IT - ADMIN - Security Architect - Consultant - SIEM Engineer
TALENT Software Services · Columbia, SC · 1 wk ago
On-siteOTHRFull-time
Daily Duties / Responsibilities
Work Schedule 100% Remote position. Participate in a monthly on-call rotation supporting a 24x7 Security Operations Center (SOC) serving multiple state agencies. Provide after-hours support as needed.
SIEM & XDR Administration
- Assist in the planning, design, deployment, administration, and operational support of enterprise SIEM and XDR platforms.
- Engineer, configure, optimize, troubleshoot, and maintain Palo Alto Cortex XSIAM and Cortex XDR environments.
- Perform multi-tenant agency onboarding, tenant-specific configurations, role-based access control (RBAC), data segregation, dashboards, and reporting.
- Develop and optimize:
- Detection rules
- Correlation rules
- Analytics
- Threat hunting queries
- Watchlists
- Alert suppression logic
- False positive reduction strategies
Log Management & Data Pipeline Engineering
- Affiliate in planning, designing, deploying, and supporting enterprise log management solutions.
- Design and manage Cribl data pipelines, including:
- Data modeling
- Log routing
- Parsing
- Normalization
- Enrichment
- Filtering
- Replay
- Log ingestion
- Optimize log volume, retention, performance, and cost while ensuring security and compliance.
Automation & Integration
- Develop, test, deploy, and maintain automated response workflows and playbooks.
- Build automation for:
- Alert enrichment
- Incident triage
- Containment
- Escalation
- Notifications
- Case management
- Incident response
- Integrate SIEM/XDR platforms with:
- Ticketing systems
- Case management platforms
- Identity solutions
- Threat intelligence platforms
- Notification systems
- Enterprise security tools
Documentation
- Create and maintain:
- Operational runbooks
- Standard Operating Procedures (SOPs)
- Escalation matrices
- Troubleshooting guides
- Architecture diagrams
- Data flow documentation
- Security use-case catalogs
- Analyst knowledge base articles
SOC Support
- Support Tier 1, Tier 2, and Tier 3 SOC Analysts and Incident Responders.
- Assist with:
- Platform troubleshooting
- Detection tuning
- Threat hunting
- Technical escalations
- Knowledge transfer
- Shift handoffs
Monitoring & Reporting
- Monitor and report:
- Log ingestion health
- Platform availability
- Alert volumes
- Detection coverage
- False positives
- Service Level Agreements (SLAs)
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Tenant-specific operational metrics
Platform Operations
- Ensure:
- High availability
- Platform resilience
- Backup and recovery
- Lifecycle management
- Controlled change management
- Operational stability of SIEM, XDR, and log pipeline services
Collaboration
- Work closely with:
- Security Architects
- Security Engineers
- SOCA
- Incident Responders
- Agency stakeholders
- Align security solutions with:
- Business objectives
- Cybersecurity best practices
- Regulatory compliance
- Industry security frameworks
- Organizational risk tolerance
Required Skills (Ranked By Importance)
- Hands-on experience with Palo Alto Cortex XSIAM and Cortex XDR design, implementation, administration, and operational support.
- Experience engineering and supporting SIEM platforms in multi-tenant environments and 24x7 Security Operations Centers (SOC).
- Strong experience developing and tuning:
- Detection rules
- Correlation rules
- Analytics
- Threat hunting queries
- Correlation rules
- Alert suppression logic
- Strong experience designing and managing complex automation playbooks.
- Hands-on experience with Cribl:Data modeling, Log pipeline design, Parsing, Normalization, Enrichment, Routing, Log ingestion.
- Experience developing automation, integrations, and response workflows using: Python, Bash.
- Hands-on experience onboarding and troubleshooting telemetry from: Cloud environments, Endpoint platforms, Network devices, Identity systems, SaaS applications, Linux, Windows, Custom applications.
- Strong understanding of: Enterprise security architecture, Incident response, Networking, Access control, Secure system design, Cybersecurity frameworks.
Preferred Skills
- Hands-on experience managing Cortex XSIAM and Cortex XDR in large-scale multi-tenant environments.
- Strong experience with Cribl Administration, data modeling, and log pipeline optimization.
- Experience supporting Tier 1-Tier 3 SOC operations, threat hunting, incident response, and 24x7 operational handoffs.
- Experience developing: Playbooks, Runbooks, Standard Operating Procedures (SOPs), Technical documentation.
- Familiarity with industry-standard security and compliance frameworks.
Required Education / Certifications
- Bachelor's degree in Information Technology, Information Security, or a related field.
- Eight (8) years of relevant work experience may be substituted in lieu of a bachelor's degree.
- Minimum five (5) years of experience supporting large enterprise IT environments and/or system deployments.
Preferred Certifications
- CISSP (Certified Information Systems Security Professional)
- CompTIA Security
- GIAC Certification
- Palo Alto Cortex Certification
- Cribl Certification
- Other relevant SIEM or cybersecurity platform certifications.