
SIEM and Data Management Engineer – Managed Security
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Design, maintain, and enhance data management functionalities that support AHEAD’s cloud-based security analytics platforms, with a focus on Palo Alto Cortex XSIAM.
• Oversee the configuration and development processes for XSIAM data onboarding, ingestion, parsing, normalization, enrichment, and lifecycle management of data storage.
• Integrate client and internal data sources into the Managed Security SIEM utilizing APIs, syslog, agents, file collection, forwarders, cloud connectors, and additional methods.
• Create, sustain, and optimize parsers, field extractions, transformations, and normalization processes.
• Collaborate with Managed Security analysts, detection engineers, SIEM/SOAR engineering teams, and client technical personnel.
• Define data standards regarding source naming, fields, tagging, metadata, categorization, and normalization.
• Resolve issues related to data collection, transport, parsing, indexing, connectivity, mapping, and search usability.
• Oversee data tiering, storage allocation, retention strategies, index lifecycle management, storage optimization, and capacity planning.
• Evaluate data quality and integrity, focusing on completeness, timeliness, parsing accuracy, normalization coverage, duplication, and consistency.
• Enhance the efficiency of data pipelines, minimize noise, and improve search and analytics performance.
• Develop dashboards, reports, and health checks to monitor ingestion, parser quality, storage, retention compliance, and onboarding status.
• Build Python or similar-language tools to automate onboarding validations, parser checks, data quality evaluations, and platform management.
• Engage in client-facing security and technical discussions to facilitate onboarding and coordinate implementation.
• Manage the daily operations of the security data platform utilized by the Managed Security Team to support 24/7 SOC activities.
• Proven experience with Palo Alto Networks Cortex XSIAM, particularly in data onboarding, pipeline management, parsing, normalization, and data operations.
• Experience in XSIAM or SIEM administration and configuration.
• Familiarity with API integrations, syslog, agent-based collection, file shipping, cloud connectors, webhooks, and other relevant ingestion methods.
• Proficient in developing or refining parsers, field mappings, regular expressions, transformation logic, and normalization procedures.
• Knowledge of index lifecycle management, tiered storage, retention strategies, archiving, and cost-performance considerations.
• Experience in capacity planning, storage optimization, and ingestion governance within SIEM or log management systems.
• Skilled in writing automation and integration tools using Python or another programming language.
• 2–4 years of experience in Information Security, SIEM engineering, security data engineering, security operations, or related fields.
• Practical experience with firewalls, IDS, EDR, SIEM, SOAR, IAM, cloud security tools, and infrastructure platforms generating security telemetry.
• Understanding of security analysis tools and methodologies.
• Awareness of security threats, attack vectors, vulnerabilities, exploits, and associated telemetry needs.
• Strong command of regular expressions, structured and unstructured log formats, and data transformation techniques.
• Exceptional verbal and written communication abilities.
• Capable of working both independently and collaboratively within larger teams.
• Adept at functioning in a highly sensitive and confidential environment.
• Proficient in meeting deadlines and managing sensitive, high-pressure situations.
• Competent in identifying issues and formulating strategic and tactical plans.
• Good judgment and decision-making capabilities.
• Bachelor’s Degree in Computer Science, Information Security, Engineering, or a related discipline, or equivalent educational or professional experience (preferred qualifications).
• Medical, Dental, and Vision Insurance.
• 401(k) plan.
• Paid company holidays.
• Paid time off.
• Paid parental and caregiver leave.
• Opportunities for cross-department training and development.
• Sponsored certifications and credentials for ongoing education.
• Participation in diversity and inclusion groups such as Moving Women AHEAD and RISE AHEAD.
• Option to opt-out of AI application and interview reviews without penalty.
Railroad19
GFT Technologies
Get handpicked remote jobs straight to your inbox weekly.