CybersecurityJobs.io
← Back to all jobs

Job Description

Ally Financial is seeking a Principal Cyber Security Engineer to lead the SIEM platform lifecycle from design through ongoing optimization. This onsite role in Detroit partners closely with the SOC, incident response, threat hunting, IT operations, and application teams to deliver reliable, compliant log management and actionable detections.

Role overview

You will own key aspects of SIEM architecture and operations, including data ingestion pipelines, parsing and normalization, storage and retention strategy, and platform performance tuning. The position also focuses on measurable detection outcomes using KPIs and KRIs, while ensuring the SIEM data handling aligns with applicable regulatory and contractual requirements.

Responsibilities

  • Design and maintain the SIEM architecture, including data ingestion pipelines, parsers, normalization schemas, storage tiers, and retention strategies.
  • Evaluate and implement SIEM platform features and integrations, and drive upgrades and migrations as needed.
  • Onboard logs from diverse sources such as EDR, firewalls, IDS/IPS, IAM, AD, DNS, proxies, email security, cloud platforms (AWS/Azure/GCP), SaaS apps, containers/Kubernetes, and databases, as well as identity providers.
  • Implement data quality monitoring and SLA-driven dashboards for ingestion health, parser accuracy, and data latency.
  • Optimize SIEM performance across indexing and search speed, hot/warm/cold storage, retention, and cost control.
  • Implement role-based access control, multitenancy (if applicable), and data governance.
  • Ensure high availability and disaster recovery; document and test failover procedures.
  • Define KPIs/KRIs such as MTTD, alert quality, data freshness, coverage, and false positive rate.
  • Run purple-team exercises and detection gap assessments, and drive remediation work.
  • Provide runbooks, knowledge base articles, and training to SOC and IT teams.
  • Align SIEM data handling with regulatory and contractual requirements including SOC 2, ISO 27001, PCI-DSS, HIPAA, and GDPR; support audits and eDiscovery.
  • Implement data minimization, masking, and retention policies.
  • Partner with IT, Cloud, and Data teams to implement logging at the source and ensure secure, reliable transport.
  • Contribute to security architecture reviews for new systems and applications.

Requirements

  • 5+ years of experience in SIEM engineering or closely related security engineering roles.
  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • Proven end-to-end expertise with at least one enterprise SIEM platform, preferably Splunk and Cribl (e.g., Splunk, Microsoft Sentinel, QRadar, Elastic Security, Exabeam, Sumo Logic, LogRhythm, Chronicle).
  • Strong proficiency in data parsing and normalization (e.g., regex, grok, KQL, SPL, AQL, Lucene).
  • Strong proficiency in detection rule creation, correlation logic, and tuning.
  • Strong proficiency in scripting/automation (e.g., Python, PowerShell, REST APIs, Terraform/Ansible preferred).
  • Hands-on experience onboarding logs from Windows/Linux, AD, network devices, cloud services, EDR, and SaaS.
  • Hands-on experience integrating SIEM with SOAR, ticketing (ServiceNow, JIRA), and case management.
  • Good understanding of security operations, incident response workflows, and threat detection frameworks (MITRE ATT&CK, NIST 800-61).
  • Experience with public cloud platforms (AWS, Azure, etc.).
  • Experience with cloud logging and security services (AWS CloudTrail/CloudWatch/GuardDuty, Azure Defender/M365, GCP Audit Logs).
  • Knowledge of data pipelines and messaging (Kafka, Kinesis, Event Hubs) and storage tiers (object storage, hot/warm/cold).
  • Experience with Agile methodologies and collaborative work environments.
  • Familiarity with identity and access management, network security, endpoint security, and common enterprise architectures.
  • Strong documentation skills; experience with IaC/CI-CD for detection content is a plus.

Technologies

  • SIEM (Security Incident & Event Management)
  • Splunk, Cribl, Microsoft Sentinel, QRadar, Elastic Security, Exabeam, Sumo Logic, LogRhythm, Chronicle
  • Regex, grok, KQL, SPL, AQL, Lucene
  • Python, PowerShell, REST APIs, Terraform, Ansible
  • SOAR, ServiceNow, JIRA
  • MITRE ATT&CK, NIST 800-61
  • AWS, Azure, AWS CloudTrail, AWS CloudWatch, AWS GuardDuty, Azure Defender, M365, GCP Audit Logs
  • Kafka, Kinesis, Event Hubs, Kubernetes

Preferred qualifications

  • Multiple SIEM platform experience (migrations, hybrid environments).
  • Experience with UEBA/behavior analytics and anomaly detection.
  • Experience with EDR/XDR integrations and telemetry correlation.
  • Exposure to data lakes, lakehouses, or security data fabrics (e.g., Snowflake, BigQuery).
  • Certifications: GCDA, GCIA, GCFE, GCIH, GMON, Splunk Certified Architect, Microsoft Certified: Cybersecurity Architect, AWS/Azure security certs, CISSP.
  • Experience operating in regulated environments (financial services, healthcare).
  • Background in purple teaming, threat hunting, or malware analysis.

Location and schedule

  • Location: Detroit, MI (onsite)
  • Work schedule: Ally designates roles as fully on-site, hybrid, or fully remote. Hybrid roles are generally expected to be in the office a certain number of days per week, as indicated by your manager. Specific work requirements for this role are discussed during the hiring process.

Compensation

  • Base pay range: USD $110,000 - $180,000 per year
  • Individual pay in the range is determined by role scope and responsibilities, work experience, education, certification(s), training, and additional qualifications. Ally reviews internal pay, the competitive market, and the business environment before extending an offer.

Benefits

  • Market-competitive base pay with pay-for-performance incentives (bonuses) tied to personal and company goals.
  • 20 paid time off days (program starts at 20 PTO days) plus 11 paid holidays.
  • 8 hours of volunteer time off yearly.
  • 401(k) retirement plan with matching and company contributions.
  • Student loan pay downs and 529 educational savings assistance.
  • Tuition reimbursement.
  • Employee stock purchase plan.
  • Financial learning center and access to a financial coach.
  • Flexible health and insurance options including medical, dental, and vision, plus employee, spouse, and child life insurance.
  • Short- and long-term disability.
  • Pre-tax Health Savings Account with employer contributions and Healthcare FSA.
  • Critical illness, accident and hospital indemnity insurance.
  • Total well-being program, adoption/surrogacy/fertility assistance, and paid parental and caregiver leave.
  • Dependent Day Care FSA backup support and childcare discounts.
  • Mentally Fit Employee Assistance Program.
  • Subsidized and discounted Weight Watchers® program.
  • Other employee discount programs; depending on the role: travel allowances, relocation assistance, a signing bonus and/or equity.

Incentive compensation

  • This position is eligible to participate in Ally’s annual incentive plan.

Similar Jobs