Enter a job title or keyword

Sr. SIEM Onboarding

Calian


Job Location:

Ontario - Canada

Yearly Salary: CAD 115000 - 150000
Posted: 29 September 2026 (Yesterday)
Application Deadline: 27 December 2026
Vacancies: 1 Vacancy

Job Summary

Position Overview

We are looking for a Senior SIEM Onboarding Engineer to lead the end-to-end onboarding of log sources and security telemetry into Microsoft Sentinel and CrowdStrike Falcon Next-Gen SIEM. This is an engineering-focused role responsible for designing implementing validating and documenting integrations before formally transitioning them to the Security Operations Center (SOC).

Working within a highly collaborative cybersecurity team the successful candidate will serve as a technical subject matter expert drive continuous improvement initiatives and work directly with customers on complex security projects.

Responsibilities

Plan design test and deploy log source integrations into Microsoft Sentinel and CrowdStrike Falcon Next-Gen SIEM.

Act as the subject matter expert for Microsoft Sentinel and provide expertise in SIEM engineering and onboarding activities.

Design and maintain Microsoft Sentinel data collection capabilities including data connectors Data Collection Rules (DCRs) KQL transformations custom tables Azure Monitor Agent deployment syslog/CEF forwarding and custom log ingestion.

Design and maintain CrowdStrike Falcon Next-Gen SIEM onboarding capabilities including data connectors Falcon Log Collector deployments HEC ingestion routing pipelines and custom parsers.

Build and maintain API-based integrations and automation scripts using technologies such as REST APIs PowerShell Python and Bash.

Optimize data ingestion for quality completeness normalization and cost efficiency.

Validate onboarded data sources including parsing accuracy field mapping data health latency and coverage.

Develop and deliver operational handover documentation for the Security Operations Center including onboarding checklists data dictionaries monitoring guidance known limitations and operational runbooks.

Maintain log source inventories technical documentation and onboarding backlogs.

Perform ad hoc firewall changes and provide recommendations related to network architecture hardening segmentation log transport and collector placement.

Contribute to the architecture design implementation and integration of the Claroty OT security platform.

Partner with project managers customers and technical teams to deliver successful security solutions.

Identify opportunities for process improvement and contribute thought leadership to the evolution of SIEM engineering practices.

Perform other related duties as required within the scope of the role.

Qualifications

Minimum five years of experience in security engineering SIEM engineering or enterprise log management.

Demonstrated subject matter expertise with Microsoft Sentinel including Data Collection Rules data connectors Azure Monitor Agent KQL and ingestion-time transformations.

Strong experience onboarding and managing enterprise-scale log sources and security telemetry.

Experience with API integrations authentication technologies automation and scripting using PowerShell Python Bash or similar technologies.

Strong Windows and Linux administration experience including logging services agents system hardening and troubleshooting.

Working knowledge of enterprise networking and firewall technologies including rules NAT segmentation and syslog/CEF transport.

Experience creating technical documentation operational procedures runbooks and knowledge-transfer materials.

Ability to work independently solve complex technical challenges and deliver solutions directly to customers.

Strong communication and customer-facing skills.

Experience in professional services consulting or managed service provider environments is considered a strong asset.

Additional Requirements

Experience with CrowdStrike Falcon Next-Gen SIEM is strongly preferred.

Experience with operational technology (OT) industrial control systems (ICS) or the Claroty platform is considered an asset.

Experience with observability log-routing or data-pipeline technologies is considered an asset.

Familiarity with standards such as ASIM or Elastic Common Schema is considered an asset.

Relevant certifications such as Microsoft SC-200 AZ-500 CrowdStrike certifications Security or CISSP are considered assets.

This position is fully remote within Canada.

Occasional after-hours support may be required in response to customer emergencies.

Eligibility to obtain a Government of Canada Reliability Status clearance is considered an asset.

Compensation

$115000 to $150000

Position Type

We have 1 available position(s).

What Happens Next

Notify Your Manager: Before applying or immediately after you are asked to inform your current manager of your application in line with our Internal Transfer Guidelines Policy.

Hiring Manager Notification: The hiring manager for the new role will be made aware of your application.

1:1 Interview: A Corporate Talent Acquisition Specialist will contact you to schedule a one-on-one interview following your application.

Eligibility: Employees are generally expected to have at least 18 months of tenure with Calian including 12 months in their current position to be eligible for an internal transfer. For full details consult the Corporate Talent Acquisition and Hiring Policy or contact your Talent Acquisition team.

Job Title: Senior SIEM Onboarding

Requisition Number: 2615

Date: September 23 2026

Location: Ottawa ON

Remote: Yes

Business Unit: Essential Industries

Department: Information Systems & Information Technology

Job Type: Full-time

#LI-XX1#

#SF#


Required Experience:

Senior IC


About Company

Company Logo

Welcome to Calian, where innovation and expertise converge to deliver Advanced Technologies, Health, Learning, and IT & Cyber Solutions.

View Profile View Profile