysis with demonstrable experience tracking sophisticated or state-sponsored adversaries.

San DiegoLast seen 6 days ago
$144,900 – $265,800 · Posted 9 days ago

Lead operational service delivery for enterprise Web Application Firewall (WAF), load balancing, DNS, certificates, and edge security platforms. Own end-to-end service performance, SLA/KPI metrics, incident escalation, and cross-team coordination across application, cloud, networking, and security teams. Manage and develop senior and staff-level engineers, drive operational governance, risk management, and continuous improvement. The role requires sufficient technical depth to guide platform designs, direct incident response, and make informed operational decisions, though not necessarily performing all configurations personally.

San DiegoLast seen 7 days ago
Posted 10 days ago

This role provides IT risk management and cybersecurity oversight for a large, multi-location enterprise environment. Key responsibilities include triaging security alerts and IOCs, conducting IT security audits (network, OS, data center), administering Microsoft 365 Defender for Cloud and endpoint protection platforms, managing vulnerability assessments, and assisting with cloud migrations to Azure and Microsoft 365 services. The role requires 5+ years of IT experience in large environments, IT audit experience, Security+ or Cloud+ certification, and hands-on administration of Active Directory, SIEM tools, and service-desk ticketing systems.

San DiegoLast seen 8 days ago
$200,000 – $240,000 · Posted 12 days ago

Director leading a pre-sales security engineering team responsible for technical strategy, solution design, and customer-facing support across EVOTEK's cybersecurity portfolio. The role combines deep technical security expertise with people leadership, requiring mentorship of engineers/architects, oversight of enterprise solution design and proof-of-concept engagements, and alignment of technical capabilities with sales and delivery practices. Responsibilities include RFP response, competitive positioning, vendor management, and technical presentations spanning AI security, network security, cloud security, identity & access management, endpoint/XDR, SIEM/SOAR, zero-trust architecture, and data protection. Must understand the VAR business model and translate complex technical capabilities into business value for enterprise stakeholders.

San DiegoLast seen 10 days ago