← Back to results

siem jobs in San Diego

$65,000 – $85,000 · Posted 1 day ago

An Associate Cybersecurity Engineer will monitor security alerts from SIEM, EDR, and IDS/IPS tools to detect and triage security incidents, then investigate confirmed events and support containment and recovery efforts. The role includes threat analysis, vulnerability validation, security awareness training administration, and phishing simulation campaign execution.… The engineer will document investigations, maintain runbooks and playbooks, and collaborate with Security, IT, and DevOps teams while supporting compliance frameworks (SOC 2, ISO 27001, PCI DSS).

San DiegoLast seen today
$105,400 – $207,800 · Posted 1 day ago

Design and implement secure, scalable Google SecOps architectures for SIEM and SOAR deployments aligned with enterprise security policies and regulatory requirements (GDPR, PCI DSS). Lead log ingestion pipelines using data fabric technologies, develop threat detection content, translate security operations into automated SOAR playbooks, and mentor junior team members.… Requires 7+ years in security operations or threat detection engineering, hands-on experience with Google Chronicle/Siemplify, Python automation, Logstash/Gostash, ETL technologies (Cribl, Bindplane, Kafka), and familiarity with security frameworks like MITRE ATT&CK.

San DiegoLast seen today
Posted 1 day ago

Lead high-severity incident investigations, mentor L1/L2 analysts, and drive detection engineering at a cybersecurity services firm. Responsibilities include threat hunting, malware analysis, digital/network forensics, SIEM/EDR tuning (KQL, SPL, Sigma, YARA), playbook development, and automation scripting in Python/PowerShell/Bash.… This is a 5+ year senior incident responder role requiring deep hands-on expertise across the full incident response lifecycle, MITRE ATT&CK, and client-facing technical briefings.

San DiegoLast seen today
$134,500 – $265,100 · Posted 2 days ago

Lead security operations and threat detection engineering for enterprise clients using Google SecOps (Chronicle SIEM and Siemplify SOAR). Design and deploy log ingestion pipelines, develop threat detection rules, translate SOC processes into automated playbooks, and manage integrations across security platforms.… Mentor junior SOC engineers and collaborate with threat detection teams to reduce alert fatigue and scale response capabilities.

San DiegoLast seen today
$82,600 – $162,800 · Posted 4 days ago

As a Managed Services Engineer II (L1 SOC Analyst) on Deloitte's Cyber Operate team, you will monitor security alerts from SIEM and other security tools, validate and escalate incidents within SLA timeframes, investigate suspected threats, and perform IOC searches. You will respond to security events using documented procedures, distinguish false positives from genuine incidents, coordinate with escalation paths, and maintain runbooks and shift handover documentation.… The role requires a Bachelor's degree in IT/Computer Science plus 1+ years of security operations or cybersecurity experience, hands-on familiarity with SIEM platforms, IDS/IPS, EDR, DLP, WAF, firewalls, and threat intelligence, and the ability to work rotating 24/7 shifts from a Deloitte office 50% of the time.

San DiegoLast seen 2 days ago
Posted 5 days ago

This Senior Systems Administrator role supports U.S. National Security by maintaining critical enterprise infrastructure, including Windows servers, domain controllers, cloud resources, and VMware environments.… The position requires hands-on administration of secure networks, troubleshooting of cryptographic encryptors (TACLANE/KG-175), performing vulnerability remediation with ACAS/Nessus, and executing rapid incident response for site outages. The role demands an active Top Secret clearance with SCI eligibility, 2+ years of direct systems/network administration experience, and 4+ years managing enterprise Windows infrastructure (AD, DHCP, DNS, GPO, WSUS).

San DiegoLast seen 2 days ago
$118,500 – $207,750 · Posted 6 days ago

Lead the design and implementation of enterprise security enforcement technologies, including SIEM platforms, endpoint security, threat detection, and incident response systems. Develop and maintain a forward-looking cybersecurity technology roadmap aligned with NIST frameworks and business objectives, evaluating emerging threats and technologies to strengthen organizational security capabilities.… Conduct threat hunting, penetration testing, and detection engineering activities while driving automation of security controls, policy enforcement, and response across complex technology environments. Mentor cybersecurity teams and influence enterprise security strategy across large organizations, with demonstrated experience securing AI-enabled solutions and understanding AI-specific security considerations.

San DiegoLast seen 4 days ago
$135,000 – $231,000 · Posted 6 days ago

Lead information systems security for a cleared defense contractor, managing a team of ISSOs and Security Administrators through the RMF process while ensuring compliance with NISPOM, DCSA, and NIST 800-53 standards. Responsibilities include vulnerability management, STIG compliance, security incident investigation, insider threat coordination, and preparation for DCSA assessments.… Requires 8+ years IT experience with 5+ years as an ISSM in a cleared facility, proficiency in Windows/Linux, eMASS, Tenable, SIEM tools, and IAM Level 3 certification (CISSP, CISM, or GSLC). Strong background in container orchestration, infrastructure automation, and DevSecOps methodologies is valued.

San DiegoLast seen 5 days ago
Posted 6 days ago

Information System Security Officer III responsible for securing assigned networks, enclaves, and platform IT systems through vulnerability assessments, STIG compliance verification, and continuous monitoring. The role requires coordinating with engineers and developers to embed security throughout the system development lifecycle, managing RMF documentation and POA&M entries, conducting daily audit log and SIEM alert reviews, and supporting incident response and cyber inspections.… Must possess TS/SCI clearance, a bachelor's degree in IT/cybersecurity or equivalent experience, six years of hands-on security implementation and vulnerability analysis, and current DoD 8140/8570 IAM Level II certification.

San DiegoLast seen 4 days ago
$135,000 – $160,000 · Posted 7 days ago

Senior IT Cyber Security Specialist responsible for enterprise vulnerability scanning, system hardening, and patch management using tools like Nessus and HBSS. Administers security technologies including SIEM platforms, firewalls, endpoint protection, and VPNs while investigating security incidents and performing root cause analysis.… Requires 7+ years of progressive IT/cybersecurity experience in DoD or defense contractor environments, with strong Linux administration and Bash scripting skills. Must hold DoD 8570.1-M IAM Level III certification (CISSP, CISM, or GSLC) and maintain compliance with NIST SP 800-171, CMMC Level 2, and DISA STIGs.

San DiegoLast seen 5 days ago
$139,874 – $250,377 · Posted 8 days ago

Lead information security engineer responsible for designing and implementing comprehensive security architectures across ICW Group's IT and business technology infrastructure. Will conduct risk assessments, penetration tests, and security compliance reviews; partner with systems engineering and project management teams to ensure secure design throughout the development lifecycle; and lead remediation strategies for identified vulnerabilities.… Requires 10+ years of security engineering experience, AWS cloud security expertise (3–5 years preferred), and hands-on proficiency with IDS/IPS, firewalls, SIEM, forensics tools, and endpoint security solutions.

San DiegoLast seen 6 days ago
$121,624 – $217,710 · Posted 11 days ago

Information Security Engineer III will lead security architecture reviews and threat modeling for data, analytics, AI, and cloud initiatives at an insurance company. The role involves designing and implementing security controls for AWS data platforms and AI/ML workloads, providing oversight of LLM usage and emerging AI threats, and mentoring engineering teams on secure development practices.… You will partner with Engineering, Cloud, Data, and Operations teams to embed security into system design, manage compliance with NIST, NYDFS, PCI DSS, and CPRA/CCPA standards, and evaluate third-party vendors and security tools. The position requires 8+ years of security engineering experience, 3-5 years in AWS cloud security, and expertise in threat modeling, risk assessment, and incident management.

San DiegoLast seen 9 days ago
Posted 11 days ago

Seeking an experienced Systems Administrator to maintain critical defense enterprise infrastructure in San Diego, including Windows servers, domain controllers, cloud resources, and VMware environments. The role requires dual network and systems administration responsibilities, including TACLANE cryptographic encryptor configuration, troubleshooting site outages, vulnerability remediation (ACAS/Nessus), system hardening, and user account management.… Requires 4+ years designing and deploying enterprise Windows infrastructure (AD, DHCP, DNS, GPO, WSUS) and 2+ years in a Network or Systems Administrator role, plus DoD 8570 IAT Level II compliance (Security+ or equivalent).

San DiegoLast seen 9 days ago
Posted 13 days ago

ManTech seeks a Systems Administrator to maintain critical enterprise infrastructure for national security operations in San Diego, supporting the 0100–0900 morning shift. The role requires administering Windows servers, domain controllers, cloud resources, and VMware environments; configuring and troubleshooting KG-175 (TACLANE) cryptographic network encryptors; performing vulnerability remediation with ACAS/Nessus; and executing rapid incident response and site outage troubleshooting.… Candidates must have 4+ years of enterprise Windows infrastructure experience (AD, DHCP, DNS, GPO, WSUS), hands-on TACLANE configuration expertise, and DoD 8570 IAT Level II compliance (Security+ CE or equivalent). The position includes up to 25% travel (CONUS/OCONUS) and requires an active Top Secret clearance with SCI eligibility.

San DiegoLast seen 11 days ago
$157,675 – $238,500 · Posted 14 days ago

Build, deploy, and continuously improve MITRE ATT&CK–aligned threat detections across cloud, endpoint, identity, email, and application telemetry. Own the full detection lifecycle from hypothesis and data validation through deployment, tuning, and retirement, advancing a detection-as-code platform with version control, peer review, automated testing, and CI/CD.… Evaluate AI-powered security capabilities including LLMs, anomaly detection, and response automation. Partner with Security Operations on investigations, incidents, and detection maintenance.

San DiegoLast seen 12 days ago
$120,001 – $160,000 · Posted 14 days ago

A Software Integration Engineer at SAIC will design, develop, and deploy a hybrid container/virtualization platform supporting enterprise-scale workloads across on-prem and cloud environments. The role encompasses infrastructure-as-code automation, Kubernetes cluster configuration, DevSecOps practices, and integration of core platform services (identity/SSO, PKI, DNS, logging/SIEM, monitoring, secrets management).… Responsibilities include automating verification/validation, establishing CI/CD pipelines and standard operating procedures, supporting GPU-enabled AI/ML workloads, and mentoring junior engineers on cloud-native best practices. The position requires 7–9+ years of experience with cloud platforms (AWS, Azure, GCP), containerization (Kubernetes, Docker), virtualization (VMware, Hyper-V, KVM), infrastructure-as-code tools (Terraform, Ansible, Puppet), and DevSecOps toolchains (ArgoCD, GitLab, Jenkins).

San DiegoLast seen 13 days ago
$117,000 – $130,000 · Posted 17 days ago

The Cybersecurity Analyst leads Bumble Bee's day-to-day cybersecurity operations, investigating and responding to security incidents, hunting threats, and tuning detection tooling. The role owns the full incident response lifecycle, manages vulnerability remediation, optimizes SIEM platforms, conducts security risk assessments for platforms and vendors, and maintains compliance through access control reviews and policy development.… The analyst builds incident response playbooks, monitors threat intelligence and CVE disclosures, and advises on third-party cyber risk. The position requires 4+ years of cybersecurity experience, proficiency with SIEM platforms, EDR tools, vulnerability management, MITRE ATT&CK framework, and knowledge of NIST, SOC, and ISO standards.

San DiegoLast seen 15 days ago
$86,900 – $198,000 · Posted 21 days ago

Lead a team of IT systems engineers architecting, deploying, and securing enterprise server infrastructure across Windows, Linux, virtualization, and cloud environments. Design and operate Active Directory and hybrid identity solutions at scale, manage enterprise endpoint management with SCCM, and guide virtualization and hyperconverged infrastructure modernization.… Serve as primary technical authority providing hands-on mentoring, engineering reviews, and on-site technical advising to government clients on system architecture, modernization strategy, and mission-critical implementation planning.

San DiegoLast seen 19 days ago
Posted 22 days ago

This role manages continuous software sustainment and operational support for production systems in secure, multi-domain defense environments. You will perform tier 2/3 technical support, proactive vulnerability management, and technical debt remediation while executing zero-downtime deployments using Agile methodologies (Scrum, Kanban, SAFe).… You must maintain DISA STIG compliance, implement Risk Management Framework controls, and support Authority to Operate (ATO) activities. The position requires hands-on expertise with Linux and Windows Server administration, shell scripting (Bash/Python/Ansible), virtualization, SIEM/security monitoring, and DoD 8140 cyber workforce certifications.

San DiegoLast seen 20 days ago
$120,000 – $150,000 · Posted 25 days ago

A senior DevSecOps engineer will design and operate an automated compliance and AI-driven security platform for DoD and federal healthcare environments. The role demands expertise in DISA STIG automation, container security, RMF/FedRAMP workflows, and SIEM/SOAR integration, with responsibilities spanning secure CI/CD pipeline development, Wazuh and Elastic Stack deployment, OpenRMF automation, and LLM-assisted security operations.… The engineer will build hardened base images, maintain compliance pipelines, develop Tines SOAR workflows, and mentor others on architecture decisions.

San DiegoLast seen 5 days ago
$129,986 – $216,609 · Posted 26 days ago

Lead a team of security engineers responsible for the operational effectiveness and innovation of security engineering controls across LPL Financial. Manage day-to-day operations and maintenance of critical security infrastructure including SIEM, EDR, DLP, vulnerability management, IAM systems, and network security appliances.… Drive continuous improvement initiatives, develop incident response playbooks, collaborate with engineering teams on security integration, and provide technical leadership and mentorship to junior engineers. Requires 10+ years in information security with at least 5 years in a security operations or engineering leadership role.

San DiegoLast seen 24 days ago
Posted 27 days ago

This Systems Engineer II role focuses on DoD cybersecurity compliance, vulnerability remediation, and production software deployments in defense environments. The engineer will implement DISA STIG compliance, Risk Management Framework (RMF) standards, and maintain continuous security monitoring (SIEM, intrusion detection) across heterogeneous Linux and Windows server environments.… The role requires hands-on execution of zero-downtime deployment strategies, Agile/SAFe methodologies, and enterprise virtualization (VMware, AWS), with strong emphasis on Information Assurance and DoD 8140 cyber workforce standards.

San DiegoLast seen 25 days ago
$105,400 – $207,800 · Posted 1 month ago

Design, assess, and troubleshoot enterprise network security environments using Cisco security technologies, with expertise in Firepower Threat Defense (FTD), Firepower Management Center (FMC), and Identity Services Engine (ISE). Implement network access control, TrustSec segmentation, threat prevention controls, and secure deployments across on-premises, campus, data center, and cloud environments.… Develop client-facing security architectures integrating Cisco platforms with SIEM tools and automation solutions, delivering technical assessments, target-state architectures, and implementation roadmaps. Lead projects and workstreams while managing multiple priorities in a fast-paced consulting environment.

San DiegoLast seen 1 month ago
Posted 1 month ago

ManTech seeks a Systems Administrator to support national security infrastructure in San Diego, maintaining Windows servers, domain controllers, cloud resources, and VMware environments. The role combines network and systems administration, including configuring cryptographic network encryptors (TACLANE), troubleshooting site outages, performing vulnerability remediation with ACAS/Nessus, and managing user accounts.… Requires a Bachelor's degree with 4+ years of IT experience (or equivalent), DoD 8570 IAT Level II compliance, and 2+ years as a Network or Systems Administrator with enterprise Windows infrastructure expertise. Travel up to 25% and an active Top Secret/SCI clearance with polygraph eligibility are required.

San DiegoLast seen 1 month ago
Posted 1 month ago

ManTech seeks a Systems Administrator to maintain critical national security enterprise infrastructure in San Diego, working a 0100–0900 morning shift with on-call support. Responsibilities include administering Windows servers, domain controllers, cloud resources, and VMware environments; configuring and troubleshooting TACLANE cryptographic network encryptors; performing patch management, vulnerability remediation (ACAS/Nessus), and system hardening; and managing user accounts and ticketing incidents.… Requires a bachelor's degree with 4+ years of IT experience (or equivalent substitution), DoD 8570 IAT Level II compliance (Security+ CE or equivalent), 4+ years of enterprise Windows infrastructure design/deployment, and hands-on TACLANE encryptor experience. Up to 25% travel (CONUS and OCONUS) is required.

San DiegoLast seen 1 month ago