Security Architect (Remote)

TM Floyd and Company

$145K — $160K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years supporting large IT environments/system deployments
  • Expertise in Palo Alto Cortex, XSIAM, Cortex XDR management
  • Experience engineering SIEM for multi-tenant and 24x7 SOC operations
  • Skilled in developing and tuning detection rules and threat-hunting queries
  • Proficient in CRIBL for log data management and processing
  • Strong scripting skills in Python and Bash for automation
  • Comprehensive knowledge of enterprise security architecture and compliance frameworks

Responsibilities

  • Plan and design enterprise SIEM and XDR capabilities
  • Deploy and support log management and security data pipelines
  • Develop and maintain automated response workflows and playbooks
  • Create operational guidelines, runbooks, and documentation
  • Support SOC analysts and incident response teams

Benefits

  • Generous array of benefits based on assignment length
  • Referral bonus of up to $1,000
Full Job Description
We're looking for a Security Architect for a remote role.

Skills & Qualifications:
  • 5 years of experience supporting large IT environments and/or system deployments
  • Experience with:
    • Palo Alto Cortex, XSIAM, and Cortex XDR design, implementation, administration, and operational support
    • Engineering and supporting SIEM capabilities for multi-tenant environments and 24x7 Security Operations Center operations
    • Developing and tuning detections, correlation rules, analytics, threat-hunting queries, dashboards, reporting and alert suppression logic
    • Creating and managing complex playbooks
    • CRIBL data modeling, log pipeline design, parsing, normalization, enrichment, routing and ingestion
    • Developing automation, integrations, playbooks and response workflows using scripting languages such as Python and Bash
    • Onboarding and troubleshooting telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, and custom application sources
  • Strong understanding of enterprise security architecture, incident response, networking, access control, secure system design and industry-standard cybersecurity frameworks

Preferred Skills:
  • CISSP, Security, or GIAC certification
  • Palo Alto Cortex, Cribl, or other relevant SIEM/security platform certification
  • Hands-on experience operating Cortex XSIAM and Cortex XDR in a large, multi-tenant environment
  • Hands-on Cribl administration, data modeling and log pipeline optimization experience
  • Experience supporting Tier 1 through Tier 3 SOC analysts, threat hunting, incident response and 24x7 operational handoffs
  • Familiarity with industry-standard security and compliance frameworks and experience developing playbooks, runbooks, procedures, and technical documentation

Key Responsibilities:
  • Assist in planning, design, deployment, administration, and operational support of enterprise SIEM and XDR capabilities
  • Assist in planning, design, deployment, and operational support of log management and security data pipelines
  • Develop, test, deploy, and maintain automated response workflows and playbooks
  • Create and maintain operational runbooks, SOPs, escalation matrices, troubleshooting guides, architecture diagrams, data-flow documentation, use-case catalogs, and analyst knowledge articles
  • Support Tier 1 through Tier 3 SOC analysts and incident responders

Education/Certifications:
  • Bachelor's degree in an Information Technology or Information Security-related field; 8 years of relevant work experience may be substituted in lieu of education

The salary range for this position is $145,000 - $160,000.

We offer a generous array of benefits, depending on the length of assignment. We also offer a referral bonus of up to $1,000. Ask us for more details!

Similar Jobs

More Jobs at TM Floyd and Company

More Information Technology Jobs

Find similar Security Architect (Remote) jobs: