Gravwell Logo

Gravwell

Customer SIEM Engineer

Posted 19 Days Ago
Be an Early Applicant
Easy Apply
Remote
Hiring Remotely in USA
120K-210K Annually
Mid level
Easy Apply
Remote
Hiring Remotely in USA
120K-210K Annually
Mid level
The Customer SIEM Engineer will onboard and support customers, architecting data pipelines, managing Linux deployments, and creating detection logic for security threats.
The summary above was generated by AI

Who We Are 

Gravwell is a full-stack security and observability platform built for people who need answers from their data—fast. Whether you're hunting threats, investigating incidents, or validating system health, Gravwell gives you the tools and performance to stay ahead. We're on a mission to simplify the SIEM experience without sacrificing power or flexibility.

About the Role 

Gravwell is seeking a highly technical Customer SIEM Engineer to facilitate our Mission Support and onboarding efforts. While the Sales Engineers win the heart of the customer, you are the one who makes the platform fly. You will take the baton from the pre-sales team to lead customers through deployment, configuration, and long-term technical success. As a bridge between sales and engineering, you’ll ensure that every Gravwell instance is tuned for maximum visibility and elite performance.

What You'll Do 

You’ll live at the heart of our customers' infrastructure. Your job is to transform raw data into actionable intelligence. You will lead the "Mission Support" process—onboarding new customers by architecting their data pipelines, hardening their Linux-based deployments, and building the detection logic they need to sleep at night. You aren't just a support tech; you are a detection engineer and a systems architect who ensures Gravwell scales with the customer's mission.

Your Responsibilities

  • Lead the Onboarding Journey: Take full technical ownership of the customer relationship immediately following the sale, moving them from initial setup to a fully operational production environment.
  • Architect Data Pipelines: Design and implement complex data ingestion strategies using Gravwell Ingesters, focusing on efficient normalization and parsing.
  • Detection Engineering: Collaborate with customer security teams to build, test, and deploy advanced queries and alerting logic to identify threats and system anomalies.
  • Systems Engineering: Provide expert-level guidance on Linux system tuning, storage optimization, and resource management to ensure Gravwell clusters perform at peak efficiency.
  • Mission Support: Act as the primary technical point of contact for complex troubleshooting, helping customers navigate deep-tier technical hurdles in their environments.
  • Develop Technical Tooling: Write custom shell scripts, utilities, and automation workflows to streamline deployment and data manipulation tasks.
  • Feedback Loop: Act as a conduit between the customer and our core Engineering team, translating real-world usage challenges into prioritized product features.

What We're Looking For

  • 3–5+ years in a highly technical role such as Security Engineer, SIEM Administrator, or Site Reliability Engineer (SRE).
  • Linux Power User: You should be comfortable living in the terminal. Deep knowledge of Linux internals, file systems, and performance tuning is a must.
  • Scripting & Automation: Proficiency in Shell scripting, Python, or Powershell for system management and tasks.
  • Detection Mindset: Strong understanding of security frameworks (MITRE ATT&CK) and the ability to translate TTPs into functional search queries and alerts.
  • Log Mastery: Experience with regex, JSON manipulation, and structured/unstructured data normalization.
  • SIEM Expertise: Hands-on experience managing or deploying enterprise-grade platforms (e.g., Splunk, Elastic, QRadar, or specialized syslog-ng/fluentd architectures).
  • Project Leadership: Ability to manage an onboarding timeline and guide multiple stakeholders through a technical mission.

Nice to Have

  • Experience with various virtualization and storage architectures.
  • Knowledge of network protocols (PCAP analysis, Netflow, IPFIX).
  • Certifications in Security (GCIA, GCIH, OSCP) or Linux (RHCSA/RHCE).

Why Gravwell?

  • Work where your impact is direct, visible, and appreciated.
  • Full autonomy and trust to solve problems that we may not have known we had.
  • Flexible remote work setup with a strong support culture.
  • Access to mission-critical projects and real-world security data.
  • Help build a better analytics experience.

Compensation

  • Base Compensation Range: $120,000 - $210,000

Don’t meet every single requirement?

That’s okay. We believe great teammates can learn new skills. If you have a passion for the command line and a knack for finding the "needle in the haystack," we want to talk to you. Gravwell is built by people who love solving problems together.

Remote Position (United States)

Gravwell provides our employees with the flexibility to be creative and successful no matter where they are located. We have a flexible approach to work, meaning you can work from home, regardless of where you live within the United States.

Top Skills

Elastic
Fluentd
JSON
Linux
Powershell
Python
Qradar
Regex
Shell Scripting
SIEM
Splunk
Syslog-Ng

Similar Jobs

A Minute Ago
Easy Apply
Remote
U.S.
Easy Apply
132K-207K Annually
Senior level
132K-207K Annually
Senior level
Artificial Intelligence • Enterprise Web • Software • Design • Generative AI
As a Senior Backend Engineer, you'll collaborate with a cross-functional team to build features for a Digital Asset Manager, tackle complex technical issues, and apply web best practices in a rapidly evolving environment.
Top Skills: CSSExpressHTMLJavaScriptMongoDBNode.jsReactTypescript
An Hour Ago
Easy Apply
Remote
United States
Easy Apply
50K-74K Annually
Entry level
50K-74K Annually
Entry level
Cloud • Security • Software • Cybersecurity • Automation
As a Business Development Representative, you'll execute prospecting initiatives, generate pipeline, and engage with Financial Services accounts while collaborating with marketing and sales teams.
Top Skills: OutreachSales NavigatorSalesforce
An Hour Ago
Easy Apply
Remote
United States
Easy Apply
50K-74K Annually
Entry level
50K-74K Annually
Entry level
Cloud • Security • Software • Cybersecurity • Automation
The Business Development Representative at GitLab will conduct outreach to generate qualified meetings, engage with prospects, and collaborate with marketing and sales teams to drive pipeline growth.
Top Skills: OutreachSales NavigatorSalesforce

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account