
Principal Consultant – SIEM
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in Canada.
• Collaborate with clients to define business, security operations, and detection needs, translating these into SIEM use cases, architectures, and operational frameworks.
• Design and validate SIEM solutions to achieve objectives related to risk reduction, visibility, and detection engineering.
• Oversee the design, deployment, migration, and optimization of SIEM platforms, including Google SecOps, Microsoft Sentinel, CrowdStrike NG-SIEM, and Palo Alto XSIAM.
• Support SIEM and SOC transformation engagement strategies focusing on detection, response, and analytics.
• Evaluate SIEM, logging, and security analytics technologies in relation to business needs, risk posture, budget constraints, and operational maturity.
• Act as a specialist in SIEM architecture, log onboarding, detection engineering, UEBA, SOAR integration, and SOC operations.
• Mentor consultants on intricate SIEM initiatives, offering technical guidance and quality assurance.
• Present to large technical and executive groups while addressing challenging technical and strategic queries.
• Tailor SIEM delivery approaches according to client maturity, platform capabilities, and operational limitations.
• Stay informed about the wider cybersecurity, SOC, and security analytics technology ecosystem.
• Participate in industry forums, contribute to thought leadership projects, and author whitepapers or publications related to SIEM, SOC, or security operations.
• Bachelor’s degree and approximately 10–15 years of relevant experience in information security or technology consulting.
• Around 8–10 years of hands-on experience in security architecture focused on SIEM and security operations platforms.
• In-depth knowledge of log collection and normalization, detection engineering, alerting strategies, content lifecycle management, SOC workflows, and SOAR/EDR integration.
• Practical experience with contemporary SIEM platforms such as Google SecOps, Microsoft Sentinel, CrowdStrike NG-SIEM, and Palo Alto XSIAM.
• Familiarity with incident response, threat detection, vulnerability management, data classification, and security governance.
• Insight into professional services and the organizational ramifications of technical and delivery decisions.
• Proficiency in TCP/IP, OSI model, Windows, Linux/UNIX, cloud platforms, EDR, NDR, firewalls, and IDS/IPS.
• Knowledge of KQL, Python, PowerShell, and YAML.
• Understanding of PCI DSS, GLBA, GDPR, and U.S. state privacy regulations.
• Experience integrating SIEM platforms into complex enterprise and cloud infrastructures, including log pipelines, APIs, and security tooling ecosystems.
• Willingness to travel as necessary to fulfill client requirements.
• A valid U.S. driver’s license and a valid passport are required.
• Must hold or be willing to pursue certifications such as CISSP, CISM, CISA, or SIEM-specific platform certifications.
• Strong interpersonal, leadership, client-facing, written, and presentation skills.
• Ability to convey complex SIEM and SOC concepts to both technical and executive audiences.
• High level of integrity and confidentiality.
• A company dedicated to our inclusive values through our Employee Resource Groups.
• Work/life balance.
• Access to professional training resources.
• Opportunities for creative problem-solving and tackling unique, complex projects.
• Volunteer opportunities available.
• "Optiv Chips In" initiative encourages employees to volunteer and connect with their teams and communities.
• The necessary tools and technology for productive remote work (where applicable).
Sprout Social, Inc.
Premier Inc.
Devoir Software Solutions
Get handpicked remote jobs straight to your inbox weekly.