Koniag Data Solutions, a Koniag Government Services company, is seeking a motivated and technically developing Junior SIEM/UEBA Engineer to support cybersecurity operations for a federal government client. This position requires the ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer. Primary work will be performed at the client site in Washington DC and approved remote/telework locations.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
This role serves as an important technical contributor responsible for supporting the administration, configuration, and optimization of Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA) platforms across a complex federal enterprise IT environment in support of continuous monitoring, threat detection, and incident response activities.
The ideal candidate is an early-career cybersecurity professional with foundational knowledge of SIEM and UEBA technologies, log management, security event analysis, and enterprise cybersecurity operations who is eager to grow their technical skills and contribute meaningfully to a high-performing federal cybersecurity team. This individual must demonstrate strong analytical curiosity, attention to detail, a commitment to continuous learning, and the professional maturity required to operate within a highly regulated federal IT environment.
The Junior SIEM/UEBA Engineer will serve as a developing technical contributor within the program's cybersecurity operations team, supporting the administration, tuning, and optimization of enterprise SIEM and UEBA platforms under the guidance of senior engineers and cybersecurity leadership. This individual assists with log source onboarding, detection rule development and tuning, alert triage and analysis, platform health monitoring, and the development of dashboards and reports that support continuous monitoring, threat detection, and compliance reporting activities across the federal enterprise IT environment.
Principal responsibilities will include but are not limited to:
SIEM Platform Support & Administration
Assist with the day-to-day administration, configuration, and maintenance of the enterprise SIEM platform, including user management, data source configurations, retention policy management, and platform health monitoring.
Support the onboarding of new log sources into the SIEM platform, assisting with log collection configuration, parsing rule development, field normalization, and data validation to ensure accurate and complete ingestion of security-relevant event data.
Assist with the development, testing, tuning, and documentation of SIEM detection rules, correlation rules, and alert logic to improve detection fidelity, reduce false positive rates, and ensure coverage of relevant threat scenarios and compliance requirements.
Monitor SIEM platform health, performance, and data ingestion status, identifying and escalating anomalies, collection failures, and performance degradation to senior engineers for investigation and resolution.
Assist with the development and maintenance of SIEM dashboards, saved searches, and reports that support security operations, continuous monitoring, SLA tracking, and compliance reporting requirements.
Support the periodic review and tuning of existing SIEM detection content, identifying opportunities to improve detection accuracy, reduce alert fatigue, and align detection coverage with current threat intelligence and operational requirements.
Assist with SIEM platform upgrades, patch applications, and configuration changes under the supervision of senior engineers, ensuring changes are tested, documented, and implemented in accordance with change management procedures.
UEBA Platform Support & Administration
Assist with the administration and configuration of the enterprise UEBA platform, supporting the establishment and maintenance of behavioral baselines, risk scoring models, and anomaly detection capabilities across user and entity populations.
Support the onboarding of data sources into the UEBA platform, assisting with integration configuration, data mapping, and validation activities to ensure the platform has complete and accurate visibility into relevant user and entity activity.
Assist with the review, tuning, and documentation of UEBA behavioral models, risk scoring rules, and anomaly detection thresholds to reduce false positives and improve the quality and actionability of UEBA-generated alerts and risk scores.
Monitor UEBA platform health, data ingestion status, and behavioral model performance, identifying and escalating anomalies and performance issues to senior engineers for investigation and resolution.
Support the development and maintenance of UEBA dashboards and reports that provide visibility into user and entity risk posture, behavioral anomalies, and insider threat indicators for security operations and program leadership.
Assist with periodic reviews of UEBA risk scoring outputs, collaborating with senior engineers and security analysts to identify false positive patterns, emerging risk trends, and tuning opportunities.
Log Management & Data Ingestion
Assist with the management and maintenance of the enterprise log management infrastructure, supporting log collection, forwarding, parsing, normalization, indexing, and retention activities across diverse log source @types and environments.
Support the development and maintenance of log parsing rules, field extraction configurations, and data normalization mappings for new and existing log sources, ensuring consistent and accurate data representation within the SIEM platform.
Assist with log source health monitoring, identifying collection gaps, parsing errors, and data quality issues, and escalating findings to senior engineers with supporting documentation.
Support the development and maintenance of log source inventory documentation, ensuring accurate records of all onboarded log sources, collection methods, data volumes, and retention configurations.
Assist with the onboarding of cloud platform log sources, including Microsoft 365 audit logs, Azure Monitor logs, AWS CloudTrail, and other cloud-native security log sources, under the guidance of senior engineers.
Alert Triage & Security Event Analysis
Perform initial triage and analysis of SIEM and UEBA-generated alerts, reviewing event data, log sources, and @contextual information to assess alert validity, severity, and recommended disposition.
Document alert triage findings accurately and completely in the ITSM or case management platform, ensuring all relevant event data, analysis steps, and disposition rationale are captured for audit and investigation purposes.
Escalate confirmed or suspected security incidents, high-priority alerts, and complex analytical findings to senior engineers and incident response personnel in a timely and well-documented manner.
Assist with security event correlation and timeline reconstruction activities, aggregating and analyzing event data across multiple log sources to support incident investigation and root cause analysis efforts.
Support the development and maintenance of alert triage procedures, runbooks, and analysis playbooks, contributing documentation based on recurring alert scenarios and lessons learned from completed triage activities.
Threat Intelligence Integration
Assist with the integration and operationalization of threat intelligence feeds within the SIEM platform, supporting the configuration of indicator of compromise (IOC) matching rules, threat intelligence enrichment workflows, and automated alert enrichment capabilities.
Support the development and maintenance of threat intelligence-driven detection rules and watchlists within the SIEM platform, ensuring detection coverage is aligned with current and emerging threat actor tactics, techniques, and procedures (TTPs).
Contribute to the program's threat intelligence repository by documenting indicators of compromise, attacker TTPs, and detection insights identified through alert triage and security event analysis activities.
Develop familiarity with the MITRE ATT&CK framework and its application to detection rule development, alert triage, and threat hunting activities under the guidance of senior engineers.
Reporting & Documentation
Assist with the development and maintenance of SIEM and UEBA operational reports, metrics dashboards, and compliance reporting outputs that support program leadership, Government stakeholders, and continuous monitoring requirements.
Develop and maintain technical documentation for SIEM and UEBA platform configurations, detection rules, log source integrations, tuning activities, and operational procedures, ensuring documentation is accurate, current, and accessible.
Contribute to the preparation of recurring security operations reports and briefings, compiling and organizing security event data, detection metrics, platform health information, and notable findings for inclusion in program reporting deliverables.
Support the development of after-action documentation for significant security events, SIEM/UEBA tuning activities, and platform changes, capturing lessons learned and improvement recommendations.
Compliance & Continuous Monitoring Support
Support the program's continuous monitoring activities, assisting with the collection, analysis, and reporting of security-relevant event data in support of FISMA, NIST SP 800-53, and client-specific continuous monitoring requirements.
Assist with the development and maintenance of SIEM-based compliance reporting content, including dashboards, saved searches, and automated reports that support audit readiness and regulatory compliance activities.
Ensure all SIEM and UEBA platform activities are conducted in compliance with applicable Federal security frameworks, including FISMA, NIST SP 800-53, NIST SP 800-207 Zero Trust Architecture, OMB M-22-09, and client-specific cybersecurity policies.
Support vulnerability management and security compliance activities by assisting with the development and maintenance of SIEM-based vulnerability tracking dashboards and compliance posture reporting.
Education and Experience:
Required:
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant technical experience or military service may be considered.
Minimum of 1-3 years of experience in cybersecurity operations, SIEM administration, log management, or a closely related technical discipline.
Foundational hands-on experience with at least one enterprise SIEM platform, such as Splunk, Microsoft Sentinel, IBM QRadar, Elastic SIEM, or equivalent.
Basic understanding of log management concepts, including log collection, parsing, normalization, and retention, across Windows, Linux, and network device log source @types.
Ability to obtain and maintain a government background investigation and all requisite IT access authorizations prior to performing work. Specific clearance requirements will be confirmed at time of offer.
Preferred:
Prior experience supporting cybersecurity operations in a federal government IT contracting environment.
Hands-on experience or academic/lab exposure to UEBA platforms such as Splunk UBA, Microsoft Sentinel UEBA, Securonix, or equivalent.
Experience or coursework related to cloud platform log sources, including Microsoft 365, Azure, or AWS.
Required Skills and Competencies:
Foundational knowledge of SIEM platform concepts, including log ingestion, parsing, normalization, correlation rule development, alert management, and dashboard development, with demonstrated hands-on experience or equivalent academic/lab exposure.
Basic understanding of UEBA concepts, including behavioral baseline establishment, anomaly detection, risk scoring, and insider threat detection use cases.
Foundational understanding of enterprise security log sources and the security-relevant events generated by Windows endpoints, Linux systems, network devices, firewalls, web proxies, Active Directory/Azure AD, and cloud platforms.
Basic proficiency with SIEM query languages, such as Splunk SPL, Microsoft KQL, or equivalent, for security event analysis, alert triage, and report development.
Foundational knowledge of cybersecurity concepts, including the cyber kill chain, common attack techniques, indicators of compromise, and network and endpoint security fundamentals.
Strong analytical and critical thinking skills with demonstrated ability to perform methodical, detail-oriented analysis of security event data and document findings accurately and completely.
Eagerness to learn and develop technical skills in SIEM and UEBA engineering, with demonstrated commitment to continuous professional development and knowledge growth.
Strong written and verbal communication skills with the ability to document technical findings, triage activities, and platform configurations clearly and accurately.
Basic familiarity with Federal cybersecurity frameworks and compliance requirements, including NIST SP 800-53, FISMA, and continuous monitoring concepts.
Ability to work effectively as part of a collaborative team under the direction of senior engineers and cybersecurity leadership, taking direction, accepting feedback, and contributing positively to team operations.
Strong organizational skills with the ability to manage multiple concurrent tasks, triage activities, and documentation responsibilities with accuracy and attention to detail.
Proficiency with Microsoft Office Suite and collaboration tools such as Microsoft Teams and SharePoint.
Desired Skills and Competencies:
CompTIA Security+, CompTIA CySA+, or equivalent entry-level cybersecurity certification demonstrating foundational security knowledge and professional development commitment.
Splunk Core Certified User, Splunk Core Certified Power User, Microsoft SC-200 (Security Operations Analyst), or equivalent SIEM platform certification or training credential.
GIAC Security Essentials (GSEC), GIAC Certified Intrusion Analyst (GCIA), or equivalent entry-level GIAC certification.
Familiarity with the MITRE ATT&CK framework and its application to threat detection, alert triage, and security event analysis.
Basic experience with scripting or query languages, including Python, PowerShell, Bash, or equivalent, for log analysis automation and security operations support tasks.
Familiarity with cloud security concepts and cloud-native log sources across Microsoft 365, Azure, or AWS environments.
Basic familiarity with network security concepts, including TCP/IP fundamentals, common network protocols, firewall log analysis, and network traffic analysis.
Familiarity with Zero Trust Architecture principles (NIST SP 800-207, OMB M-22-09) and their application to continuous monitoring and security operations within a federal enterprise IT environment.
Familiarity with incident response processes and ITIL-based IT service management concepts as they relate to security event triage, escalation, and case management activities.
Experience with threat intelligence concepts, including indicator of compromise @types, threat actor TTPs, and the practical application of threat intelligence to SIEM detection and alert enrichment.
Familiarity with log management and SIEM data pipeline concepts, including syslog, Windows Event Forwarding, Beats/agents, API-based collection, and cloud-native log forwarding mechanisms.
Prior internship, academic project, Capture the Flag (CTF) competition experience, or home lab work demonstrating hands-on engagement with SIEM, log analysis, or cybersecurity operations tools and concepts.
Our Equal Employment Opportunity Policy:
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com .
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
Job Details
Job Family IT, Cyber Security, Network Systems
Job Function Cyber Security Operations Analyst
Pay Type Salary
Hiring Min Rate 95,000 USD
Hiring Max Rate 125,000 USD