JOBSEARCHER

Security Architect - SIEM Engineer

ARCHIVED

We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.

Job Title: Security Architect – SIEM EngineerLocation: Columbia, SCJob Type: Long Term ContractWork Setup: Remote/Hybrid - and participate in a monthly on-call rotation supporting a 24x7 SOC that serves multiple state agencies. Additional after-hours work may be required as needed.OverviewWe're seeking an experienced Security Architect – SIEM Engineer to join a large-scale enterprise security program supporting a 24x7 Security Operations Center (SOC). This is a hands-on engineering role where you'll design, implement, optimize, and automate enterprise SIEM and XDR capabilities across multiple environmentsIf you're passionate about Palo Alto Cortex XSIAM, Cortex XDR, Cribl, detection engineering, and enterprise-scale cybersecurity, we'd love to hear from youWhat You'll Do!Design, implement, administer, and optimize Palo Alto Cortex XSIAM and Cortex XDREngineer enterprise SIEM solutions supporting a multi-tenant 24x7 SOCDevelop detection logic, correlation rules, threat-hunting queries, dashboards, and reportsBuild and maintain automated incident response playbooks and security workflowsConfigure and optimize Cribl log pipelines, routing, parsing, normalization, and enrichmentOnboard cloud, network, endpoint, identity, SaaS, and custom application telemetryCollaborate with security architects, SOC analysts, and incident responders to improve detection and response capabilitiesTroubleshoot platform performance, optimize data ingestion, and reduce false positivesCreate technical documentation, runbooks, SOPs, and architecture diagramsParticipate in a monthly on-call rotation supporting a 24x7 Security Operations CenterRequired Qualifications:5+ years of enterprise SIEM or Security Engineering experienceHands-on experience with Palo Alto Cortex XSIAMExperience administering Palo Alto Cortex XDRExperience supporting enterprise or multi-tenant Security Operations CentersStrong detection engineering and threat hunting experienceExperience developing SIEM correlation rules and detection contentExperience with Cribl data pipelines and log managementExperience with Python and/or Bash scripting for automationStrong understanding of:Incident ResponseSecurity ArchitectureAccess ControlsEnterprise NetworkingSecurity FrameworksLog ManagementPreferred Qualifications:Experience supporting Tier 1–Tier 3 SOC operationsCloud security experience (AWS, Azure, or GCP)Experience integrating security platforms with enterprise systemsCISSP, Security+, GIAC, or equivalent certificationsPalo Alto Cortex or Cribl certifications are highly desirableTechnical Environment:Palo Alto Cortex XSIAMPalo Alto Cortex XDRCriblPythonBashSIEMSOARThreat HuntingDetection EngineeringIncident ResponseCloud SecurityEnterprise Security OperationsWindowsLinuxAWSAzure