Security Information and Event Management Detection Engineer
Your Opportunity:
Information Security Management ensures the security and protection of Health Shared Services (HSS) information through monitoring, consulting, advisory services, and direct security support across the organization. The SIEM Detection Engineer helps identify, assess, and communicate security risks to HSS leadership and IT teams. The role influences security and operational priorities by advising on security technologies, controls, and best practices; evaluating risks related to software, hardware, and processes; and operating technical solutions used to monitor and protect systems. This position serves as the owner of several critical Security Operations monitoring technologies and processes, ensuring their effectiveness and ongoing improvement. The role may also support Human Resources investigations by collecting, analyzing, and reporting digital evidence. As part of normal security operations, the incumbent may be exposed to information that could lead to HR investigations or disciplinary action.
Description:
Manage and optimize SIEM operations, data integrations, and monitoring coverage to maintain effective security visibility. Design, implement, and maintain MITRE ATT&CK-aligned detections, analytics, and correlation rules. Develop dashboards, reports, queries, workbooks, and automation playbooks to improve threat detection, response, and operational efficiency. Continuously enhance detection effectiveness through tuning, threat validation, threat intelligence integration, and alert optimization. Lead the implementation and improvement of SIEM integrations, analytics, automation, and monitoring capabilities. Provide subject matter expertise to IT, corporate, clinical teams, projects, and stakeholders on security standards, technologies, and best practices. Support incident investigations, root cause analysis, remediation activities, and threat-hunting initiatives. Provide technical leadership and guidance for security-related operational and project activities. Assess the security landscape and recommend improvements to monitoring capabilities, tools, processes, configurations, and detection strategies. Advise on the use of SIEM and related security technologies to strengthen detection, investigation, and response capabilities across HSS. Administration and Special Assignments: Identify gaps in security monitoring technologies, processes, and practices, and support the design and implementation of detective and preventive controls. Contribute to the development and enhancement of organizational security capabilities through continuous improvement initiatives. Perform specialized assignments requiring advanced expertise, including areas such as digital forensics, software security, database security, and other security disciplines as required.
- Transition Company: Health Shared Services
- Classification: IT Infrastructure Services 3
- Union: Exempt
- Unit and Program: Information Security Management
- Primary Location: CN Tower
- Location Details: Eligible to work remotely within Alberta
- Negotiable Location: Provincial
- Employee Class: Regular Full Time
- FTE: 1.00
- Posting End Date: 29-SEP-2026
- Date Available: 09-OCT-2026
- Hours per Shift: 7.75
- Length of Shift in weeks: 2
- Shifts per cycle: 10
- Shift Pattern: Days
- Days Off: Saturday/Sunday
- Minimum Salary: $42.12
- Maximum Salary: $56.86
- Vehicle Requirement: Not Applicable
Bachelor’s degree in computer science, Information Security, or a related field (or equivalent experience). Minimum 5 years of hands-on experience with enterprise SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, Securonix, or comparable solutions, including log integration, detection engineering, correlation rule development, and security tool integration.
Additional Required Qualifications:
Minimum 4 years of experience in SIEM administration, detection engineering, security monitoring, or a related cybersecurity role. Strong understanding of cybersecurity principles, threat detection, incident response, and SIEM technologies. Hands-on experience with enterprise SIEM platforms (e.g., Microsoft Sentinel, Securonix) and endpoint detection and response (EDR) solutions. Proficiency in scripting and automation using PowerShell, Python, KQL, or similar languages. Experience with log ingestion, data normalization, correlation rules, detection use cases, and security monitoring.
Preferred Qualifications:
Experience supporting cloud environments (Azure, AWS, or GCP) and cloud-native security monitoring solutions is considered an asset. 5+ years of experience with SIEM platforms, including Securonix, Splunk, IBM QRadar, Microsoft Sentinel, or equivalent solutions. GIAC, CISSP, or comparable Information Security certification preferred. Hands-on experience integrating SIEM platforms with endpoint security tools to enhance threat detection, monitoring, and response capabilities.
Please note:
All postings close at 23:59 MT of the posting end date indicated.
Security Screening:
A satisfactory criminal record check and/or Vulnerable Sector Search is required prior to your first day of work. Additionally, all employees have an ongoing duty to disclose any charges or convictions that may occur during their employment with AHS.
Healthy Albertans. Healthy
Communities. Together.
We’re passionate about what we do. Our team of skilled and dedicated health care professionals, support staff, and physicians promote wellness and provide health care all across Alberta.
Everything we do at AHS reflects a patient and family centred approach; it’s about putting patients’ and families’ experiences, priorities and trust first.
We are an equal opportunity employer. AHS values the diversity of the people and communities we serve and is committed to attracting, engaging and developing a diverse and inclusive workforce.











