SIEM and Data Management Engineer – Managed Security

9 hours, 41 minutes ago
Full-time
Junior
DevOps and Infrastructure
AHEAD

AHEAD

AHEAD accelerates the impact of technology on clients by engineering customized data, developer, and infrastructure platforms that improve IT operations. By weaving together cloud infrastructure, intelligent operations, and modern applications, we help...

IT Services
1K-5K
$43M raised

Description

  • Configure and manage XSIAM data onboarding, ingestion, parsing, normalization, enrichment, and storage lifecycle processes.
  • Onboard client and internal data sources using APIs, syslog, agents, file collection, forwarders, cloud connectors, and webhooks.
  • Develop and tune parsers, field mappings, transformations, and normalization logic for security telemetry.
  • Partner with analysts, detection engineers, and client teams to define log source requirements.
  • Troubleshoot collection, transport, parsing, indexing, connectivity, mapping, and search usability issues.
  • Manage data tiering, retention, storage allocation, capacity planning, and ingestion governance.
  • Analyze data quality, pipeline health, parsing success, normalization coverage, duplication, and consistency.
  • Build dashboards, reports, health checks, and automation scripts for onboarding and platform administration.
  • Collaborate with SIEM, detection, and SOAR teams to support dashboards, detections, automations, and incident workflows.
  • Participate in client-facing meetings and improve onboarding, parser governance, and data quality processes.

Requirements

  • 2–4 years of experience in information security, SIEM engineering, security data engineering, security operations, or a related field.
  • Experience administering and configuring Palo Alto Cortex XSIAM, especially data onboarding, ingestion pipelines, parsing, normalization, and storage management.
  • Experience with Elastic Security is valuable.
  • Knowledge of API, syslog, agent-based, file-based, webhook, and cloud-native log collection methods.
  • Experience developing or tuning parsers, regular expressions, field mappings, transformations, and normalization processes.
  • Understanding of data lifecycle management, tiered storage, retention, archiving, and cost-performance tradeoffs.
  • Experience with capacity planning, storage optimization, and ingestion governance in SIEM or log management platforms.
  • Ability to write automation tools in Python or another programming language.
  • Hands-on familiarity with firewalls, IDS, EDR, SIEM, SOAR, IAM, cloud security, and infrastructure telemetry.
  • Bachelor’s degree in a related field or equivalent education/work experience preferred; relevant Palo Alto, Elastic, CISSP, GIAC, cloud, or security platform certifications preferred.

Benefits

  • Medical, dental, and vision insurance.
  • 401(k) plan.
  • Paid company holidays and paid time off.
  • Paid parental and caregiver leave.
  • Cross-department training and development opportunities.
  • Company-sponsored certifications and credentials.
  • Access to a multi-million-dollar technology lab.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Zero Trust Engineer (R-00205)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking Zero Trust Engineers to implement enterprise Zero Trust use cases across prioritized Department of Veterans Affairs information systems and guide them through planning, validation, testing, and operational transition.

Azure Cybersecurity
8 hours, 56 minutes ago

Pillar Lead: Device & Endpoint Specialist (R-00212)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking a Device & Endpoint Specialist to lead the Devices pillar of enterprise Zero Trust architecture, supporting implementation and integrating device posture and security signals into access decisions.

CrowdStrike Cybersecurity
9 hours, 11 minutes ago

Senior Security Operations Engineer

Included Health 1K-5K Insurance

Included Health is seeking a remote Senior Security Operations Engineer to lead DLP protection across corporate and cloud environments, investigating data security events and improving defenses against data loss.

CrowdStrike Network Security PowerShell Python SIEM Splunk SQL
9 hours, 26 minutes ago

Pillar Lead: Indentity Architect (R-00210)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking an Identity Architect to lead the Identity pillar for VA Zero Trust initiatives by defining reusable identity architecture, access models, and integration patterns across enterprise systems.

Active Directory
9 hours, 26 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers