SIEM Engineer - Contract - Remote (Onsite in SC if required)
Indexed description
Job Title: SIEM Engineer
Location:100%Remote. Preference will be given to local candidates who can come to the officeas needed for client and departmental meetings, trainings, and other onsiteactivities.
Interview Process:1-2 Rounds of Virtual Interviews. In personavailability for interviews preferred.
Duration:12 Months
Employment Type: Contract
Experience Required: 10+ Years
Project Scope:
We are seeking an experienced SecurityArchitect Consultant – SIEM Engineer to support the Department ofAdministration's Division of Information Security. This role is focused on thedesign, implementation, administration, optimization, and operational supportof Palo Alto Cortex XSIAM and Cortex XDR in a large-scale,multi-tenant enterprise security environment.
The successful candidate will work alongsideenterprise security architects, engineers, and a 24x7 Security OperationsCenter (SOC) team to enhance SIEM, XDR, detection engineering, automation,incident response, and security monitoring capabilities across multiple stateagencies. This role also provides secondary support for Cribl datapipelines, log management, and telemetry onboarding.
Key Responsibilities:
·Design,implement, configure, and maintain Palo Alto Cortex XSIAM and CortexXDR platforms.
·Supportmulti-tenant SIEM environments, including tenant onboarding, role-based access,data segregation, dashboards, and reporting.
·Develop andoptimize: Detection rules, Correlation rules, Analytics, Threat hunting queries,Watchlists, Alert suppression logic
·Design and manage Cribl log pipelines, including: Data modeling, Parsing, Normalization, Enrichment,Routing, Filtering, Replay, Log ingestion
·Integratetelemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, andcustom applications.
·Develop andmaintain automated playbooks and response workflows using Python and Bash.
·Support incidentresponse, threat hunting, and SOC operations.
·Create andmaintain: Runbooks, SOPs, Architecture diagrams, Data flow documentation, Knowledgearticles
·Support Tier1–Tier 3 SOC analysts through troubleshooting, tuning, and knowledge transfer.
·Monitor SIEMhealth, ingestion, availability, detection coverage, false positives, MTTD,MTTR, and operational metrics.
·Ensure platformresilience, backup, recovery, lifecycle management, and change control.
·Collaborate withsecurity architects, engineers, analysts, and business stakeholders to improveenterprise security capabilities.
Required Skills & Experience:
- Hands-on experience with Palo Alto Cortex XSIAM and Cortex XDR architecture, implementation, administration, and operational support.
- Experience supporting enterprise SIEM platforms within large multi-tenant environments.
- Experience supporting 24x7 Security Operations Centers (SOC).
- Strong detection engineering experience including:
- Correlation rules
- Threat hunting
- Analytics
- Dashboards
- Alert tuning
- False-positive reduction
- Hands-on Cribl administration including:
- Data modeling
- Log pipeline design
- Parsing
- Normalization
- Enrichment
- Routing
- Ingestion
- Experience developing automation using:
- Python
- Bash
- Experience onboarding cloud, endpoint, network, identity, SaaS, Windows, Linux, and custom application telemetry.
- Strong knowledge of:
- Enterprise security architecture
- Incident response
- Secure system design
- Networking
- Identity & Access Management
- Cybersecurity frameworks
Preferred Skills:
·Excellent writtenand verbal communication skills.
·Strong ability tocreate: Business Requirements Documents (BRD), Functional RequirementsDocuments (FRD), Use Cases, Process Documentation
·Experiencegathering requirements through stakeholder interviews, policy documents,regulations, and business rules analysis.
·Knowledge ofbusiness modeling techniques and graphical process flow tools.
·Ability tocommunicate effectively with: Executive management, Business users, Projectmanagers, Technical teams, External stakeholders
Education
Bachelor's degree in Information Technology, Information Security, ComputerScience, or related field.
Eight(8) years of relevant experience may be substituted for the degree requirement.
Minimumfive (5) years supporting large enterprise IT environments or systemdeployments.
Preferred Certifications
- CISSP
- Security+
- GIAC
- Palo Alto Cortex Certification
- Cribl Certification
- Other relevant SIEM or cybersecurity certifications
Originally posted on Himalayas
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search