Sr. SIEM Onboarding
Date: 23 Sept 2026
Location: Remote, CA
Company: Calian
Position Overview
We are looking for a Senior SIEM Onboarding Engineer to lead the end-to-end onboarding of log sources and security telemetry into Microsoft Sentinel and CrowdStrike Falcon Next-Gen SIEM. This is an engineering-focused role responsible for designing, implementing, validating, and documenting integrations before formally transitioning them to the Security Operations Center (SOC).
Working within a highly collaborative cybersecurity team, the successful candidate will serve as a technical subject matter expert, drive continuous improvement initiatives, and work directly with customers on complex security projects.
Responsibilities
Plan, design, test, and deploy log source integrations into Microsoft Sentinel and CrowdStrike Falcon Next-Gen SIEM.
Act as the subject matter expert for Microsoft Sentinel and provide expertise in SIEM engineering and onboarding activities.
Design and maintain Microsoft Sentinel data collection capabilities, including data connectors, Data Collection Rules (DCRs), KQL transformations, custom tables, Azure Monitor Agent deployment, syslog/CEF forwarding, and custom log ingestion.
Design and maintain CrowdStrike Falcon Next-Gen SIEM onboarding capabilities, including data connectors, Falcon Log Collector deployments, HEC ingestion, routing pipelines, and custom parsers.
Build and maintain API-based integrations and automation scripts using technologies such as REST APIs, PowerShell, Python, and Bash.
Optimize data ingestion for quality, completeness, normalization, and cost efficiency.
Validate onboarded data sources, including parsing accuracy, field mapping, data health, latency, and coverage.
Develop and deliver operational handover documentation for the Security Operations Center, including onboarding checklists, data dictionaries, monitoring guidance, known limitations, and operational runbooks.
Maintain log source inventories, technical documentation, and onboarding backlogs.
Perform ad hoc firewall changes and provide recommendations related to network architecture, hardening, segmentation, log transport, and collector placement.
Contribute to the architecture, design, implementation, and integration of the Claroty OT security platform.
Partner with project managers, customers, and technical teams to deliver successful security solutions.
Identify opportunities for process improvement and contribute thought leadership to the evolution of SIEM engineering practices.
Perform other related duties as required within the scope of the role.
Qualifications
Minimum five years of experience in security engineering, SIEM engineering, or enterprise log management.
Demonstrated subject matter expertise with Microsoft Sentinel, including Data Collection Rules, data connectors, Azure Monitor Agent, KQL, and ingestion-time transformations.
Strong experience onboarding and managing enterprise-scale log sources and security telemetry.
Experience with API integrations, authentication technologies, automation, and scripting using PowerShell, Python, Bash, or similar technologies.
Strong Windows and Linux administration experience, including logging, services, agents, system hardening, and troubleshooting.
Working knowledge of enterprise networking and firewall technologies, including rules, NAT, segmentation, and syslog/CEF transport.
Experience creating technical documentation, operational procedures, runbooks, and knowledge-transfer materials.
Ability to work independently, solve complex technical challenges, and deliver solutions directly to customers.
Strong communication and customer-facing skills.
Experience in professional services, consulting, or managed service provider environments is considered a strong asset.
Additional Requirements
Experience with CrowdStrike Falcon Next-Gen SIEM is strongly preferred.
Experience with operational technology (OT), industrial control systems (ICS), or the Claroty platform is considered an asset.
Experience with observability, log-routing, or data-pipeline technologies is considered an asset.
Familiarity with standards such as ASIM or Elastic Common Schema is considered an asset.
Relevant certifications such as Microsoft SC-200, AZ-500, CrowdStrike certifications, Security+, or CISSP are considered assets.
This position is fully remote within Canada.
Occasional after-hours support may be required in response to customer emergencies.
Eligibility to obtain a Government of Canada Reliability Status clearance is considered an asset.
Compensation
$115,000 to $150,000
Position Type
We have 1 available position(s).
What Happens Next?
Notify Your Manager: Before applying, or immediately after, you are asked to inform your current manager of your application, in line with our Internal Transfer Guidelines Policy.
Hiring Manager Notification: The hiring manager for the new role will be made aware of your application.
1:1 Interview: A Corporate Talent Acquisition Specialist will contact you to schedule a one-on-one interview following your application.
Eligibility: Employees are generally expected to have at least 18 months of tenure with Calian, including 12 months in their current position, to be eligible for an internal transfer. For full details, consult the Corporate Talent Acquisition and Hiring Policy or contact your Talent Acquisition team.
Job Title: Senior SIEM Onboarding
Requisition Number: 2615
Date: September 23, 2026
Location: Ottawa, ON
Remote: Yes
Business Unit: Essential Industries
Department: Information Systems & Information Technology
Job Type: Full-time
#LI-XX1#
#SF#