R

Senior SIEM and XDR Engineer

RICEFW Technologies Inc • United State
Remote
Apply
AI Summary

Design, deploy, and operate enterprise SIEM and XDR capabilities. Develop and maintain automated response workflows and playbooks. Support Tier 1 through Tier 3 SOC analysts and incident responders.

Key Highlights
Design, deploy, and operate enterprise SIEM and XDR capabilities
Develop and maintain automated response workflows and playbooks
Support Tier 1 through Tier 3 SOC analysts and incident responders
Key Responsibilities
Assist in the planning, design, deployment, administration and operational support of enterprise SIEM and XDR capabilities
Develop, test, deploy and maintain automated response workflows and playbooks for enrichment, triage, containment, escalation, notifications, case management and incident response
Support Tier 1 through Tier 3 SOC analysts and incident responders through platform troubleshooting, detection tuning, threat hunting, technical escalation, knowledge transfer and shift handoffs
Technical Skills Required
SIEM and XDR Python Bash
Benefits & Perks
100% remote work
No relocation package provided
No visa sponsorship available
Nice to Have
CISSP, Security+ or GIAC certification
Palo Alto Cortex, Cribl or other relevant SIEM/security platform certification

Job Description


Work Location: Role is 100% Remote. Preference will be given to local candidates who can come to the office as needed for client and departmental meetings, trainings, and other onsite activities.

Candidate location: No South Carolina residency required. Open to nationwide candidates. All travel-related costs for onsite work will be the responsibility of the resource no matter the frequency of onsite work.



Daily Duties / Responsibilities

:This Position Is 100% Remote And Will Participate In A Monthly On-Call Rotation Supporting A 24x7 Security Operations Center Serving Multiple State Agencies. Other After-Hours Work May Be Required As Needed

  • .PRIMARILY Assist in the planning, design, deployment, administration and operational support of enterprise SIEM and XDR capabilities, including

:PALO ALTO CORTEX XSIAM AND CORTEX XDR PLATFORM ENGINEERING, CONFIGURATION, OPTIMIZATION AND TROUBLESHOOTIN

GMULTI-TENANT AGENCY ONBOARDING, TENANT-SPECIFIC CONFIGURATION, ROLE-BASED ACCESS, DATA SEGREGATION, DASHBOARDS AND REPORTIN

GDETECTION ENGINEERING, CORRELATION RULES, ANALYTICS, THREAT-HUNTING QUERIES, WATCHLISTS, SUPPRESSION LOGIC AND FALSE-POSITIVE REDUCTIO

  • NSECONDARILY Assist in the planning, design, deployment and operational support of log management and security data pipelines, including

:CRIBL DATA MODELING, LOG PIPELINE DESIGN, ROUTING, PARSING, NORMALIZATION, ENRICHMENT, FILTERING, REPLAY AND INGESTIO

NONBOARDING AND HEALTH MONITORING OF CLOUD, ENDPOINT, NETWORK, IDENTITY, SAAS AND CUSTOM APPLICATION TELEMETR

YLOG VOLUME, RETENTION, PERFORMANCE AND COST OPTIMIZATION WHILE MAINTAINING SECURITY AND COMPLIANCE REQUIREMENT

SINTEGRATIONS WITH TICKETING, CASE MANAGEMENT, NOTIFICATION, IDENTITY, THREAT INTELLIGENCE AND OTHER ENTERPRISE SYSTEMS AS NEEDE

  • DDevelop, test, deploy and maintain automated response workflows and playbooks for enrichment, triage, containment, escalation, notifications, case management and incident response
  • .Create and maintain operational runbooks, standard operating procedures, escalation matrices, troubleshooting guides, architecture diagrams, data-flow documentation, use-case catalogs and analyst knowledge articles
  • .Support Tier 1 through Tier 3 SOC analysts and incident responders through platform troubleshooting, detection tuning, threat hunting, technical escalation, knowledge transfer and shift handoffs
  • .Monitor and report on ingestion health, platform availability, alert volumes, detection coverage, false positives, service levels, mean time to detect, mean time to respond and tenant-specific operational metrics
  • .Ensure high availability, resilience, backup, recovery, lifecycle management and controlled change processes for SIEM, XDR and supporting log pipeline services
  • .Collaborate with security architects, engineers, analysts and agency stakeholders to align solutions with business goals, industry-standard frameworks, regulatory requirements and organizational risk tolerance


.
Required Skills (rank in order of Importance

  • ):HANDS-ON PALO ALTO CORTEX XSIAM AND CORTEX XDR DESIGN, IMPLEMENTATION, ADMINISTRATION AND OPERATIONAL SUPPOR
  • T.Experience engineering and supporting SIEM capabilities for multi-tenant environments and 24x7 Security Operations Center operation
  • s.Experience developing and tuning detections, correlation rules, analytics, threat-hunting queries, dashboards, reporting and alert suppression logi
  • c.Strong experience creating and managing complex playboo
  • ksCRIBL DATA MODELING, LOG PIPELINE DESIGN, PARSING, NORMALIZATION, ENRICHMENT, ROUTING AND INGESTIO
  • N.Experience developing automation, integrations, playbooks and response workflows using scripting languages such as Python and Bas
  • h.Experience onboarding and troubleshooting telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows and custom application source
  • s.Strong understanding of enterprise security architecture, incident response, networking, access control, secure system design and industry-standard cybersecurity framework


s.
Preferred Skills (rank in order of Importanc

  • e):HANDS-ON EXPERIENCE OPERATING CORTEX XSIAM AND CORTEX XDR IN A LARGE, MULTI-TENANT ENVIRONME
  • NT.Hands-on Cribl administration, data modeling and log pipeline optimization experien
  • ce.Experience supporting Tier 1 through Tier 3 SOC analysts, threat hunting, incident response and 24x7 operational handof
  • fs.Familiarity with industry-standard security and compliance frameworks and experience developing playbooks, runbooks, procedures and technical documentati

on.Required Education/Certificatio

ns:• BACHELOR'S DEGREE IN

ANINFORMATION TECHNOLOGY

ORINFORMATION SECURITY RELA

TEDFI

ELD• EIGHT YEARS OF RELEVANT W

ORKEXPERIENCE MAY BE SUBSTITUTED IN LIEU OF EDUCAT

ION• FIVE YEARS OF EXPERIENCE IN SUPPORTING LARGE IT ENVIRONMENTS AND/OR SYSTEM DEPLOYME

NTSPreferred Education/Certificatio

ns:• CISSP, Security+ or GIAC certificat

ion• Palo Alto Cortex, Cribl or other relevant SIEM/security platform certificat


ion

Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

Infor

United State

Senior IT Specialist (Contractor)

Networking
•
2h ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Not Applicable

Customer.io

United State

Virtualization Engineer

Networking
•
3h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

Bright Vision Technologies

United State

Subscribe our newsletter

New Things Will Always Update Regularly