Security Architect Consultant SIEM Engineer
Accord Technologies Inc
full-remoteseniorcontractsecuritybackend United States 8 days ago via LinkedIn
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
Palo Alto Cortex XSIAMPalo Alto Cortex XDRSIEM EngineeringSOC OperationsCriblLog PipelinesThreat HuntingIncident ResponsePythonRBAC
About the role
Role Overview
Security Architect Consultant / SIEM Engineer (Remote, W2 Contract)
You will design, implement, administer, and optimize enterprise security monitoring and response platforms, partnering with security architects, engineers, and SOC analysts to improve detection, response, threat-hunting, automation, and platform reliability.
Responsibilities
- Design and operate SIEM/XDR platforms
- Deploy, configure, and maintain Palo Alto Cortex XSIAM
- Administer and optimize Palo Alto Cortex XDR capabilities
- Support enterprise SIEM architecture and operations
- Multi-tenant security + access control
- Configure multi-tenant environments and tenant-specific settings
- Implement role-based access controls (RBAC) and data segregation
- Detection, analytics, and tuning
- Build detection rules, correlation rules, and analytics
- Create threat-hunting queries, watchlists, and detection use cases
- Tune alerts and suppression logic to reduce false positives
- Automation + incident response workflows
- Develop automated response workflows
- Create playbooks for enrichment, triage, containment, and escalation
- Support incident response, technical escalations, and SOC analyst handoffs (Tier 1–3)
- Cribl log pipeline + telemetry onboarding
- Design and optimize Cribl data models and log pipelines
- Perform routing, parsing, normalization, enrichment, filtering, replay, and ingestion
- Onboard telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, and custom apps
- Monitor ingestion health, availability, alert volumes, and optimize cost/retention/performance
- Integrations + reporting + documentation
- Integrate SIEM/XDR with ticketing/case-management tools
- Support threat-intelligence, identity, notification, and enterprise-system integrations
- Build dashboards, reports, and operational metrics
- Maintain runbooks/SOPs/escalation matrices, runbooks and architecture diagrams, documentation and knowledge articles
- Operational requirements
- Participate in a monthly on-call rotation for a 24x7 security operations environment
- Occasional after-hours maintenance or incident escalation support as needed
Requirements
- Deep hands-on SIEM engineering and SOC operations experience in large-scale, multi-tenant environments
- Strong expertise with:
- Palo Alto Cortex XSIAM and Cortex XDR
- Cribl and log pipelines
- Data modeling, telemetry onboarding, and incident response
- Experience developing security automation using Python and Bash
- Ability to build detection rules/use cases and tune alerts/suppression logic
- Experience with secure design principles, access controls, and cybersecurity best practices
Preferred Qualifications
- Bachelor’s degree in IT, Information Security, or related field (or equivalent experience)
- Certifications such as CISSP, Security+, GIAC, Palo Alto Cortex, Cribl, or related SIEM/security-platform credentials
About Accord Technologies Inc
Accord Technologies Inc is a technology services company providing consulting and engineering support for enterprise systems. The role described focuses on security monitoring, SIEM/XDR engineering, and SOC operations in large-scale environments.
Scraped 7/22/2026