SIEM Engineer - Contract - Remote (Onsite in SC if required)

Sunshine Enterprise USA LLC
Columbia, SC, United States
22 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Data Analysis ARM Architecture Bash Shell Business Process Modeling Software as a Service Cloud Computing CompTIA Security+ Cyber Security Custom Software Linux Identity and Access Management
+13 more
Intrusion Detection and Prevention Python (Programming Language) Routing Parsing Runbook Security Information and Event Management Data Streaming Data Ingestion Mttr Information Technology Cybercrime 3-tier Architectures Data Pipelines

Job description

We are seeking an experienced Security Architect Consultant - SIEM Engineer to support the Department of Administration’s Division of Information Security. This role is focused on the design, implementation, administration, optimization, and operational support of Palo Alto Cortex XSIAM and Cortex XDR in a large-scale, multi-tenant enterprise security environment. The successful candidate will work alongside enterprise security architects, engineers, and a 24x7 Security Operations Center (SOC) team to enhance SIEM, XDR, detection engineering, automation, incident response, and security monitoring capabilities across multiple state agencies. This role also provides secondary support for Cribl data pipelines, log management, and telemetry onboarding., · Design, implement, configure, and maintain Palo Alto Cortex XSIAM and Cortex XDR platforms. · Support multi-tenant SIEM environments, including tenant onboarding, role-based access, data segregation, dashboards, and reporting. · Develop and optimize: Detection rules, Correlation rules, Analytics, Threat hunting queries, Watchlists, Alert suppression logic · Design and manage Cribl log pipelines, including: Data modeling, Parsing, Normalization, Enrichment, Routing, Filtering, Replay, Log ingestion · Integrate telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, and custom applications. · Develop and maintain automated playbooks and response workflows using Python and Bash. · Support incident response, threat hunting, and SOC operations. · Create and maintain: Runbooks, SOPs, Architecture diagrams, Data flow documentation, Knowledge articles · Support Tier 1-Tier 3 SOC analysts through troubleshooting, tuning, and knowledge transfer. · Monitor SIEM health, ingestion, availability, detection coverage, false positives, MTTD, MTTR, and operational metrics. · Ensure platform resilience, backup, recovery, lifecycle management, and change control. · Collaborate with security architects, engineers, analysts, and business stakeholders to improve enterprise security capabilities.

Requirements

  • Hands-on experience with Palo Alto Cortex XSIAM and Cortex XDR architecture, implementation, administration, and operational support.

  • Experience supporting enterprise SIEM platforms within large multi-tenant environments.

  • Experience supporting 24x7 Security Operations Centers (SOC).

  • Strong detection engineering experience including:

  • Correlation rules

  • Threat hunting

  • Analytics

  • Dashboards

  • Alert tuning

  • False-positive reduction

  • Hands-on Cribl administration including:

  • Data modeling

  • Log pipeline design

  • Parsing

  • Normalization

  • Enrichment

  • Routing

  • Ingestion

  • Experience developing automation using:

  • Python

  • Bash

  • Experience onboarding cloud, endpoint, network, identity, SaaS, Windows, Linux, and custom application telemetry.

  • Strong knowledge of:

  • Enterprise security architecture

  • Incident response

  • Secure system design

  • Networking

  • Identity & Access Management

  • Cybersecurity frameworks

Preferred Skills: · Excellent written and verbal communication skills. · Strong ability to create: Business Requirements Documents (BRD), Functional Requirements Documents (FRD), Use Cases, Process Documentation · Experience gathering requirements through stakeholder interviews, policy documents, regulations, and business rules analysis. · Knowledge of business modeling techniques and graphical process flow tools. · Ability to communicate effectively with: Executive management, Business users, Project managers, Technical teams, External stakeholders Education Bachelor’s degree in Information Technology, Information Security, Computer Science, or related field. Eight (8) years of relevant experience may be substituted for the degree requirement. Minimum five (5) years supporting large enterprise IT environments or system deployments. Preferred Certifications

  • CISSP

  • Security+

  • GIAC

  • Palo Alto Cortex Certification

  • Cribl Certification

  • Other relevant SIEM or cybersecurity certifications

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · WWC 2021

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · WWC Europe 2026

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

Videos

See all

Related articles

See all