2 open positions available
Design, implement, and support Palo Alto Cortex XSIAM and Cortex XDR platforms in a multi-tenant 24x7 SOC environment. | Extensive hands-on experience with Palo Alto Cortex XSIAM/XDR, SIEM in multi-tenant environments, detection tuning, automation, and SOC operations with a bachelor's degree or equivalent experience. | Title:Palo Alto Cortex XSIAM Consultant- W2 Only Location:Remote Length:Long term Restriction:w2 only Description: • ** no c2c * *** W2 only;Webcam interview***Remote*** Job Description Scope This position will serve as a SIEM engineer. The successful candidate will show extensive experience successfully designing, implementing, maintaining and optimizing Palo Alto Cortex XSIAM and Cortex XDR in large-scale, multi-tenant security environments. This contractor will work with a large enterprise security team and a 24x7 Security Operations Center (SOC), assisting full-time security architects, engineers and analysts with the design, implementation, integration and continuous improvement of SIEM, XDR, detection and response capabilities supporting multiple state agencies. Successful Candidate This contractor will be primarily focused on Cortex XSIAM and Cortex XDR engineering, administration, detection content, automation and operational support while also providing important secondary support for Cribl data modeling, log pipeline design, parsing, normalization, enrichment and ingestion. The role requires hands-on experience supporting both security engineering and SOC operations, including multi-tenant onboarding, tenant-specific configurations, access controls, data separation, integrations, dashboards, reporting, incident response, threat hunting, playbooks, runbooks, standard operating procedures and analyst enablement. The candidate must be able to support strategic planning, solution design, implementation, troubleshooting, performance optimization and continuous improvement of secure systems and services. Daily Duties / Responsibilities This position is 100% remote and will participate in a monthly on-call rotation supporting a 24x7 Security Operations Center serving multiple state agencies. Other after-hours work may be required as needed. • Primarily assist in the planning, design, deployment, administration and operational support of enterprise SIEM and XDR capabilities, including: • Palo Alto Cortex XSIAM and Cortex XDR platform engineering, configuration, optimization and troubleshooting • Multi-tenant agency onboarding, tenant-specific configuration, role-based access, data segregation, dashboards and reporting • Detection engineering, correlation rules, analytics, threat-hunting queries, watchlists, suppression logic and false-positive reduction • Secondarily assist in the planning, design, deployment and operational support of log management and security data pipelines, including: • Cribl data modeling, log pipeline design, routing, parsing, normalization, enrichment, filtering, replay and ingestion • Onboarding and health monitoring of cloud, endpoint, network, identity, SaaS and custom application telemetry • Log volume, retention, performance and cost optimization while maintaining security and compliance requirements • Integrations with ticketing, case management, notification, identity, threat intelligence and other enterprise systems as needed • Develop, test, deploy and maintain automated response workflows and playbooks for enrichment, triage, containment, escalation, notifications, case management and incident response. • Create and maintain operational runbooks, standard operating procedures, escalation matrices, troubleshooting guides, architecture diagrams, data-flow documentation, use-case catalogs and analyst knowledge articles. • Support Tier 1 through Tier 3 SOC analysts and incident responders through platform troubleshooting, detection tuning, threat hunting, technical escalation, knowledge transfer and shift handoffs. • Monitor and report on ingestion health, platform availability, alert volumes, detection coverage, false positives, service levels, mean time to detect, mean time to respond and tenant-specific operational metrics. • Ensure high availability, resilience, backup, recovery, lifecycle management and controlled change processes for SIEM, XDR and supporting log pipeline services. • Collaborate with security architects, engineers, analysts and agency stakeholders to align solutions with business goals, industry-standard frameworks, regulatory requirements and organizational risk tolerance. Required Skills (Rank in Order of Importance) • Hands-on Palo Alto Cortex XSIAM and Cortex XDR design, implementation, administration and operational support. • Experience engineering and supporting SIEM capabilities for multi-tenant environments and 24x7 Security Operations Center operations. • Experience developing and tuning detections, correlation rules, analytics, threat-hunting queries, dashboards, reporting and alert suppression logic. • Strong experience creating and managing complex playbooks. • Cribl data modeling, log pipeline design, parsing, normalization, enrichment, routing and ingestion. • Experience developing automation, integrations, playbooks and response workflows using scripting languages such as Python and Bash. • Experience onboarding and troubleshooting telemetry from cloud, endpoint, network, identity, SaaS, Linux, Windows and custom application sources. • Strong understanding of enterprise security architecture, incident response, networking, access control, secure system design and industry-standard cybersecurity frameworks. Preferred Skills (Rank in Order of Importance) • Hands-on experience operating Cortex XSIAM and Cortex XDR in a large, multi-tenant environment. • Hands-on Cribl administration, data modeling and log pipeline optimization experience. • Experience supporting Tier 1 through Tier 3 SOC analysts, threat hunting, incident response and 24x7 operational handoffs. • Familiarity with industry-standard security and compliance frameworks and experience developing playbooks, runbooks, procedures and technical documentation. Required Education/Certifications • Bachelor''s degree in an Information Technology or Information Security related field. • Eight years of relevant work experience may be substituted in lieu of education. • Five years of experience in supporting large IT environments and/or system deployments preferred. Preferred Education/Certifications • CISSP, Security+ or GIAC certification. • Palo Alto Cortex, Cribl or other relevant SIEM/security platform certification.
Manage and administer FileCloud and AWS GovCloud infrastructure including VDI, provide technical support, and ensure system security and compliance. | Requires extensive experience with FileCloud administration, AWS infrastructure, system security, patching, and strong communication skills. | Title:FileCloud Administrator Location:RemoteLength:Long term Restriction:w2 or c2c Description: • **WebCam Interview*** Very long term project; Initial PO till for 1 year - expect to go for 3+ years ***Remote*** Job Description This role serves as the primary administrator for the DIAL AWS GovCloud environment, overseeing essential platforms such as AMANDA, FileCloud, and the DIAL Virtual Desktop Infrastructure (VDI). In addition to managing these cloud-based systems, the position is responsible for FileCloud administration, delivering comprehensive technical support to all FileCloud users. By maintaining these critical environments, they help ensure reliable operations and seamless user experiences across the organization. The Iowa Department of Management (DOM) is seeking a skilled Infrastructure Technical Specialist (ITS) with expertise with AWS, AWS VDI and FileCloud. This role is responsible for cloud infrastructure management, monitoring, security and compliance, collaboration and support, and deployment. Required Skill Set Demonstrated through prior experience the ability to: • FileCloud administrator for handling staff onboarding, troubleshooting issues, and providing technical support to users. • Manage AWS infrastructure for VDI. • Knowledge of advanced system security methods and techniques. • Complete assigned tasks, provide clear status updates, adhere to quality standards, and work collaboratively. • Handle on-call nightly and weekend patching, upgrades, and troubleshooting. • Excellent verbal and written communication skills are essential for effectively collaborating with multiple teams. • Work independently with little supervision or guidance. • Exhibit initiative by proactively learning new systems, processes, and aspects of business functionality independently. Requirements • Broad experience with cloud adoption, including application readiness assessment, prototyping of new environments, server builds, data migration. • Experience as an enterprise systems administrator in a client or server environment, including deployment automation tools. • Experience in a customer-facing capacity, support, or consulting role. • Experience with cloud service provider offerings like Microsoft Azure or Amazon Web Services (AWS) or Google Cloud Platform (Google Cloud Platform). • Experience with design and implementation of distributed systems architecture on private or public cloud infrastructure. • Experience with troubleshooting very complex distributed environments pertaining to connectivity & app performance and monitoring tools & offering. • Experience working with cloud platforms. • Extensive knowledge of systems including Hardware, software, networking, and storage. • High-level strategic planning & advice to an entity that will allow for the successful adoption or migration of Cloud-based technologies or services. • Performance tuning of cloud environments. • Robust proficiency in Windows, Linux & CLI with 1-2 years of experience in VM infrastructure. • Strong written and oral communication skills. • Technical knowledge of infrastructure components such as Network, Storage, Linux/Windows, Application knowledge of Java, .Net, and IT security. Skills/Requirements • FileCloud Administration experience handling staff onboarding, troubleshooting issues & providing technical support to users. Required 8 Years • Demonstrated through prior experience the Ability to Manage AWS infrastructure for VDI. Required 5 Years • Demonstrated through prior experience the Ability to Manage AWS infrastructure supporting business applications. Required 5 Years • Demonstrated through prior experience the Knowledge of advanced system security methods and techniques. Required 5 Years • Demonstrated through prior experience the ability to Complete assigned tasks, provide clear status updates, adhere to quality standards & work collabo Required 5 Years • Demonstrated through prior experience the ability to Handle on-call nightly and weekend patching, upgrades, and troubleshooting. Required 5 Years • Excellent verbal and written communication skills are essential for effectively collaborating with multiple teams. Required 5 Years • Work independently with little supervision or guidance. Required 5 Years • Exhibit initiative by proactively learning new systems, processes, and aspects of business functionality independently. Required 5 Years
Create tailored applications specifically for MSYS Inc. with our AI-powered resume builder
Get Started for Free