远程工作雷达

SIEM 工程师 - 合同制 - 远程 (如需可现场在 SC)

SIEM Engineer - Contract - Remote (Onsite in SC if required)

开发工程限定地区(需当地身份)
公司SUNSHINE ENTERPRISE USA LLC
薪资未公开
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Contractor
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

职位名称:SIEM 工程师
地点:100% 远程办公。优先考虑可按需到办公室参加客户和部门会议、培训及其他现场活动的本地候选人。
面试流程:1-2 轮虚拟面试。现场面试优先。
时长:12 个月
雇佣类型:合同制
经验要求:10 年以上

候选人所在地:不要求南卡罗来纳州居民。面向全国候选人。所有现场工作的差旅费用由资源方承担,无论现场工作频率如何。

项目范围:
我们正在寻找一位经验丰富的安全架构顾问 – SIEM 工程师,以支持行政部的信息安全分部。该职位专注于在大规模、多租户企业安全环境中设计、实施、管理、优化和操作 Palo Alto Cortex XSIAM 和 Cortex XDR。
成功候选人将与企业安全架构师、工程师以及 24x7 安全运营中心(SOC)团队合作,提升多个州机构的 SIEM、XDR、检测工程、自动化、事件响应和安全监控能力。该职位还为 Cribl 数据管道、日志管理和遥测接入提供次要支持。

关键职责:
· 设计、实施、配置和维护 Palo Alto Cortex XSIAM 和 Cortex XDR 平台。
· 支持多租户 SIEM 环境,包括租户接入、基于角色的访问、数据隔离、仪表板和报告。
· 开发和优化:检测规则、关联规则、分析、威胁狩猎查询、警报列表、告警抑制逻辑
· 设计和管理 Cribl 日志管道,包括:数据建模、解析、标准化、增强、路由、过滤、重放、日志采集
· 集成来自云、端点、网络、身份、SaaS、Linux、Windows 和自定义应用的遥测数据。
· 使用 Python 和 Bash 开发和维护自动化剧本和响应工作流。
· 支持事件响应、威胁狩猎和 SOC 运营。
· 创建和维护:操作手册、标准操作程序、架构图、数据流文档、知识文章
· 通过故障排除、调优和知识传递支持 Tier1–Tier3 SOC 分析员。
· 监控 SIEM 健康状况、采集、可用性、检测覆盖率、误报、MTTD、MTTR 和运营指标。
· 确保平台的弹性、备份、恢复、生命周期管理。

查看英文原文

Job Title: SIEM Engineer
Location:100%Remote. Preference will be given to local candidates who can come to the officeas needed for client and departmental meetings, trainings, and other onsiteactivities.
Interview Process:1-2 Rounds of Virtual Interviews. In personavailability for interviews preferred.
Duration:12 Months
Employment Type: Contract
Experience Required: 10+ Years

Candidatelocation: No South Carolina residency required. Open to nationwidecandidates. All travel-related costs for onsite work will be the responsibilityof the resource no matter the frequency of onsite work.

Project Scope:
We are seeking an experienced SecurityArchitect Consultant – SIEM Engineer to support the Department ofAdministration's Division of Information Security. This role is focused on thedesign, implementation, administration, optimization, and operational supportof Palo Alto Cortex XSIAM and Cortex XDR in a large-scale,multi-tenant enterprise security environment.
The successful candidate will work alongsideenterprise security architects, engineers, and a 24x7 Security OperationsCenter (SOC) team to enhance SIEM, XDR, detection engineering, automation,incident response, and security monitoring capabilities across multiple stateagencies. This role also provides secondary support for Cribl datapipelines, log management, and telemetry onboarding.
Key Responsibilities:
·Design,implement, configure, and maintain Palo Alto Cortex XSIAM and CortexXDR platforms.
·Supportmulti-tenant SIEM environments, including tenant onboarding, role-based access,data segregation, dashboards, and reporting.
·Develop andoptimize: Detection rules, Correlation rules, Analytics, Threat hunting queries,Watchlists, Alert suppression logic
·Design and manage Cribl log pipelines, including: Data modeling, Parsing, Normalization, Enrichment,Routing, Filtering, Replay, Log ingestion
·Integratetelemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, andcustom applications.
·Develop andmaintain automated playbooks and response workflows using Python and Bash.
·Support incidentresponse, threat hunting, and SOC operations.
·Create andmaintain: Runbooks, SOPs, Architecture diagrams, Data flow documentation, Knowledgearticles
·Support Tier1–Tier 3 SOC analysts through troubleshooting, tuning, and knowledge transfer.
·Monitor SIEMhealth, ingestion, availability, detection coverage, false positives, MTTD,MTTR, and operational metrics.
·Ensure platformresilience, backup, recovery, lifecycle management, and change control.
·Collaborate withsecurity architects, engineers, analysts, and business stakeholders to improveenterprise security capabilities.
Required Skills & Experience:

  • Hands-on experience with Palo Alto Cortex XSIAM and Cortex XDR architecture, implementation, administration, and operational support.
  • Experience supporting enterprise SIEM platforms within large multi-tenant environments.
  • Experience supporting 24x7 Security Operations Centers (SOC).
  • Strong detection engineering experience including:
  • Correlation rules
  • Threat hunting
  • Analytics
  • Dashboards
  • Alert tuning
  • False-positive reduction
  • Hands-on Cribl administration including:
  • Data modeling
  • Log pipeline design
  • Parsing
  • Normalization
  • Enrichment
  • Routing
  • Ingestion
  • Experience developing automation using:
  • Python
  • Bash
  • Experience onboarding cloud, endpoint, network, identity, SaaS, Windows, Linux, and custom application telemetry.
  • Strong knowledge of:
  • Enterprise security architecture
  • Incident response
  • Secure system design
  • Networking
  • Identity & Access Management
  • Cybersecurity frameworks

Preferred Skills:
·Excellent writtenand verbal communication skills.
·Strong ability tocreate: Business Requirements Documents (BRD), Functional RequirementsDocuments (FRD), Use Cases, Process Documentation
·Experiencegathering requirements through stakeholder interviews, policy documents,regulations, and business rules analysis.
·Knowledge ofbusiness modeling techniques and graphical process flow tools.
·Ability tocommunicate effectively with: Executive management, Business users, Projectmanagers, Technical teams, External stakeholders
Education
Bachelor's degree in Information Technology, Information Security, ComputerScience, or related field.
Eight(8) years of relevant experience may be substituted for the degree requirement.
Minimumfive (5) years supporting large enterprise IT environments or systemdeployments.
Preferred Certifications

  • CISSP
  • Security+
  • GIAC
  • Palo Alto Cortex Certification
  • Cribl Certification
  • Other relevant SIEM or cybersecurity certifications

Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

LIHTC开发顾问 - 远程

SUNSHINE ENTERPRISE USA LLCUnited StatesFull Time6 天前
职能支持限定地区(需当地身份)

← 返回全部职位