IT - ADMIN - Security Architect - Consultant - SIEM Engineer

DataSoft Technologies
Columbia, SC, United States
25 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows ARM Architecture Bash Shell Software as a Service Cloud Computing Cyber Security Linux Python (Programming Language) Parsing Runbook Security Information and Event Management Systems Integration
+5 more
Scripting Cyber Threat Analysis Information Technology Cybercrime 3-tier Architectures

Job description

Preference will be given to local candidates who can come to the office as needed for client and departmental meetings, trainings, and other onsite activities. Interview Process: 1-2 Rounds of Virtual Interviews. In-person availability for interviews preferred. Submission Deadline: 07/22 at 5:00 PM ES

Requirements

  • Bachelor’s Degree in Information Technology, Information Security, or a related field. (8+ years of relevant work experience may be substituted in lieu of education.)
  • 5+ years of experience supporting large IT environments and/or system deployments.
  • Hands-on experience with Palo Alto Cortex, Cortex XSIAM, and Cortex XDR design, implementation, administration, and operational support.
  • Experience engineering and supporting SIEM capabilities for multi-tenant environments and 24x7 Security Operations Center (SOC) operations.
  • Experience developing and tuning detections, correlation rules, analytics, threat-hunting queries, dashboards, reporting, and alert suppression logic.
  • Experience creating and managing complex playbooks.
  • Experience with CRIBL data modeling, log pipeline design, parsing, normalization, enrichment, routing, and ingestion.
  • Experience developing automation, integrations, playbooks, and response workflows using scripting languages such as Python and Bash.
  • Experience onboarding and troubleshooting telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, and custom application sources.
  • Strong understanding of enterprise security architecture, incident response, networking, access control, secure system design, and industry-standard cybersecurity frameworks., * CISSP, Security+, or GIAC certification.
  • Palo Alto Cortex, Cribl, or other relevant SIEM/Security Platform certification.
  • Hands-on experience operating Cortex XSIAM and Cortex XDR in a large, multi-tenant environment.
  • Hands-on Cribl administration, data modeling, and log pipeline optimization experience.
  • Experience supporting Tier 1-Tier 3 SOC Analysts, threat hunting, incident response, and 24x7 operational handoffs.
  • Familiarity with industry-standard security and compliance frameworks.
  • Experience developing playbooks, runbooks, procedures, and technical documentation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:56 min

Open-sourcing a complex parsing library for game data

Johan Hutting Johan Hutting · WWC 2024

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:36 min

Managing complex operation sequence weights using recursive parsing

Florian Rappl · LIVE

Videos

See all

Related articles

See all