What are the responsibilities and job description for the SIEM Engineer position at Core Technology Solutions?
Seeking an experienced SIEM Engineer for long term contract opportunity. It is a new Engineering role directly supporting SIEM Architecture and 24x7 SOC Operations. This is a remote position, however the candidate will need to be in a commutable distance to Columbia, SC. This is a W2 position, no c2c candidates will be considered.
Scope of the Project:
THIS POSITION WILL SERVE AS A SIEM ENGINEER WITHIN THE DIVISION OF INFORMATION SECURITY. THE SUCCESSFUL CANDIDATE WILL SHOW EXTENSIVE EXPERIENCE SUCCESSFULLY DESIGNING, IMPLEMENTING, MAINTAINING AND OPTIMIZING PALO ALTO CORTEX XSIAM
AND CORTEX XDR IN LARGE-SCALE, MULTI-TENANT SECURITY ENVIRONMENTS. THIS CANDIDATE WILL WORK WITH A LARGE ENTERPRISE SECURITY TEAM AND A 24X7 SECURITY OPERATIONS CENTER (SOC), ASSISTING FULL-TIME SECURITY ARCHITECTS, ENGINEERS AND ANALYSTS WITH THE DESIGN, IMPLEMENTATION, INTEGRATION AND CONTINUOUS IMPROVEMENT OF SIEM, XDR, DETECTION AND RESPONSE CAPABILITIES SUPPORTING MULTIPLE STATE AGENCIES.
What You Will Do In This Role:
CANDIDATE WILL BE PRIMARILY FOCUSED ON CORTEX XSIAM AND CORTEX XDR ENGINEERING, ADMINISTRATION, DETECTION CONTENT, AUTOMATION AND OPERATIONAL SUPPORT WHILE ALSO PROVIDING IMPORTANT SECONDARY SUPPORT FOR CRIBL DATA MODELING, LOG PIPELINE DESIGN, PARSING, NORMALIZATION, ENRICHMENT AND INGESTION. THE ROLE REQUIRES HANDS-ON EXPERIENCE SUPPORTING BOTH SECURITY ENGINEERING AND SOC OPERATIONS, INCLUDING MULTI-TENANT ONBOARDING, TENANT-SPECIFIC CONFIGURATIONS, ACCESS CONTROLS, DATA SEPARATION, INTEGRATIONS, DASHBOARDS, REPORTING, INCIDENT RESPONSE, THREAT HUNTING, PLAYBOOKS, RUNBOOKS, STANDARD OPERATING PROCEDURES AND ANALYST ENABLEMENT. THE CANDIDATE MUST BE ABLE TO SUPPORT STRATEGIC.
Required Experience:
- HANDS-ON PALO ALTO CORTEX XSIAM AND CORTEX XDR DESIGN, IMPLEMENTATION, ADMINISTRATION AND OPERATIONAL SUPPORT.
- CRIBL DATA MODELING, LOG PIPELINE DESIGN, PARSING, NORMALIZATION, ENRICHMENT, ROUTING AND INGESTION.
- Experience engineering and supporting SIEM capabilities for multi-tenant environments and 24x7 Security Operations Center operations.
- Experience developing and tuning detections, correlation rules, analytics, threat-hunting queries, dashboards, reporting and alert suppression logic.
- Strong experience creating and managing complex playbooks.
- Experience developing automation, integrations, playbooks and response workflows using scripting languages such as Python and Bash.
- Experience onboarding and troubleshooting telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows and custom application sources.
- Strong understanding of enterprise security architecture, incident response, networking, access control, secure system design and industry- standard cybersecurity frameworks.
Preferred Experience:
- HANDS-ON EXPERIENCE OPERATING CORTEX XSIAM AND CORTEX XDR IN A LARGE, MULTI-TENANT ENVIRONMENT.
Required Education:
- BACHELOR'S DEGREE IN AN INFORMATION TECHNOLOGY OR INFORMATION SECURITY RELATED FIELD