xelys jobs xelys jobs

Security Architect Consultant SIEM Engineer

Accord Technologies Inc

full-remoteseniorcontractsecuritybackend United States 8 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Palo Alto Cortex XSIAMPalo Alto Cortex XDRSIEM EngineeringSOC OperationsCriblLog PipelinesThreat HuntingIncident ResponsePythonRBAC

About the role

Role Overview

Security Architect Consultant / SIEM Engineer (Remote, W2 Contract)

You will design, implement, administer, and optimize enterprise security monitoring and response platforms, partnering with security architects, engineers, and SOC analysts to improve detection, response, threat-hunting, automation, and platform reliability.

Responsibilities

  • Design and operate SIEM/XDR platforms
    • Deploy, configure, and maintain Palo Alto Cortex XSIAM
    • Administer and optimize Palo Alto Cortex XDR capabilities
    • Support enterprise SIEM architecture and operations
  • Multi-tenant security + access control
    • Configure multi-tenant environments and tenant-specific settings
    • Implement role-based access controls (RBAC) and data segregation
  • Detection, analytics, and tuning
    • Build detection rules, correlation rules, and analytics
    • Create threat-hunting queries, watchlists, and detection use cases
    • Tune alerts and suppression logic to reduce false positives
  • Automation + incident response workflows
    • Develop automated response workflows
    • Create playbooks for enrichment, triage, containment, and escalation
    • Support incident response, technical escalations, and SOC analyst handoffs (Tier 1–3)
  • Cribl log pipeline + telemetry onboarding
    • Design and optimize Cribl data models and log pipelines
    • Perform routing, parsing, normalization, enrichment, filtering, replay, and ingestion
    • Onboard telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows, and custom apps
    • Monitor ingestion health, availability, alert volumes, and optimize cost/retention/performance
  • Integrations + reporting + documentation
    • Integrate SIEM/XDR with ticketing/case-management tools
    • Support threat-intelligence, identity, notification, and enterprise-system integrations
    • Build dashboards, reports, and operational metrics
    • Maintain runbooks/SOPs/escalation matrices, runbooks and architecture diagrams, documentation and knowledge articles
  • Operational requirements
    • Participate in a monthly on-call rotation for a 24x7 security operations environment
    • Occasional after-hours maintenance or incident escalation support as needed

Requirements

  • Deep hands-on SIEM engineering and SOC operations experience in large-scale, multi-tenant environments
  • Strong expertise with:
    • Palo Alto Cortex XSIAM and Cortex XDR
    • Cribl and log pipelines
    • Data modeling, telemetry onboarding, and incident response
  • Experience developing security automation using Python and Bash
  • Ability to build detection rules/use cases and tune alerts/suppression logic
  • Experience with secure design principles, access controls, and cybersecurity best practices

Preferred Qualifications

  • Bachelor’s degree in IT, Information Security, or related field (or equivalent experience)
  • Certifications such as CISSP, Security+, GIAC, Palo Alto Cortex, Cribl, or related SIEM/security-platform credentials

About Accord Technologies Inc

Accord Technologies Inc is a technology services company providing consulting and engineering support for enterprise systems. The role described focuses on security monitoring, SIEM/XDR engineering, and SOC operations in large-scale environments.

Scraped 7/22/2026