Senior SIEM Onboarding
- Canada
- Remote
- Posted Sep 26, 2026
- 1 position
$115,000–$150,000 / year
Opens an external site
- Employment type
- Full-time
- Experience level
- Senior · 5+ years
- Posting language
- English
- Working hours
- 40 hours per week
- Seniority
- Mid-Senior level
Job summary
Lead the design, deployment, validation, and documentation of log-source and security-telemetry integrations into Microsoft Sentinel and CrowdStrike Falcon Next-Gen SIEM. Optimize ingestion and automation, support network and Claroty OT security integrations, and prepare operational handover materials for the SOC while collaborating with customers and technical teams.
Job details
Position Overview We are looking for a Senior SIEM Onboarding Engineer to lead the end-to-end onboarding of log sources and security telemetry into Microsoft Sentinel and CrowdStrike Falcon Next-Gen SIEM. This is an engineering-focused role responsible for designing, implementing, validating, and documenting integrations before formally transitioning them to the Security Operations Center (SOC). Working within a highly collaborative cybersecurity team, the successful candidate will serve as a technical subject matter expert, drive continuous improvement initiatives, and work directly with customers on complex security projects. Responsibilities Plan, design, test, and deploy log source integrations into Microsoft Sentinel and CrowdStrike Falcon Next-Gen SIEM. Act as the subject matter expert for Microsoft Sentinel and provide expertise in SIEM engineering and onboarding activities. Design and maintain Microsoft Sentinel data collection capabilities, including data connectors, Data Collection Rules (DCRs), KQL transformations, custom tables, Azure Monitor Agent deployment, syslog/CEF forwarding, and custom log ingestion. Design and maintain CrowdStrike Falcon Next-Gen SIEM onboarding capabilities, including data connectors, Falcon Log Collector deployments, HEC ingestion, routing pipelines, and custom parsers. Build and maintain API-based integrations and automation scripts using technologies such as REST APIs, PowerShell, Python, and Bash. Optimize data ingestion for quality, completeness, normalization, and cost efficiency. Validate onboarded data sources, including parsing accuracy, field mapping, data health, latency, and coverage. Develop and deliver operational handover documentation for the Security Operations Center, including onboarding checklists, data dictionaries, monitoring guidance, known limitations, and operational runbooks. Maintain log source inventories, technical documentation, and onboarding backlogs. Perform ad hoc firewall changes and provide recommendations related to network architecture, hardening, segmentation, log transport, and collector placement. Contribute to the architecture, design, implementation, and integration of the Claroty OT security platform. Partner with project managers, customers, and technical teams to deliver successful security solutions. Identify opportunities for process improvement and contribute thought leadership to the evolution of SIEM engineering practices. Perform other related duties as required within the scope of the role. Qualifications Minimum five years of experience in security engineering, SIEM engineering, or enterprise log management. Demonstrated subject matter expertise with Microsoft Sentinel, including Data Collection Rules, data connectors, Azure Monitor Agent, KQL, and ingestion-time transformations. Strong experience onboarding and managing enterprise-scale log sources and security telemetry. Experience with API integrations, authentication technologies, automation, and scripting using PowerShell, Python, Bash, or similar technologies. Strong Windows and Linux administration experience, including logging, services, agents, system hardening, and troubleshooting. Working knowledge of enterprise networking and firewall technologies, including rules, NAT, segmentation, and syslog/CEF transport. Experience creating technical documentation, operational procedures, runbooks, and knowledge-transfer materials. Ability to work independently, solve complex technical challenges, and deliver solutions directly to customers. Strong communication and customer-facing skills. Experience in professional services, consulting, or managed service provider environments is considered a strong asset. Additional Requirements Experience with CrowdStrike Falcon Next-Gen SIEM is strongly preferred. Experience with operational technology (OT), industrial control systems (ICS), or the Claroty platform is considered an asset. Experience with observability, log-routing, or data-pipeline technologies is considered an asset. Familiarity with standards such as ASIM or Elastic Common Schema is considered an asset. Relevant certifications such as Microsoft SC-200, AZ-500, CrowdStrike certifications, Security+, or CISSP are considered assets. This position is fully remote within Canada. Occasional after-hours support may be required in response to customer emergencies. Eligibility to obtain a Government of Canada Reliability Status clearance is considered an asset. Compensation $115,000 to $150,000 Position Type We have 1 available position.
What you’ll do
Lead the design, deployment, validation, and documentation of log-source and security-telemetry integrations into Microsoft Sentinel and CrowdStrike Falcon Next-Gen SIEM. Optimize ingestion and automation, support network and Claroty OT security integrations, and prepare operational handover materials for the SOC while collaborating with customers and technical teams.
Requirements
Requires at least five years of security engineering, SIEM engineering, or enterprise log-management experience, with strong Microsoft Sentinel expertise and experience managing enterprise-scale telemetry. Candidates should also bring scripting and API integration skills, Windows and Linux administration, networking and firewall knowledge, documentation ability, and strong customer-facing communication; CrowdStrike SIEM experience is strongly preferred.
Listed skills
- Technical Documentation · Preferred
- Python · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Microsoft Sentinel
- CrowdStrike Falcon Next-Gen SIEM
- SIEM Engineering
- Log Source Onboarding
- Data Collection Rules
- KQL
- Azure Monitor Agent
- API Integrations
- PowerShell
- Python
- Bash
- Windows Administration
- Linux Administration
- Firewall Technologies
- Syslog/CEF
- Technical Documentation
Job areas
- Technology
- Security & Safety
- Engineering
- Consulting
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
EVAMAX Inc.
Tax Analyst - SR&ED
SponsoredDirect employerEasy Apply- Hybrid
- Oakville, ON
- Posted Sep 29, 2026
Synapses Games
Bilingual Administrative Assistant
SponsoredDirect employerEasy Apply- Hybrid
- Vaudreuil-Dorion, QC
- Posted Sep 28, 2026
Trista
Residential Home Care Services Manager (NOC 60040)
SponsoredDirect employerEasy Apply- On-site
- Calgary, AB
- Posted Sep 25, 2026
