> Markdown version of [/jobs/ext/1409608-security-architect-siem](https://www.wearedevelopers.com/jobs/ext/1409608-security-architect-siem). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - SIEM - **Company:** Concordant LLC - **Location:** United States (Remote available) - **Salary:** $112,320.0 - $133,120.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, ARM Architecture, Bash Shell, Software as a Service, Cyber Security, Linux, Issue Tracking Systems, Intrusion Detection and Prevention, Python (Programming Language), Network Security, Log Analysis, Parsing, Performance Tuning, Runbook, Security Information and Event Management, Systems Integration, Trusted Systems, Scripting, Enterprise Software Applications, Cyber Threat Analysis, Information Technology, Cybercrime, Data Pipelines - **Published:** July 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=13be17f30578234e ## About the Role * Strong experience building and maintaining complex automation playbooks and response workflows * Hands-on experience with Cribl data modeling, log pipeline design, parsing, normalization, enrichment, routing, and ingestion * Experience using scripting languages such as Python and Bash for automation and integrations * Experience onboarding and troubleshooting security telemetry from diverse technology environments * Strong understanding of: * Enterprise security architecture * Incident response * Network security * Access control * Secure systems design * Cybersecurity frameworks and best practices Education * Bachelor's degree in Information Technology, Information Security, Cybersecurity, Computer Science, or related field OR * Eight (8) years of directly relevant experience may be substituted for the degree requirement Additional Requirements * Minimum five (5) years supporting large enterprise IT environments and/or system deployments * Ability to obtain and maintain CJIS certification * Ability to participate in an on-call rotation Preferred Qualifications * CISSP certification * Security+ certification * GIAC certification * Palo Alto Cortex certifications * Cribl certifications * Experience operating Cortex XSIAM and Cortex XDR in large multi-tenant environments * Experience supporting threat hunting and incident response teams * Experience creating security playbooks, runbooks, and operational procedures Screening Requirements All candidates must successfully pass the following pre-employment requirements: * Criminal background investigation * Credit history check * Motor vehicle record review * 10-panel drug screening * E-Verify employment verification * Additional public safety screening requirements These requirements are mandatory and non-negotiable. Candidates must also obtain and maintain annual CJIS certification as a condition of continued engagement., * Bachelor's (Preferred) Experience: * Palo Alto Cortex XSIAM and Cortex XDR: 1 year (Required) * supporting SIEM platforms: 1 year (Required) * 24/7 SOC support: 1 year (Required) * developing tuning detection, analytics, reporting: 1 year (Required) * building/maintaining automation playbook: 1 year (Required) * Cribl hands-on: 1 year (Required) * Python & Bash : 1 year (Required) * security telemetry from diverse tech environments: 1 year (Required) * supporting large enterprise IT environments/deployments: 5 years (Required) ## Description In this role, you will work alongside security architects, engineers, and analysts supporting a 24x7 Security Operations Center (SOC). You'll help design, implement, maintain, and continuously improve SIEM, XDR, detection engineering, automation, and incident response capabilities across a complex multi-tenant environment., * Design, implement, administer, optimize, and troubleshoot Palo Alto Cortex XSIAM and Cortex XDR platforms * Support multi-tenant environments including agency onboarding, role-based access controls, data segregation, dashboards, and reporting * Develop and tune detection rules, analytics, threat-hunting queries, watchlists, suppression logic, and alert correlation * Improve detection coverage while reducing false positives Security Data Pipelines & Cribl * Design and maintain Cribl data models and log pipelines * Perform log parsing, normalization, enrichment, routing, filtering, replay, and ingestion * Onboard telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, and custom application sources * Optimize log retention, ingestion performance, and overall platform efficiency Automation & Incident Response * Develop and maintain automated workflows, playbooks, and response actions * Build integrations with ticketing systems, case management platforms, threat intelligence tools, and enterprise applications * Support incident investigations, threat hunting, escalation activities, and operational response efforts Documentation & Operational Support * Create runbooks, SOPs, architecture diagrams, troubleshooting guides, and technical documentation * Support Tier 1-3 SOC analysts through platform administration, tuning, mentoring, and knowledge transfer * Monitor platform health, ingestion metrics, alert volumes, service levels, and operational KPIs * Participate in after-hours support and on-call rotations as required Required QualificationsRequired Experience * Hands-on experience designing, implementing, administering, and supporting Palo Alto Cortex XSIAM and Cortex XDR * Experience supporting SIEM platforms within large-scale enterprise environments * Experience supporting 24x7 Security Operations Centers (SOC) * Experience developing and tuning detections, analytics, correlation rules, dashboards, and reporting ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)