Demo

IT - ADMIN - Security Architect - Consultant - SIEM Engineer

TALENT Software Services
Columbia, SC Full Time
POSTED ON 7/16/2026
AVAILABLE BEFORE 1/11/2027
Daily Duties / Responsibilities

Work Schedule

  • 100% Remote position.
  • Participate in a monthly on-call rotation supporting a 24x7 Security Operations Center (SOC) serving multiple state agencies.
  • Provide after-hours support as needed.

SIEM & XDR Administration

  • Assist in the planning, design, deployment, administration, and operational support of enterprise SIEM and XDR platforms.
  • Engineer, configure, optimize, troubleshoot, and maintain Palo Alto Cortex XSIAM and Cortex XDR environments.
  • Perform multi-tenant agency onboarding, tenant-specific configurations, role-based access control (RBAC), data segregation, dashboards, and reporting.
  • Develop and optimize:
    • Detection rules
    • Correlation rules
    • Analytics
    • Threat hunting queries
    • Watchlists
    • Alert suppression logic
    • False positive reduction strategies

Log Management & Data Pipeline Engineering

  • Assist in planning, designing, deploying, and supporting enterprise log management solutions.
  • Design and manage Cribl data pipelines, including:
    • Data modeling
    • Log routing
    • Parsing
    • Normalization
    • Enrichment
    • Filtering
    • Replay
    • Log ingestion
  • Onboard and monitor telemetry from:
    • Cloud platforms
    • Endpoint security tools
    • Network devices
    • Identity platforms
    • SaaS applications
    • Custom applications
  • Optimize log volume, retention, performance, and cost while ensuring security and compliance.

Automation & Integration

  • Develop, test, deploy, and maintain automated response workflows and playbooks.
  • Build automation for:
    • Alert enrichment
    • Incident triage
    • Containment
    • Escalation
    • Notifications
    • Case management
    • Incident response
  • Integrate SIEM/XDR platforms with:
    • Ticketing systems
    • Case management platforms
    • Identity solutions
    • Threat intelligence platforms
    • Notification systems
    • Enterprise security tools

Documentation

  • Create and maintain:
    • Operational runbooks
    • Standard Operating Procedures (SOPs)
    • Escalation matrices
    • Troubleshooting guides
    • Architecture diagrams
    • Data flow documentation
    • Security use-case catalogs
    • Analyst knowledge base articles

SOC Support

  • Support Tier 1, Tier 2, and Tier 3 SOC Analysts and Incident Responders.
  • Assist with:
    • Platform troubleshooting
    • Detection tuning
    • Threat hunting
    • Technical escalations
    • Knowledge transfer
    • Shift handoffs

Monitoring & Reporting

  • Monitor and report:
    • Log ingestion health
    • Platform availability
    • Alert volumes
    • Detection coverage
    • False positives
    • Service Level Agreements (SLAs)
    • Mean Time to Detect (MTTD)
    • Mean Time to Respond (MTTR)
    • Tenant-specific operational metrics

Platform Operations

  • Ensure:
    • High availability
    • Platform resilience
    • Backup and recovery
    • Lifecycle management
    • Controlled change management
    • Operational stability of SIEM, XDR, and log pipeline services

Collaboration

  • Work closely with:
    • Security Architects
    • Security Engineers
    • SOC Analysts
    • Incident Responders
    • Agency stakeholders
  • Align security solutions with:
    • Business objectives
    • Cybersecurity best practices
    • Regulatory compliance
    • Industry security frameworks
    • Organizational risk tolerance

Required Skills (Ranked By Importance)

  • Hands-on experience with Palo Alto Cortex XSIAM and Cortex XDR design, implementation, administration, and operational support.
  • Experience engineering and supporting SIEM platforms in multi-tenant environments and 24x7 Security Operations Centers (SOC).
  • Strong experience developing and tuning:
    • Detection rules
    • Correlation rules
    • Analytics
    • Threat hunting queries
    • Dashboards
    • Reporting
    • Alert suppression logic
  • Strong experience designing and managing complex automation playbooks.
  • Hands-on experience with Cribl:
    • Data modeling
    • Log pipeline design
    • Parsing
    • Normalization
    • Enrichment
    • Routing
    • Log ingestion
  • Experience developing automation, integrations, and response workflows using:
    • Python
    • Bash
  • Experience onboarding and troubleshooting telemetry from:
    • Cloud environments
    • Endpoint platforms
    • Network devices
    • Identity systems
    • SaaS applications
    • Linux
    • Windows
    • Custom applications
  • Strong understanding of:
    • Enterprise security architecture
    • Incident response
    • Networking
    • Access control
    • Secure system design
    • Cybersecurity frameworks

Preferred Skills

  • Hands-on experience managing Cortex XSIAM and Cortex XDR in large-scale multi-tenant environments.
  • Strong experience with Cribl Administration, data modeling, and log pipeline optimization.
  • Experience supporting Tier 1-Tier 3 SOC operations, threat hunting, incident response, and 24x7 operational handoffs.
  • Experience developing:
    • Playbooks
    • Runbooks
    • Standard Operating Procedures (SOPs)
    • Technical documentation
  • Familiarity with industry-standard security and compliance frameworks.

Required Education / Certifications

  • Bachelor's degree in Information Technology, Information Security, or a related field.
  • Eight (8) years of relevant work experience may be substituted in lieu of a bachelor's degree.
  • Minimum five (5) years of experience supporting large enterprise IT environments and/or system deployments.

Preferred Certifications

  • CISSP (Certified Information Systems Security Professional)
  • CompTIA Security
  • GIAC Certification
  • Palo Alto Cortex Certification
  • Cribl Certification
  • Other relevant SIEM or cybersecurity platform certifications.

Join our team in Columbia, SC, where you can enjoy the flexibility of a remote role while supporting a dynamic and critical 24x7 Security Operations Center. Be part of an innovative environment that values collaboration and expertise in cybersecurity.

Salary : $85 - $90

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a IT - ADMIN - Security Architect - Consultant - SIEM Engineer?

Sign up to receive alerts about other jobs on the IT - ADMIN - Security Architect - Consultant - SIEM Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$149,432 - $188,965
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at TALENT Software Services

  • TALENT Software Services Overland Park, KS
  • This is going to be a Dummy role for the Pipeline purposes only Staff Electrical Engineering Technician - Advanced Power Generation (APG) Must sit onsite a... more
  • 12 Days Ago

  • TALENT Software Services Marlborough, MA
  • Job Description: The Pre-Authorization Specialist II is responsible for performing proficient benefit verification and pre-authorization functions with ins... more
  • 12 Days Ago

  • TALENT Software Services Detroit, MI
  • Responsible for purchasing materials, services, rentals and services per the Policies and Procedures of Supply Chain Management including appropriate Terms... more
  • 12 Days Ago

  • TALENT Software Services Detroit, MI
  • The Organizational Development & Learning Consultant partners with business leaders to assess performance needs, design and develop learning solutions, and... more
  • 12 Days Ago


Not the job you're looking for? Here are some other IT - ADMIN - Security Architect - Consultant - SIEM Engineer jobs in the Columbia, SC area that may be a better fit.

  • InterSources Inc Columbia, SC
  • Title: Security Architect – Consultant (SIEM Engineer) – (12751) Location: Columbia, SC 29210100% Remote Candidate Location: Open to nationwide candidates;... more
  • 5 Days Ago

  • Syntricate Columbia, SC
  • Requisition Name: Security Architect - Consultant - SIEM Engineer Work Address – Remote Work - 100% Remote. Preference will be given to local candidates wh... more
  • 4 Days Ago

AI Assistant is available now!

Feel free to start your new journey!