EngineerJobs.io
← Back to all jobs

Job Description

Ally Financial is seeking a Principal Cyber Security Engineer to own the end-to-end lifecycle of SIEM platforms that support reliable, compliant log management and actionable threat detections. This onsite role in Detroit, MI focuses on hands-on SIEM architecture, large-scale onboarding, performance optimization, and close collaboration with SOC, incident response, threat hunting, and IT and application teams.

Role focus

The position designs, deploys, and optimizes SIEM platforms at scale, taking responsibility for data ingestion, parsing, normalization, storage and retention, operational resilience, and the quality and usefulness of detections. You will define KPIs and KRIs such as MTTD, alert quality, data freshness, coverage, and false positive rate, and use those measures to drive continuous improvements across security monitoring and compliance-aligned data handling.

Responsibilities

  • Design and maintain SIEM architecture, including data ingestion pipelines, parsers, normalization schemas, storage tiers, and retention strategies.
  • Evaluate and implement SIEM platform features and integrations, and drive upgrades and migrations as needed.
  • Onboard logs from diverse sources including EDR, firewalls, IDS/IPS, IAM, AD, DNS, proxies, email security, AWS/Azure/GCP, SaaS apps, containers/Kubernetes, databases, and identity providers.
  • Implement data quality monitoring and SLA-driven dashboards for ingestion health, parser accuracy, and data latency.
  • Optimize SIEM performance across indexing, search speed, hot/warm/cold storage, retention, and cost control.
  • Implement role-based access control, multitenancy (if applicable), and data governance.
  • Ensure high availability and disaster recovery; document and test failover procedures.
  • Define KPIs/KRIs such as MTTD, alert quality, data freshness, coverage, and false positive rate.
  • Conduct purple-team exercises and detection gap assessments, then drive remediation work.
  • Provide runbooks, knowledge base articles, and training to support SOC and IT teams.
  • Align SIEM data handling with regulatory and contractual requirements including SOC 2, ISO 27001, PCI-DSS, HIPAA, and GDPR.
  • Implement data minimization, masking, and retention policies; support audits and eDiscovery.
  • Partner with IT/Cloud/Data teams to implement logging at source and ensure secure, reliable transport.
  • Contribute to security architecture reviews for new systems and applications.

Requirements

  • 5+ years of experience in SIEM engineering or closely related security engineering roles.
  • Bachelor’s degree in Computer Science, Information Security, or a related field; or equivalent experience.
  • Proven end-to-end enterprise SIEM expertise, preferably Splunk and Cribl (examples include Splunk, Microsoft Sentinel, QRadar, Elastic Security, Exabeam, Sumo Logic, LogRhythm, Chronicle).
  • Strong data parsing and normalization skills (examples include regex, grok, KQL, SPL, AQL, Lucene).
  • Strong detection rule creation, correlation logic, and tuning skills.
  • Strong scripting and automation experience (Python, PowerShell, REST APIs, with Terraform/Ansible preferred).
  • Hands-on experience onboarding logs from Windows/Linux, AD, network devices, cloud services, EDR, and SaaS.
  • Experience integrating SIEM with SOAR and ticketing/case management (ServiceNow, JIRA).
  • Understanding of security operations, incident response workflows, and threat detection frameworks (MITRE ATT&CK, NIST 800-61).
  • Experience with public cloud platforms (AWS, Azure, etc.).
  • Experience with cloud logging and security services (AWS CloudTrail/CloudWatch/GuardDuty, Azure Defender/M365, GCP Audit Logs).
  • Knowledge of data pipelines and messaging (Kafka, Kinesis, Event Hubs) and storage tiers (object storage, hot/warm/cold).
  • Experience working in Agile environments and collaborating across teams.
  • Familiarity with identity and access management, network security, endpoint security, and common enterprise architectures.
  • Strong documentation skills, with IaC/CI-CD for detection content as a plus.

Technologies

SIEM (Security Incident & Event Management), Splunk, Cribl, Microsoft Sentinel, QRadar, Elastic Security, Exabeam, Sumo Logic, LogRhythm, Chronicle, regex, grok, KQL, SPL, AQL, Lucene, Python, PowerShell, REST APIs, Terraform, Ansible, SOAR, ServiceNow, JIRA, MITRE ATT&CK, NIST 800-61, AWS, Azure, AWS CloudTrail, AWS CloudWatch, AWS GuardDuty, Azure Defender, M365, GCP Audit Logs, Kafka, Kinesis, Event Hubs, Kubernetes.

Preferred qualifications

  • Multiple SIEM platform experience (migrations, hybrid environments).
  • Experience with UEBA/behavior analytics and anomaly detection.
  • Experience with EDR/XDR integrations and telemetry correlation.
  • Exposure to data lakes, lakehouses, or security data fabrics (e.g., Snowflake, BigQuery).
  • Certifications such as GCDA, GCIA, GCFE, GCIH, GMON, Splunk Certified Architect, Microsoft Certified: Cybersecurity Architect, AWS/Azure security certifications, CISSP.
  • Experience operating in regulated environments (financial services, healthcare).
  • Background in purple teaming, threat hunting, or malware analysis.

Base pay and incentives

The base pay range for this position is USD 110,000 - 180,000 per year. An individual’s pay within this range is determined by factors including role scope, responsibilities, experience, education, certifications, training, and additional qualifications. The role is eligible to participate in an annual incentive plan.

Benefits

  • Market-competitive base pay with pay-for-performance incentives (bonuses) based on personal and company goals.
  • 20 paid time off days (program starts at 20 paid time off days) plus 11 paid holidays.
  • 8 hours of volunteer time off yearly.
  • 401K retirement savings plan with matching and company contributions.
  • Student loan pay downs and 529 educational save up assistance programs.
  • Tuition reimbursement.
  • Employee stock purchase plan.
  • Flexible health and insurance options including medical, dental, and vision, plus life insurance and disability coverage.
  • Pre-tax Health Savings Account with employer contributions and Healthcare FSA.
  • Critical illness, accident & hospital indemnity insurance.
  • Total well-being program and Mentally Fit Employee Assistance Program.
  • Adoption, surrogacy and fertility assistance, paid parental and caregiver leave, and Dependent Day Care FSA back-up child and adult/elder care days (with childcare discounts).
  • Subsidized and discounted Weight Watchers® program and other employee discount programs.
  • Depending on the role: travel allowances, relocation assistance, a signing bonus and/or equity.

Work schedule

  • Ally designates roles as (1) fully on-site, (2) hybrid, or (3) fully remote.
  • Hybrid roles are generally expected to be in the office a set number of days per week as indicated by your manager.
  • Your hiring manager will discuss specific work requirements during the hiring process, and work requirements may change based on leader discretion and/or business need.

Similar Jobs