368,746open jobs
9,444companies
47,506added this week
Browse all
Salary
$120k – $160k per year
Location
Remote (United States)
Seniority
Junior · 2+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
AHEAD helps enterprises build modern, secure, and scalable digital platforms by combining cloud, data, AI, and automation. Their consulting and managed services drive real business impact through smarter IT.

The Managed Security Team at AHEAD monitors client environments and performs incident detection, validation, and reporting. The SIEM and Data Management Engineer will be responsible for the implementation, maintenance, and continuous improvement of the data management capabilities that support our cloud-based security analytics platforms, with a primary focus on Palo Alto Cortex XSIAM, and the broader Managed Security program success across AHEAD.

This is a technical hands-on position that requires someone with a strong understanding of the needs of a 24/7 SOC (Security Operations Center). We are looking for a candidate with XSIAM, SIEM, log management, and security data engineering experience who will work closely with the Managed Security staff and other highly technical members across multiple teams, both within AHEAD and in client environments, to continuously improve and enhance AHEAD’s Managed Security data onboarding, normalization, storage, and optimization capabilities, with Palo Alto Cortex XSIAM serving as the primary platform.

Incumbents will possess strong technical and analytical skills while providing accurate analysis of security-related problems. They will have a well-rounded networking and infrastructure background and will be responsible for troubleshooting data ingestion issues, parser behavior, storage utilization, and client onboarding challenges. This individual is user focused and works to resolve client needs in a timely manner. These needs may involve onboarding new data sources, improving parsing and normalization, optimizing storage and retention strategies, and supporting the reliability and performance of the data pipelines that power Managed Security operations.

The SIEM and Data Management Engineer is responsible for the day-to-day management of the security data platform used by the Managed Security Team to monitor client environments and detect security threats, with a primary emphasis on Palo Alto Cortex XSIAM and supporting familiarity with platforms such as Elastic Security. This includes data source onboarding, ingestion pipeline configuration, parser development and tuning, normalization and enrichment, data tier and retention management, storage optimization, and standardization of security telemetry across client environments. The SIEM and Data Management Engineer is expected to be familiar with a wide range of security tools and understand core security and logging fundamentals.

Roles and Responsibilities

    Lead and perform configuration and development activities related to XSIAM data onboarding, ingestion, parsing, normalization, enrichment, and storage lifecycle management within the primary security analytics platform

    Onboard new client and internal data sources into the Managed Security SIEM environment through a variety of collection and transport methods, including API-based ingestion, syslog, agents, file-based collection, forwarders, cloud-native connectors, and other supported methods

    Develop, maintain, and tune parsers, field extractions, transformations, and normalization logic to ensure incoming telemetry is usable, consistent, and aligned to Managed Security standards

    Partner with Managed Security analysts, detection engineers, and client technical teams to define log source requirements for visibility, detection content, investigations, and reporting

    Establish and maintain data standards for source naming, field usage, tagging, metadata, categorization, and normalization across multiple client environments

    Support and optimize ingestion pipelines to ensure reliability, scale, and performance across diverse client log sources and varying data volumes

    Perform troubleshooting of data collection, transport, parser, and indexing issues, including validation of connectivity, format, mapping, field extraction, and downstream search usability

    Manage data tiering, storage allocation, retention strategies, and index lifecycle practices to ensure telemetry is retained appropriately and efficiently based on operational, contractual, and cost requirements

    Perform storage optimization and capacity planning activities within the SIEM platform to ensure ingestion remains within contracted scope while preserving the data needed for security operations and investigations

    Analyze data quality and data health across sources, including completeness, timeliness, parsing success, normalization coverage, duplication, and consistency

    Identify and implement opportunities to improve data pipeline efficiency, reduce noise, eliminate unnecessary data, and improve search and analytics performance

    Partner with SIEM, detection, and SOAR engineering resources to ensure standardized and enriched data supports dashboards, detections, automations, and incident workflows

    Build and maintain dashboards, reports, and health checks related to ingestion performance, parser quality, storage consumption, retention compliance, and onboarding progress

    Create tooling and scripts in Python or similar languages to automate onboarding checks, parser validation, data quality assessments, and platform administration tasks

    Assist with the development of processes and procedures to improve onboarding consistency, parser governance, data quality, and overall Managed Security functions

    Participate in client-facing security and technical meetings to support onboarding efforts, explain data requirements, review issues, and coordinate implementation activities

Position Requirements

    Experience with Palo Alto Networks Cortex XSIAM, with a strong emphasis on data onboarding, data pipeline management, parsing, normalization, and platform data operations; experience with Elastic Security and its components is also valuable

    XSIAM or SIEM administration and configuration experience with a strong emphasis on data onboarding, ingestion pipelines, parsing, normalization, and storage management

    Working knowledge of common log collection and transport techniques, including API integrations, syslog, agent-based collection, file shipping, cloud connectors, webhooks, and related ingestion patterns

    Experience developing or tuning parsers, field mappings, regular expressions, transformation logic, and normalization processes for security telemetry

    Understanding of data lifecycle and storage concepts such as index lifecycle management, hot-warm-cold or tiered storage, retention strategy, archive considerations, and cost-performance tradeoffs

    Experience performing capacity planning, storage optimization, and ingestion governance in SIEM or log management platforms

    Experience writing tools to automate tasks and integrate systems in Python or another language

    The ability to think creatively to find elegant solutions to complex problems

    Excellent verbal and written communication skills

    The desire to work both independently and collaboratively with a larger team

    A willingness to be challenged along with a strong appetite for learning

    2-4 years of experience in Information Security, SIEM engineering, data engineering for security operations, security operations, or related disciplines

    Hands-on experience with common security technologies such as firewalls, IDS, EDR, SIEM, SOAR, IAM, cloud security tools, and infrastructure platforms that generate operational and security telemetry

    Knowledge of common security analysis tools and techniques

    Understanding of common security threats, attack vectors, vulnerabilities, and exploits, and the types of telemetry required to support visibility into them

    Strong knowledge of regular expressions, structured and unstructured log formats, and data transformation concepts

    Customer service focused and portrays energy, professionalism, and welcoming characteristics

    Strong ability to work in a highly sensitive and confidential environment

    Ability to meet deadlines and handle sensitive and pressured situations

    Ability to identify issues and help develop strategy and tactical plans for various department initiatives

    Ability to use good judgment and decision-making skills

Prefered Qualifications

    Experience with Palo Alto Cortex XSIAM in multi-tenant Managed Security or MSSP environments

    Experience with data onboarding and normalization across a wide variety of network, endpoint, identity, cloud, and application log sources

    Familiarity with common schemas or data models used in security analytics and event standardization

    Experience supporting detection engineering and SOC operations through improved telemetry quality and consistency

    Familiarity with automation of onboarding validation, parser testing, and data health monitoring

    Education

    Bachelor’s Degree in Computer Science, Information Security, Engineering, or related/equivalent educational or work experience

    One or more of the following certifications preferred: Palo Alto Networks certifications, Elastic Certified Engineer, CISSP, GCIA, GCIH, GMON, cloud certifications, or other security/data platform related credentials

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,746 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$84k – $178k per year (Estimated) • In office • Full-Time • 10+ years exp • Wellington
Java
Python
DevOps
Ansible
AWS
Azure
CI/CD
Docker
GCP
Helm
Kubernetes
Platform Engineering
Prometheus
Service Mesh
Terraform
GitLab
IAM
Apply
Founding Engineer 1 day ago
$81k – $116k per year • In office • Full-Time • Bachelor's Degree • Munich
JavaScript
Python
TypeScript
Databases
MySQL
PostgreSQL
Frontend
Next.js
React.js
Tailwind CSS
DevOps
AWS
Azure
CI/CD
Docker
GCP
Grafana
Kubernetes
OpenTelemetry
Prometheus
Apply
$98k – $195k per year (Estimated) • In office • Full-Time • 7+ years exp • Wellington
Java
Python
SQL
Java
Spring Boot
Databases
Apache Kafka
Databricks
Neo4j
AI/ML
Flink
Spark
Frontend
GraphQL
DevOps
Azure
CI/CD
Datadog
Dynatrace
Kibana
Kubernetes
OpenShift
Platform Engineering
Splunk
Amazon ECS
Apply
$70k – $105k per year • In office • Full-Time • 3+ years exp
Python
SQL
TypeScript
AI/ML
LLM
RAG
Function Calling
LLM Guardrails
Cybersecurity
GDPR
Management
n8n
Apply
Founding Engineer 1 day ago
$93k – $140k per year • In office • Full-Time • 3+ years exp • Munich
Python
Python
FastAPI
AI/ML
Fine-tuning
LLM
VLM
Apply
$130k – $145k per year • Remote • Full-Time • 3+ years exp • Bachelor's Degree
PowerShell
Python
SQL
DevOps
AWS
Azure
FinOps
GCP
Kubernetes
Analytics
Power BI
Tableau
Management
Jira
ServiceNow
Apply
$28k – $66k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Gurgaon
DevOps
VMWare
Apply
NetSuite Developer 5 days ago
$11k – $41k per year (Estimated) • Remote • Full-Time • 3+ years exp
JavaScript
SQL
Apex
Apex
MuleSoft
Databases
Snowflake
Analytics
ETL/ELT
Marketing
Salesforce
Apply
$230k – $290k per year • Remote • Full-Time • 8+ years exp • PhD
Python
AI/ML
AI Agents
Copilot
Anthropic
LLM Guardrails
OpenAI
DevOps
Azure
Azure DevOps
Bicep
CI/CD
FinOps
GitHub Actions
Platform Engineering
Terraform
GitHub
Cybersecurity
Microsoft Entra ID
Apply
$23k – $57k per year (Estimated) • Remote • Full-Time • 8+ years exp • Bachelor's Degree • Gurgaon
PowerShell
Python
AI/ML
AWS Bedrock
Claude
Claude Code
Copilot
CrewAI
Cursor
LangChain
LangGraph
LlamaIndex
LLM
Prompt Engineering
RAG
Vertex AI
Windsurf
AI Agents
Amazon SageMaker
Devin
OpenAI
DevOps
AWS
Azure
Bicep
CI/CD
FinOps
GCP
GitOps
Kubernetes
Platform Engineering
Service Mesh
Terraform
Vector
VMWare
GitHub
Apply
See all jobs
This is one of many
368,746 more open roles from verified company boards, updated every day.