SIEM Security Engineer (Ottawa)

SIEM Security Engineer (Ottawa)

19 Aug
|
Maplesoft Group, an SEB
|
Ottawa

19 Aug

Maplesoft Group, an SEB

Ottawa

Job ID: 14365

Job Title: Senior IT Security Engineer

Contract Length: 24+ Months

Location: Remote within Canada

Federal Government Clearance Level Required: Active Government of Canada Reliability Status

Vacancy Type

- New Position

________________________________________

About Us

Maplesoft Group is currently seeking a Senior IT Security Engineer for a contract opportunity supporting Government of Canada cybersecurity operations. This role will provide senior-level expertise in Security Information and Event Management (SIEM), cyber threat surveillance, security monitoring, content development, threat intelligence, and security event analysis. The successful candidate will work with security teams and stakeholders to develop, enhance, and maintain enterprise security monitoring capabilities.

________________________________________

Position Summary The Senior IT Security Engineer will work within a large-scale SIEM environment to evaluate and develop security use cases, onboard and troubleshoot security event logs, enhance security monitoring capabilities, and provide expert guidance on emerging threats.

The role requires strong hands-on experience with SIEM platforms, security content development, log analysis, threat modelling, security analytics, and cloud-based security monitoring. The successful candidate will also support the migration and modernization of SIEM capabilities, including the development and implementation of Microsoft Sentinel solutions in Azure.

________________________________________

Key Responsibilities

- Build, support, customize, and maintain SIEM content using platforms such as ArcSight, IBM QRadar, and Microsoft Sentinel.
- Develop and tune SIEM rules, correlation rules, reports, dashboards, queries, and security use cases.
- Onboard security event logs from multiple departments, partners, and environments.
- Troubleshoot log ingestion, parsing, timestamp, and data integrity issues.
- Develop custom parsers, including Regex-based parsing for CEF and LEEF formats.
- Design and implement security monitoring use cases based on organizational requirements and emerging threats.
- Develop and maintain Microsoft Sentinel content, dashboards, reports, integrations, and KQL queries.
- Support migration of SIEM use cases from ArcSight to Microsoft Sentinel.
- Analyze security alerts and logs to identify threats, vulnerabilities, and potential security incidents.
- Develop and enhance SIEM network models and centralized security monitoring capabilities.
- Integrate threat intelligence with security monitoring and live data feeds.
- Apply the MITRE ATT&CK; Framework to security monitoring and detection activities.
- Provide expert advice on SIEM, UEBA, correlation, log aggregation, threat intelligence, and security architecture.
- Develop dashboards, metrics, trends, and reports to support security operations and management decision-making.
- Act as an escalation point for complex troubleshooting, log analysis, SIEM content development, and security data queries.




- Work with stakeholders to identify requirements and translate business and security objectives into technical solutions and use cases.
- Participate in threat modelling and threat intelligence activities to support proactive threat detection.
- Support security infrastructure involving SIEM, IDS/IPS, firewalls, and other security technologies.
- Provide technical documentation, implementation plans, solution analysis, status reports, and recommendations.
- Mentor and provide knowledge transfer to security analysts and other technical personnel.
- Collaborate across multiple teams and departments to coordinate technical activities and meet project timelines.

________________________________________

Required Qualifications

- Minimum 10 years of experience within the last 15 years working as an IT Security Engineer or in a closely related IT security engineering role.
- Must meet at least one of the following education/experience combinations:
- University degree in a related business or technology discipline; or
- Two-year college diploma in a related discipline plus two years of related experience; or
- University degree in any field plus five years of related experience; or
- At least 10 years of IT experience within the last 15 years.
- Must hold at least one valid certification:
- CISSP
- CCNA
- GIAC GCIH
- Minimum 3 years of technical-writing experience covering technical documentation, standard operating procedures, build documents, and basic architecture documents.
- Extensive hands-on experience with one or more enterprise SIEM platforms, including ArcSight, IBM QRadar, and/or Microsoft Sentinel.
- Strong experience developing SIEM rules, correlation logic, dashboards, reports, alerts, and security use cases.
- Strong experience with security log analysis, log onboarding, parsing, filtering, aggregation, and troubleshooting.
- Hands-on experience with Microsoft Sentinel and Azure security monitoring capabilities.
- Strong experience with Kusto Query Language (KQL) for security analytics and data querying.
- Experience with CEF and/or LEEF formats and Regex-based log parsing.
- Experience developing and tuning real-time security detection rules and actionable alerts.
- Experience with threat intelligence, threat modelling, and security monitoring.
- Experience applying the MITRE ATT&CK; Framework to security detection and monitoring.
- Knowledge of network and security technologies, including firewalls, IDS/IPS, APT, and internet protocols.
- Ability to analyze security data, identify threats and vulnerabilities, and provide security recommendations.
- Robust technical documentation, communication,



and stakeholder engagement skills.
- Ability to work in English, both written and spoken.
- Active Government of Canada Reliability Status is mandatory.
- Canadian citizenship or permanent residency is required.

________________________________________

Preferred Qualifications

- 36+ months of experience architecting and deploying ArcSight and/or Microsoft Sentinel/Lighthouse in Azure.
- 37+ months of experience working with SIEM and cyber-threat surveillance in a large-scale 24/7 SOC supporting 2,000+ users.
- 60+ months of experience analyzing security alerts and events in a large-scale 24/7 SOC environment.
- 12+ months of experience designing Microsoft Sentinel cloud infrastructure for log ingestion and security analytics.
- 18+ months of experience implementing ArcSight, QRadar, and/or Sentinel use cases in a large enterprise or Government of Canada SOC.
- 36+ months of hands-on KQL development and optimization.
- Experience migrating SIEM use cases from ArcSight to Microsoft Sentinel.
- Experience with CEF, LEEF, Regex, IDS/IPS, firewalls, APT tooling, UEBA, and enterprise log aggregation.
- Experience integrating ArcSight with IBM technologies using CEF and LEEF.
- Experience with Microsoft Sentinel/Lighthouse and Azure cloud environments.
- Experience integrating Sentinel with technologies such as Kafka, Elasticsearch, Logstash, and Kibana.
- Experience integrating SIEM platforms with external incident management systems.
- Experience developing centralized SIEM architectures across complex multi-partner environments.
- Experience developing security KPIs, metrics, trends, dashboards, and executive reporting.
- Experience providing knowledge transfer, mentoring, and training on SIEM content development.
- Experience with Independent Verification and Validation (IV&V;) of IT security projects.
- Previous Government of Canada security-environment experience is an asset.
- Candidates who currently hold or previously held higher-level Government of Canada security clearances are encouraged to apply.

________________________________________

Compensation

Salary Range: $120.00 - $140.00 / hour

________________________________________

Our recruitment process is led by human recruiters who review all applications and make the final hiring decisions. We use AI-assisted tools to help screen and organize applications. These tools do not replace human judgment, and all hiring decisions are made by people.

Please note that data collected by the Company may be stored or processed on servers located outside of Canada.

________________________________________

Application Submission Details

Submission Deadline

Thursday, August 20, 2026 - 5:00pm EST

How To Apply

Click the "APPLY NOW" Button below:

________________________________________

Maplesoft is an equal opportunity employer and welcomes applications from all qualified candidates. Accommodations are available upon request throughout the recruitment process.

📌 SIEM Security Engineer (Ottawa)
🏢 Maplesoft Group, an SEB
📍 Ottawa

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: siem security engineer (ottawa) / ottawa