Security Architect - Consultant - SIEM Engineer for Remote Work

Syntricate Technologies Inc
  • Columbia, SC
  • Remote
  • Quick Apply
30+ days ago

Job Description

 Requisition Name:   Security Architect - Consultant - SIEM Engineer
Work Address –  Remote Work - 100% Remote. Preference will be given to local candidates who can come to the office as needed for client and departmental meetings, trainings, and other onsite activities.).
Duration of the Contract: 12 Months
Possibility for Extension: Yes
 
 
Security Architect - Consultant – SIEM Engineer
 
Daily Duties and Responsibilities
 
  1. This position is 100% remote and participates in a monthly on-call rotation supporting a 24x7 Security Operations Center serving multiple state agencies. Additional after-hours work may be required as needed.
  2. Enterprise SIEM and XDR
  3. Primarily assist in the planning, design, deployment, administration, and operational support of enterprise SIEM and XDR capabilities, including:
  4. Palo Alto Cortex XSIAM and Cortex XDR platform engineering, configuration, optimization, and troubleshooting
  5. Multi-tenant agency onboarding, tenant-specific configuration, role-based access, data segregation, dashboards, and reporting
  6. Detection engineering, correlation rules, analytics, threat-hunting queries, watchlists, suppression logic, and false-positive reduction
  7. Log Management and Security Data Pipelines
  8. Secondarily assist in the planning, design, deployment, and operational support of log management and security data pipelines, including:
  9. Cribl data modeling, log pipeline design, routing, parsing, normalization, enrichment, filtering, replay, and ingestion
  10. Onboarding and health monitoring of cloud, endpoint, network, identity, SaaS, and custom application telemetry
  11. Log volume, retention, performance, and cost optimization while maintaining security and compliance requirements
  12. Integrations with ticketing, case management, notification, identity, threat intelligence, and other enterprise systems as needed

    Additional Responsibilities
  13. Develop, test, deploy, and maintain automated response workflows and playbooks for enrichment, triage, containment, escalation, notifications, case management, and incident response.
  14. Create and maintain operational runbooks, standard operating procedures, escalation matrices, troubleshooting guides, architecture diagrams, data-flow documentation, use-case catalogs, and analyst knowledge articles.
  15. Support Tier 1 through Tier 3 SOC analysts and incident responders through platform troubleshooting, detection tuning, threat hunting, technical escalation, knowledge transfer, and shift handoffs.
  16. Monitor and report on ingestion health, platform availability, alert volumes, detection coverage, false positives, service levels, mean time to detect, mean time to respond, and tenant-specific operational metrics.
  17. Ensure high availability, resilience, backup, recovery, lifecycle management, and controlled change processes for SIEM, XDR, and supporting log pipeline services.
  18. Collaborate with security architects, engineers, analysts, and agency stakeholders to align solutions with business goals, industry-standard frameworks, regulatory requirements, and organizational risk tolerance.
 
Required Skills (Ranked in Order of Importance)
  1. Hands-on Palo Alto Cortex XSIAM and Cortex XDR design, implementation, administration, and operational support.
  2. Experience engineering and supporting SIEM capabilities for multi-tenant environments and 24x7 Security Operations Center operations.
  3. Experience developing and tuning detections, correlation rules, analytics, threat-hunting queries, dashboards, reporting, and alert suppression logic.
  4. Strong experience creating and managing complex playbooks.
  5. Cribl data modeling, log pipeline design, parsing, normalization, enrichment, routing, and ingestion.
  6. Experience developing automation, integrations, playbooks, and response workflows using scripting languages such as Python and Bash.
  7. Experience onboarding and troubleshooting telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, and custom application sources.
  8. Strong understanding of enterprise security architecture, incident response, networking, access control, secure system design, and industry-standard cybersecurity frameworks.
 
Preferred Skills (Ranked in Order of Importance)
  1. Hands-on experience operating Cortex XSIAM and Cortex XDR in a large, multi-tenant environment.
  2. Hands-on Cribl administration, data modeling, and log pipeline optimization experience.
  3. Experience supporting Tier 1 through Tier 3 SOC analysts, threat hunting, incident response, and 24x7 operational handoffs.
  4. Familiarity with industry-standard security and compliance frameworks and experience developing playbooks, runbooks, procedures, and technical documentation.
 
Required Education and Certifications
  1. Bachelor's degree in an Information Technology or Information Security-related field.
  2. Eight years of relevant work experience may be substituted in lieu of education.
  3. Five years of experience supporting large IT environments and/or system deployments.
 
Preferred Education and Certifications
  1. CISSP, Security+, or GIAC certification.
  2. Palo Alto Cortex, Cribl, or other relevant SIEM/security platform certification.
 

Numbers & Facts

LocationColumbia, SC (
Remote
)

Skills

  • Administrative Skillsunmatched
  • Analysis Skillsunmatched
  • Automationunmatched
  • Bash Scriptingunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Case Managementunmatched
  • Change Controlunmatched
  • Cloud Computingunmatched
  • CompTIA Security+unmatched
  • Computer Securityunmatched
  • Cost Controlunmatched
  • Data Managementunmatched
  • Data Modelingunmatched
  • Data Recoveryunmatched
  • Documentationunmatched
  • Enterprise Architectureunmatched
  • Enterprise Protectionunmatched
  • GIAC - Global Information Assurance Certificationunmatched
  • High Availabilityunmatched
  • Huntingunmatched
  • Identify Issuesunmatched
  • Incident Responseunmatched
  • Industry Standardsunmatched
  • Information Technology & Information Systemsunmatched
  • Internet Securityunmatched
  • Knowledge Transferunmatched
  • Linux Operating Systemunmatched
  • Maintain Complianceunmatched
  • Metricsunmatched
  • Microsoft Windows Operating Systemunmatched
  • Network Access Control (NAC)unmatched
  • On Callunmatched
  • Onboardingunmatched
  • Operational Supportunmatched
  • Performance Tuning/Optimizationunmatched
  • Python Programming/Scripting Languageunmatched
  • Regulatory Complianceunmatched
  • Regulatory Requirementsunmatched
  • Reporting Dashboardsunmatched
  • Riskunmatched
  • Scripting (Scripting Languages)unmatched
  • Security Architectureunmatched
  • Security Consultingunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Infrastructureunmatched
  • Software as a Service (SaaS)unmatched
  • Standard Operating Procedures (SOP)unmatched
  • Systems Administration/Managementunmatched
  • Technical Supportunmatched
  • Technical Writingunmatched
  • Telemetryunmatched
  • Test Plan/Scheduleunmatched
  • Testingunmatched
  • Use Casesunmatched
  • Work From Homeunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder