<p style="line-height:normal; margin-top:0px"><b><span class="size" style="font-size:12pt">Job Title: SIEM Engineer<br> </span><span style="">Location:</span></b><span style=""> 100%
Remote. Preference will be given to local candidates who can come to the office
as needed for client and departmental meetings, trainings, and other onsite
activities.</span></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Interview Process:</span></b> <span style="">1-2 Rounds of Virtual Interviews. In person
availability for interviews preferred.<br> <b>Duration: </b>12 Months<b><br> Employment Type:</b> Contract<b><br> Experience Required:</b> 10+ Years</span></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><br></p><div><b>Candidate
location:</b> No South Carolina residency required. Open to nationwide
candidates. All travel-related costs for onsite work will be the responsibility
of the resource no matter the frequency of onsite work.<br></div><div><br></div><p><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Project Scope:</span></b><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><span style="">We are seeking an experienced <b>Security
Architect Consultant – SIEM Engineer</b> to support the Department of
Administration's Division of Information Security. This role is focused on the
design, implementation, administration, optimization, and operational support
of <b>Palo Alto Cortex XSIAM</b> and <b>Cortex XDR</b> in a large-scale,
multi-tenant enterprise security environment.</span><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><span style="">The successful candidate will work alongside
enterprise security architects, engineers, and a 24x7 Security Operations
Center (SOC) team to enhance SIEM, XDR, detection engineering, automation,
incident response, and security monitoring capabilities across multiple state
agencies. This role also provides secondary support for <b>Cribl</b> data
pipelines, log management, and telemetry onboarding.</span><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style=""> </span></b><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Key Responsibilities:</span></b><b><i><span class="font" style="font-family:" times="" new="" roman",="" serif"=""><span class="size" style="font-size:12pt"> </span></span></i></b><br></p><p class="MsoListParagraphCxSpFirst" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Design,
implement, configure, and maintain <b>Palo Alto Cortex XSIAM</b> and <b>Cortex
XDR</b> platforms.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Support
multi-tenant SIEM environments, including tenant onboarding, role-based access,
data segregation, dashboards, and reporting.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Develop and
optimize: Detection rules, Correlation rules, Analytics, Threat hunting queries,
Watchlists, Alert suppression logic</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Design and manage <b>Cribl</b> log pipelines, including: Data modeling, Parsing, Normalization, Enrichment,
Routing, Filtering, Replay, Log ingestion</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Integrate
telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, and
custom applications.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Develop and
maintain automated playbooks and response workflows using Python and Bash.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Support incident
response, threat hunting, and SOC operations.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Create and
maintain: Runbooks, SOPs, Architecture diagrams, Data flow documentation, Knowledge
articles</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Support Tier
1–Tier 3 SOC analysts through troubleshooting, tuning, and knowledge transfer.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Monitor SIEM
health, ingestion, availability, detection coverage, false positives, MTTD,
MTTR, and operational metrics.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Ensure platform
resilience, backup, recovery, lifecycle management, and change control.</span><br></p><p class="MsoListParagraphCxSpLast" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Collaborate with
security architects, engineers, analysts, and business stakeholders to improve
enterprise security capabilities.</span><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style=""> </span></b><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Required Skills & Experience:</span></b><br></p><ul style="margin-top:0in"><li style="margin-bottom:0in; line-height:normal"><span style="">Hands-on
experience with <b>Palo Alto Cortex XSIAM</b> and <b>Cortex XDR</b> architecture, implementation, administration, and operational support.</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Experience
supporting enterprise SIEM platforms within <b>large multi-tenant
environments</b>.</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Experience
supporting <b>24x7 Security Operations Centers (SOC)</b>.</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Strong
detection engineering experience including:</span><br></li><ul style="margin-top:0in"><li style="margin-bottom:0in; line-height:normal"><span style="">Correlation
rules</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Threat
hunting</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Analytics</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Dashboards</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Alert
tuning</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">False-positive
reduction</span><br></li></ul><li style="margin-bottom:0in; line-height:normal"><span style="">Hands-on <b>Cribl</b> administration including:</span><br></li><ul style="margin-top:0in"><li style="margin-bottom:0in; line-height:normal"><span style="">Data
modeling</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Log
pipeline design</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Parsing</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Normalization</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Enrichment</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Routing</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Ingestion</span><br></li></ul><li style="margin-bottom:0in; line-height:normal"><span style="">Experience
developing automation using:</span><br></li><ul style="margin-top:0in"><li style="margin-bottom:0in; line-height:normal"><span style="">Python</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Bash</span><br></li></ul><li style="margin-bottom:0in; line-height:normal"><span style="">Experience
onboarding cloud, endpoint, network, identity, SaaS, Windows, Linux, and
custom application telemetry.</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Strong
knowledge of:</span><br></li><ul style="margin-top:0in"><li style="margin-bottom:0in; line-height:normal"><span style="">Enterprise
security architecture</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Incident
response</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Secure
system design</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Networking</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Identity
& Access Management</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Cybersecurity
frameworks</span><br></li></ul></ul><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style=""> </span></b><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Preferred Skills:</span></b><br></p><p class="MsoListParagraphCxSpFirst" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Excellent written
and verbal communication skills.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Strong ability to
create: Business Requirements Documents (BRD), Functional Requirements
Documents (FRD), Use Cases, Process Documentation</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Experience
gathering requirements through stakeholder interviews, policy documents,
regulations, and business rules analysis.</span><br></p><p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Knowledge of
business modeling techniques and graphical process flow tools.</span><br></p><p class="MsoListParagraphCxSpLast" style="margin-bottom:0in; text-indent:-0.25in; line-height:normal; margin-top:0px"><span class="font" style="font-family:Symbol"><span style="">·<span class="font" style="font-family:" times="" new="" roman""=""><span class="size" style="font-size:7pt; font-style:normal; font-variant:normal; font-size-adjust:none; font-weight:normal; font-stretch:normal; line-height:normal"> </span></span></span></span><span style="">Ability to
communicate effectively with: Executive management, Business users, Project
managers, Technical teams, External stakeholders</span><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Education</span></b><span style=""> <br> Bachelor's degree in Information Technology, Information Security, Computer
Science, or related field.</span></p><p style="margin:0px 0in 0in 0.25in; line-height:normal"><span style="">Eight
(8) years of relevant experience may be substituted for the degree requirement.</span><br></p><p style="margin:0px 0in 0in 0.25in; line-height:normal"><span style="">Minimum
five (5) years supporting large enterprise IT environments or system
deployments.</span><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style=""> </span></b><br></p><p style="margin-bottom:0in; line-height:normal; margin-top:0px"><b><span style="">Preferred Certifications</span></b><br></p><ul style="margin-top:0in"><li style="margin-bottom:0in; line-height:normal"><span style="">CISSP</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Security+</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">GIAC</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Palo Alto
Cortex Certification</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Cribl
Certification</span><br></li><li style="margin-bottom:0in; line-height:normal"><span style="">Other
relevant SIEM or cybersecurity certifications</span><br></li></ul><div><br></div><br>