Senior SIEMSOAR Architect

BAA CONSULTING

Richmond (VA)

On-site

USD 140,000 - 180,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

401(k)
Employee discounts
Health insurance
Paid time off
Competitive salary

Job summary

BAA Consulting is seeking a talented and driven Senior SIEM/SOAR Architect to join our growing cybersecurity team in Richmond, VA. In this high-impact role, you will design, architect, deploy, configure, and optimize advanced SIEM and SOAR solutions for enterprise and Federal clients.

The role emphasizes threat detection engineering, automation, and integrations with security tools, threat feeds, and APIs, while guiding junior engineers and coordinating with SOC teams.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related field.
  • 5+ years in hands-on SIEM/SOAR design, deployment, and operations for enterprise security.

Responsibilities

  • Architect and deploy enterprise SIEM/SOAR platforms focusing on Microsoft Sentinel.
  • Design data ingestion, retention, correlation, and security monitoring capabilities.
  • Develop and tune analytics rules, playbooks, and automated incident responses.
  • Lead detection engineering, log source onboarding, and use case optimization.
  • Support Federal logging requirements and collaborate with SOC teams to reduce MTTD/MTTR.
  • Mentor junior engineers and communicate complex security concepts to stakeholders.

Skills

SIEM/SOAR
Microsoft Sentinel
Automation
Threat detection

Education

Bachelor's degree in Cybersecurity

Tools

Microsoft Sentinel
Splunk
IBM QRadar
Palo Alto Cortex XSOAR
ServiceNow Security Operations
Azure

Job description

Benefits:
  • 401(k)
  • Employee discounts
  • Health insurance
  • Paid time off
  • Competitive salary
About the Role

BAA Consulting is seeking a talented and driven Senior SIEM/SOAR Architect to join our growing cybersecurity team in Richmond, VA. In this high-impact role, you will design, architect, deploy, configure, and optimize advanced Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solutions for enterprise and Federal clients.

Responsibilities
  • Architect, deploy, configure, and optimize enterprise SIEM and SOAR platforms, with a strong emphasis on Microsoft Sentinel
  • Lead the design and implementation of SIEM/SOAR architectures, including log ingestion, data connectors, data normalization, retention strategies, and security monitoring capabilities
  • Develop, configure, and operationally tune Microsoft Sentinel analytics rules, workbooks, automation rules, playbooks, and detection use cases
  • Develop and tune correlation rules, playbooks, and automated incident response workflows
  • Lead threat detection engineering efforts, including use case development, log source onboarding, and detection optimization
  • Support and implement Federal cybersecurity logging and monitoring requirements, including OMB M-21-31 EL2 requirements or equivalent Federal logging maturity standards
  • Collaborate with SOC and cybersecurity operations teams to improve incident response processes and reduce mean time to detect (MTTD) and mean time to respond (MTTR)
  • Conduct security assessments and provide strategic and technical recommendations for SIEM/SOAR architecture and operational improvements
  • Integrate threat intelligence feeds, security tools, APIs, and third-party technologies into automated SOAR workflows
  • Develop automation using scripting and orchestration technologies to improve security operations efficiency
  • Mentor junior engineers and serve as a senior technical subject matter expert (SME) on SIEM, SOAR, security operations, and detection engineering technologies
  • Communicate complex technical security concepts and recommendations to technical and non-technical stakeholders
Required Qualifications

Candidates must meet the following minimum qualifications:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a closely related field
  • Four (4) additional years of relevant specialized hands-on experience may be considered in lieu of a qualifying bachelor's degree
  • Five (5) or more years of hands-on SIEM and/or SOAR experience involving the design, implementation, configuration, administration, engineering, or operational support of enterprise security operations platforms
  • At least two (2) years of direct, hands-on Microsoft Sentinel experience, including:
    • Architecture and solution design
    • Deployment and implementation
    • Configuration and administration
    • Log source and data connector integration
    • Analytics rule and detection engineering
    • Automation and orchestration
    • Operational tuning and optimization
  • Demonstrated experience supporting OMB Memorandum M-21-31 Event Logging Maturity Level 2 (EL2) requirements, or equivalent Federal cybersecurity logging, monitoring, and logging maturity requirements
  • Active certification in at the time of offer:
    • Microsoft Certified: Cybersecurity Architect Expert (SC-100)
    • Microsoft Certified: Security Operations Analyst Associate (SC-200)
    • Certified Information Systems Security Professional (CISSP)
  • Strong experience with SIEM/SOAR architecture, log management, security event correlation, data normalization, and security telemetry
  • Experience developing and tuning security detection use cases, correlation rules, and automated response workflows
  • Strong understanding of cybersecurity frameworks and methodologies, including MITRE ATT&CK, NIST Cybersecurity Framework, NIST guidance, and the Cyber Kill Chain
  • Experience integrating security tools, threat intelligence feeds, APIs, and third-party technologies into SIEM/SOAR environments
  • Proficiency in one or more scripting or automation languages, such as Python, PowerShell, or Bash
  • Excellent written and verbal communication skills, including the ability to present complex security concepts to technical and non-technical stakeholders
Preferred Qualifications
  • Experience supporting Federal government cybersecurity, SOC, or enterprise security operations environments
  • Experience implementing Federal logging, monitoring, and cybersecurity requirements
  • Experience with additional SIEM/SOAR platforms such as Splunk, IBM QRadar, Palo Alto Cortex XSOAR, Splunk SOAR, or ServiceNow Security Operations
  • Experience designing cloud-based security operations architectures in Microsoft Azure or other major cloud environments
  • Active security clearance or the ability to obtain and maintain one
About Us

BAA Consulting is a trusted cybersecurity and technology consulting firm dedicated to delivering innovative, mission-driven solutions to clients across the public and private sectors. Our clients rely on us for our deep expertise, integrity, and commitment to excellence in every engagement.

At BAA Consulting, our team members enjoy a collaborative culture, challenging work, and the opportunity to make a meaningful impact in the ever-evolving cybersecurity landscape.

This is a remote position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SIEM/SOAR Architect — Remote (Microsoft Sentinel)
Senior SIEM/SOAR Architect — Remote (Microsoft Sentinel)

BAA CONSULTING • Richmond (VA)

On-site
USD 140,000 - 180,000
401(k)
Employee discounts
Health insurance
+2
Splunk SOAR Administrator
Splunk SOAR Administrator

G2IT, LLC. • Suitland (MD)

On-site
USD 130,000 - 190,000
Microsoft Sentinel Security Platform Engineer
Microsoft Sentinel Security Platform Engineer

Allied Consultants, Inc. • Austin (TX)

On-site
USD 120,000 - 190,000
Highly competitive pay rates
Medical insurance
401(k) plan with company match
+1
Software Developer - Microsoft Sentinel
Software Developer - Microsoft Sentinel

Cyberobotix • Austin (TX)

On-site
USD 90,000 - 120,000
Competitive salary
Flexible work environment
SOAR Engineer
SOAR Engineer

IQUASAR LLC • St. Louis (MO)

On-site
USD 120,000 - 170,000
401(k)
401(k) matching
Dental insurance
+4
SOAR Automation Engineer
SOAR Automation Engineer

Dragonfli Group • Washington

Remote
USD 120,000 - 160,000
Health, dental, and vision insurance
Paid Time Off (PTO) and 11 Federal Holidays
401(k) employer match
SOAR Automation Engineer
SOAR Automation Engineer

BlackCube Labs • Washington

On-site
USD 120,000 - 180,000
Cybersecurity Engineer
Cybersecurity Engineer

Creative Solutions Services, LLC • Richmond (VA)

On-site
USD 120,000 - 170,000
SOAR Engineer
SOAR Engineer

MSM Technology, LLC • Scott Air Force Base (IL)

On-site
USD 90,000 - 130,000
Splunk SOAR Administrator New Suitland, Maryland, United States
Splunk SOAR Administrator New Suitland, Maryland, United States

G2it, Llc. • Suitland (MD), Northern (KY)

On-site
USD 120,000 - 150,000