Security Architect - SIEM
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+11 more
Job description
In this role, you will work alongside security architects, engineers, and analysts supporting a 24x7 Security Operations Center (SOC). You’ll help design, implement, maintain, and continuously improve SIEM, XDR, detection engineering, automation, and incident response capabilities across a complex multi-tenant environment., * Design, implement, administer, optimize, and troubleshoot Palo Alto Cortex XSIAM and Cortex XDR platforms
- Support multi-tenant environments including agency onboarding, role-based access controls, data segregation, dashboards, and reporting
- Develop and tune detection rules, analytics, threat-hunting queries, watchlists, suppression logic, and alert correlation
- Improve detection coverage while reducing false positives
Security Data Pipelines & Cribl
- Design and maintain Cribl data models and log pipelines
- Perform log parsing, normalization, enrichment, routing, filtering, replay, and ingestion
- Onboard telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, and custom application sources
- Optimize log retention, ingestion performance, and overall platform efficiency
Automation & Incident Response
- Develop and maintain automated workflows, playbooks, and response actions
- Build integrations with ticketing systems, case management platforms, threat intelligence tools, and enterprise applications
- Support incident investigations, threat hunting, escalation activities, and operational response efforts
Documentation & Operational Support
- Create runbooks, SOPs, architecture diagrams, troubleshooting guides, and technical documentation
- Support Tier 1-3 SOC analysts through platform administration, tuning, mentoring, and knowledge transfer
- Monitor platform health, ingestion metrics, alert volumes, service levels, and operational KPIs
- Participate in after-hours support and on-call rotations as required
Required QualificationsRequired Experience
- Hands-on experience designing, implementing, administering, and supporting Palo Alto Cortex XSIAM and Cortex XDR
- Experience supporting SIEM platforms within large-scale enterprise environments
- Experience supporting 24x7 Security Operations Centers (SOC)
- Experience developing and tuning detections, analytics, correlation rules, dashboards, and reporting
Requirements
- Strong experience building and maintaining complex automation playbooks and response workflows
- Hands-on experience with Cribl data modeling, log pipeline design, parsing, normalization, enrichment, routing, and ingestion
- Experience using scripting languages such as Python and Bash for automation and integrations
- Experience onboarding and troubleshooting security telemetry from diverse technology environments
- Strong understanding of:
- Enterprise security architecture
- Incident response
- Network security
- Access control
- Secure systems design
- Cybersecurity frameworks and best practices
Education
- Bachelor’s degree in Information Technology, Information Security, Cybersecurity, Computer Science, or related field
OR
- Eight (8) years of directly relevant experience may be substituted for the degree requirement
Additional Requirements
- Minimum five (5) years supporting large enterprise IT environments and/or system deployments
- Ability to obtain and maintain CJIS certification
- Ability to participate in an on-call rotation
Preferred Qualifications
- CISSP certification
- Security+ certification
- GIAC certification
- Palo Alto Cortex certifications
- Cribl certifications
- Experience operating Cortex XSIAM and Cortex XDR in large multi-tenant environments
- Experience supporting threat hunting and incident response teams
- Experience creating security playbooks, runbooks, and operational procedures
Screening Requirements
All candidates must successfully pass the following pre-employment requirements:
- Criminal background investigation
- Credit history check
- Motor vehicle record review
- 10-panel drug screening
- E-Verify employment verification
- Additional public safety screening requirements
These requirements are mandatory and non-negotiable. Candidates must also obtain and maintain annual CJIS certification as a condition of continued engagement., * Bachelor’s (Preferred)
Experience:
- Palo Alto Cortex XSIAM and Cortex XDR: 1 year (Required)
- supporting SIEM platforms: 1 year (Required)
- 24/7 SOC support: 1 year (Required)
- developing tuning detection, analytics, reporting: 1 year (Required)
- building/maintaining automation playbook: 1 year (Required)
- Cribl hands-on: 1 year (Required)
- Python & Bash : 1 year (Required)
- security telemetry from diverse tech environments: 1 year (Required)
- supporting large enterprise IT environments/deployments: 5 years (Required)
Benefits & conditions
$54 - $64 an hour - Full-time, Contract
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
9 Ways to Make Money Hacking
What Are The Top Skills Required For Azure Developers?
Understanding and Mitigating Common Web Vulnerabilities