Security Architect - SIEM # 26-17159
US Tech Solutions · Columbia, SC · 6 days ago
On-siteOTHRFull-time
Job Functions & Responsibilities
- Aid in the planning, design, deployment, administration and operational support of enterprise SIEM and XDR capabilities, including:
- Palo Alto Cortex XSIAM and Cortex XDR platform engineering, configuration, optimization and troubleshooting
- Multi-tenant agency onboarding, tenant-specific configuration, role-based access, data segregation, dashboards and reporting
- Detection engineering, correlation rules, analytics, threat-hunting queries, watchlists, suppression logic and false-positive reduction
- Assist in the planning, design, deployment and operational support of log management and security data pipelines, including:
- Cribl data modeling, log pipeline design, routing, parsing, normalization, enrichment, filtering, replay and ingestion
- Onboarding and health monitoring of cloud, endpoint, network, identity, SaaS and custom application telemetry
- Log volume, retention, performance and cost optimization while maintaining security and compliance requirements
- Integrations with ticketing, case management, notification, identity, threat intelligence and other enterprise systems as needed
- Create, test, deploy and maintain automated response workflows and playbooks for enrichment, triage, containment, escalation, notifications, case management and incident response
- Support tier 1 through tier 3 SOC analysts and incident responders through platform troubleshooting, detection tuning, threat hunting, technical escalation, knowledge transfer and shift handoffs
- Maintain operational runbooks, standard operating procedures, escalation matrices, troubleshooting guides, architecture diagrams, data-flow documentation, use-case catalogs and analyst knowledge articles
- Monitor and report on ingestion health, platform availability, alert volumes, detection coverage, false positives, service levels, mean time to detect, mean time to respond and tenant-specific operational metrics
- Ensure high availability, resilience, backup, recovery, lifecycle management and controlled change processes for SIEM, XDR and supporting log pipeline services
- Collaborate with security architects, engineers, analysts and agency stakeholders to align solutions with business goals, industry-standard frameworks, regulatory requirements
Required skills
- Hands-on Palo Alto Cortex XSIAM and Cortex XDR design, implementation, administration and operational support
- Experience in engineering and supporting SIEM capabilities for multi-tenant environments and 24x7 Security Operations Center operations
- Experience developing and tuning detections, correlation rules, analytics, threat-hunting queries, dashboards, reporting and alert suppression logic
- Strong experience creating and managing complex playbooks
- Cribl data modeling, log pipeline design, parsing, normalization, enrichment, routing and ingestion
- Experience developing automation, integrations, playbooks and response workflows using scripting languages such as Python and Bash
- Experience onboarding and troubleshooting telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows and custom application sources
- Strong understanding of enterprise security architecture, incident response, networking, access control, secure system design and industry-standard cybersecurity frameworks
Required Education/Certifications
- Bachelor's degree in information technology or information security related field
- Eight years of relevant work experience may be substituted in lieu of education
- Five years of experience in supporting large IT environments and/or system deployments
Preferred skills
- Hands-on experience operating Cortex XSIAM and Cortex XDR in a large, multi-tenant environment
- Hands-on Cribl administration, data modeling and log pipeline optimization experience
- Experience supporting Tier 1 through Tier 3 SOC analysts, threat hunting, incident response and 24x7 operational handoffs
- Familiarity with industry-standard security and compliance frameworks and experience developing playbooks, runbooks, procedures and technical documentation
Preferred Education/Certifications
- CISSP, Security+ or GIAC certification
- Palo Alto Cortex, Cribl or other relevant SIEM/security platform certification