SIEM Engineer - Contract - Remote (Onsite in SC if required)
Other Jobs To Apply
No other job posts for this day.
<p style="line-height:normal; margin-top:0px"><b><span class="size" style="font-size:12pt">Job Title: SIEM Engineer<br> </span><span style="">Location:</span></b><span style=""> 100% Remote. Preference will be given to local candidates who can come to the office as needed for client and departmental meetings, trainings, and other onsite activities.</span></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Interview Process:</span></b> <span style="">1-2 Rounds of Virtual Interviews. In person availability for interviews preferred.<br> <b>Duration: </b>12 Months<b><br> Employment Type:</b> Contract<b><br> Experience Required:</b> 10+ Years</span></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><br></p><div><b>Candidate location:</b> No South Carolina residency required. Open to nationwide candidates. All travel-related costs for onsite work will be the responsibility of the resource no matter the frequency of onsite work.<br></div><div><br></div><p><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Project Scope:</span></b><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><span style="">We are seeking an experienced <b>Security Architect Consultant – SIEM Engineer</b> to support the Department of Administration's Division of Information Security. This role is focused on the design, implementation, administration, optimization, and operational support of <b>Palo Alto Cortex XSIAM</b> and <b>Cortex XDR</b> in a large-scale, multi-tenant enterprise security environment.</span><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><span style="">The successful candidate will work alongside enterprise security architects, engineers, and a 24x7 Security Operations Center (SOC) team to enhance SIEM, XDR, detection engineering, automation, incident response, and security monitoring capabilities across multiple state agencies. This role also provides secondary support for <b>Cribl</b> data pipelines, log management, and telemetry onboarding.</span><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style=""> </span></b><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Key Responsibilities:</span></b><b><i><span class="font" style="font-family:" times="" new="" roman",="" serif"=""><span class="size" style="font-size:12pt"> </span></span></i></b><br></p><p class="MsoListParagraphCxSpFirst" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Design, implement, configure, and maintain <b>Palo Alto Cortex XSIAM</b> and <b>Cortex XDR</b> platforms.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Support multi-tenant SIEM environments, including tenant onboarding, role-based access, data segregation, dashboards, and reporting.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Develop and optimize: Detection rules, Correlation rules, Analytics, Threat hunting queries, Watchlists, Alert suppression logic</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Design and manage <b>Cribl</b> log pipelines, including: Data modeling, Parsing, Normalization, Enrichment, Routing, Filtering, Replay, Log ingestion</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Integrate telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, and custom applications.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Develop and maintain automated playbooks and response workflows using Python and Bash.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Support incident response, threat hunting, and SOC operations.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Create and maintain: Runbooks, SOPs, Architecture diagrams, Data flow documentation, Knowledge articles</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Support Tier 1–Tier 3 SOC analysts through troubleshooting, tuning, and knowledge transfer.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Monitor SIEM health, ingestion, availability, detection coverage, false positives, MTTD, MTTR, and operational metrics.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Ensure platform resilience, backup, recovery, lifecycle management, and change control.</span><br></p><p class="MsoListParagraphCxSpLast" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Collaborate with security architects, engineers, analysts, and business stakeholders to improve enterprise security capabilities.</span><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style=""> </span></b><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Required Skills & Experience:</span></b><br></p><ul style="margin-top:0in"><li style="margin-bottom:0in; line-height:normal"><span style="">Hands-on experience with <b>Palo Alto Cortex XSIAM</b> and <b>Cortex XDR</b> architecture, implementation, administration, and operational support.</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Experience supporting enterprise SIEM platforms within <b>large multi-tenant environments</b>.</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Experience supporting <b>24x7 Security Operations Centers (SOC)</b>.</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Strong detection engineering experience including:</span><br></li><ul style="margin-top:0in"><li style="margin-bottom:0in; line-height:normal"><span style="">Correlation rules</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Threat hunting</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Analytics</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Dashboards</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Alert tuning</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">False-positive reduction</span><br></li></ul><li style="margin-bottom:0in; line-height:normal"><span style="">Hands-on <b>Cribl</b> administration including:</span><br></li><ul style="margin-top:0in"><li style="margin-bottom:0in; line-height:normal"><span style="">Data modeling</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Log pipeline design</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Parsing</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Normalization</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Enrichment</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Routing</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Ingestion</span><br></li></ul><li style="margin-bottom:0in; line-height:normal"><span style="">Experience developing automation using:</span><br></li><ul style="margin-top:0in"><li style="margin-bottom:0in; line-height:normal"><span style="">Python</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Bash</span><br></li></ul><li style="margin-bottom:0in; line-height:normal"><span style="">Experience onboarding cloud, endpoint, network, identity, SaaS, Windows, Linux, and custom application telemetry.</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Strong knowledge of:</span><br></li><ul style="margin-top:0in"><li style="margin-bottom:0in; line-height:normal"><span style="">Enterprise security architecture</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Incident response</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Secure system design</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Networking</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Identity & Access Management</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Cybersecurity frameworks</span><br></li></ul></ul><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style=""> </span></b><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Preferred Skills:</span></b><br></p><p class="MsoListParagraphCxSpFirst" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Excellent written and verbal communication skills.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Strong ability to create: Business Requirements Documents (BRD), Functional Requirements Documents (FRD), Use Cases, Process Documentation</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Experience gathering requirements through stakeholder interviews, policy documents, regulations, and business rules analysis.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Knowledge of business modeling techniques and graphical process flow tools.</span><br></p><p class="MsoListParagraphCxSpLast" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Ability to communicate effectively with: Executive management, Business users, Project managers, Technical teams, External stakeholders</span><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Education</span></b><span style=""> <br> Bachelor's degree in Information Technology, Information Security, Computer Science, or related field.</span></p><p style="margin:0px 0in 0in 0.25in; line-height:normal"><span style="">Eight (8) years of relevant experience may be substituted for the degree requirement.</span><br></p><p style="margin:0px 0in 0in 0.25in; line-height:normal"><span style="">Minimum five (5) years supporting large enterprise IT environments or system deployments.</span><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style=""> </span></b><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Preferred Certifications</span></b><br></p><ul style="margin-top:0in"><li style="margin-bottom:0in; line-height:normal"><span style="">CISSP</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Security+</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">GIAC</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Palo Alto Cortex Certification</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Cribl Certification</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Other relevant SIEM or cybersecurity certifications</span><br></li></ul><div><br></div><br>