Jobs · OTHR · South Carolina

Security Architect - SIEM # 26-17159

US Tech Solutions · Columbia, SC · 6 days ago
On-siteOTHRFull-time

Job Functions & Responsibilities

  • Aid in the planning, design, deployment, administration and operational support of enterprise SIEM and XDR capabilities, including:
    • Palo Alto Cortex XSIAM and Cortex XDR platform engineering, configuration, optimization and troubleshooting
    • Multi-tenant agency onboarding, tenant-specific configuration, role-based access, data segregation, dashboards and reporting
    • Detection engineering, correlation rules, analytics, threat-hunting queries, watchlists, suppression logic and false-positive reduction
  • Assist in the planning, design, deployment and operational support of log management and security data pipelines, including:
    • Cribl data modeling, log pipeline design, routing, parsing, normalization, enrichment, filtering, replay and ingestion
    • Onboarding and health monitoring of cloud, endpoint, network, identity, SaaS and custom application telemetry
    • Log volume, retention, performance and cost optimization while maintaining security and compliance requirements
    • Integrations with ticketing, case management, notification, identity, threat intelligence and other enterprise systems as needed
    • Create, test, deploy and maintain automated response workflows and playbooks for enrichment, triage, containment, escalation, notifications, case management and incident response
    • Support tier 1 through tier 3 SOC analysts and incident responders through platform troubleshooting, detection tuning, threat hunting, technical escalation, knowledge transfer and shift handoffs
    • Maintain operational runbooks, standard operating procedures, escalation matrices, troubleshooting guides, architecture diagrams, data-flow documentation, use-case catalogs and analyst knowledge articles
  • Monitor and report on ingestion health, platform availability, alert volumes, detection coverage, false positives, service levels, mean time to detect, mean time to respond and tenant-specific operational metrics
  • Ensure high availability, resilience, backup, recovery, lifecycle management and controlled change processes for SIEM, XDR and supporting log pipeline services
  • Collaborate with security architects, engineers, analysts and agency stakeholders to align solutions with business goals, industry-standard frameworks, regulatory requirements

Required skills

  • Hands-on Palo Alto Cortex XSIAM and Cortex XDR design, implementation, administration and operational support
  • Experience in engineering and supporting SIEM capabilities for multi-tenant environments and 24x7 Security Operations Center operations
  • Experience developing and tuning detections, correlation rules, analytics, threat-hunting queries, dashboards, reporting and alert suppression logic
  • Strong experience creating and managing complex playbooks
  • Cribl data modeling, log pipeline design, parsing, normalization, enrichment, routing and ingestion
  • Experience developing automation, integrations, playbooks and response workflows using scripting languages such as Python and Bash
  • Experience onboarding and troubleshooting telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows and custom application sources
  • Strong understanding of enterprise security architecture, incident response, networking, access control, secure system design and industry-standard cybersecurity frameworks

Required Education/Certifications

  • Bachelor's degree in information technology or information security related field
  • Eight years of relevant work experience may be substituted in lieu of education
  • Five years of experience in supporting large IT environments and/or system deployments

Preferred skills

  • Hands-on experience operating Cortex XSIAM and Cortex XDR in a large, multi-tenant environment
  • Hands-on Cribl administration, data modeling and log pipeline optimization experience
  • Experience supporting Tier 1 through Tier 3 SOC analysts, threat hunting, incident response and 24x7 operational handoffs
  • Familiarity with industry-standard security and compliance frameworks and experience developing playbooks, runbooks, procedures and technical documentation

Preferred Education/Certifications

  • CISSP, Security+ or GIAC certification
  • Palo Alto Cortex, Cribl or other relevant SIEM/security platform certification

Similar jobs

Security Architect

Veeam SoftwareAlpharetta, GA· 1 wk ago
Information Technology$150k–$234k/yrapply on careers.veeam.com

Security Architect

Enzo HealthLehi, UT· 2 mo ago
Information Technologyapply on ats.rippling.com

Security Architect

thyssenkrupp Materials NASouthfield, MI· 1 mo ago
Information Technologyapply on jobs.thyssenkrupp.com