SIEM and Data Management Engineer – Managed Security

AHEAD

Northern (KY)

Hybrid

USD 120,000 - 160,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision Insurance
401(k)
Paid time off
Competitive compensation

Job summary

AHEAD is seeking a SIEM and Data Management Engineer to lead data onboarding, parsing, and optimization for Cortex XSIAM within a 24/7 security operations context.

Responsibilities include onboarding client data sources, tuning parsers, and ensuring scalable, secure data pipelines across diverse environments, with a focus on Cortex XSIAM and Elastic Security.

Qualifications

  • Experience with Cortex XSIAM data onboarding and ingestion pipelines.
  • Familiarity with normalization, enrichment, and storage management in SIEM environments.

Responsibilities

  • Lead XSIAM data onboarding, ingestion, parsing, normalization, enrichment, and storage lifecycle management within the primary security analytics platform.
  • Onboard data sources into the Managed Security SIEM environment via APIs, syslog, agents, files, and cloud connectors.
  • Develop, tune, and maintain parsers and field extractions to ensure consistent telemetry.

Skills

XSIAM
SIEM
Data ingestion
Parser development
Python
Data normalization
Security analytics
Onboarding

Education

Bachelor’s Degree in Computer Science, Information Security, Engineering, or related/equivalent

Tools

Palo Alto Cortex XSIAM
Elastic Security

Job description

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.

At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD.

We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived.

We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD.

The Managed Security Team at AHEAD monitors client environments and performs incident detection, validation, and reporting. The SIEM and Data Management Engineer will be responsible for the implementation, maintenance, and continuous improvement of the data management capabilities that support our cloud-based security analytics platforms, with a primary focus on Palo Alto Cortex XSIAM, and the broader Managed Security program success across AHEAD.

This is a technical hands‑on position that requires someone with a strong understanding of the needs of a 24/7 SOC (Security Operations Center). We are looking for a candidate with XSIAM, SIEM, log management, and security data engineering experience who will work closely with the Managed Security staff and other highly technical members across multiple teams, both within AHEAD and in client environments, to continuously improve and enhance AHEAD’s Managed Security data onboarding, normalization, storage, and optimization capabilities, with Palo Alto Cortex XSIAM serving as the primary platform.

Incumbents will possess strong technical and analytical skills while providing accurate analysis of security‑related problems. They will have a well‑rounded networking and infrastructure background and will be responsible for troubleshooting data ingestion issues, parser behavior, storage utilization, and client onboarding challenges. This individual is user focused and works to resolve client needs in a timely manner. These needs may involve onboarding new data sources, improving parsing and normalization, optimizing storage and retention strategies, and supporting the reliability and performance of the data pipelines that power Managed Security operations.

The SIEM and Data Management Engineer is responsible for the day‑to‑day management of the security data platform used by the Managed Security Team to monitor client environments and detect security threats, with a primary emphasis on Palo Alto Cortex XSIAM and supporting familiarity with platforms such as Elastic Security. This includes data source onboarding, ingestion pipeline configuration, parser development and tuning, normalization and enrichment, data tier and retention management, storage optimization, and standardization of security telemetry across client environments. The SIEM and Data Management Engineer is expected to be familiar with a wide range of security tools and understand core security and logging fundamentals.

Roles and Responsibilities
  • Lead and perform configuration and development activities related to XSIAM data onboarding, ingestion, parsing, normalization, enrichment, and storage lifecycle management within the primary security analytics platform
  • Onboard new client and internal data sources into the Managed Security SIEM environment through a variety of collection and transport methods, including API-based ingestion, syslog, agents, file-based collection, forwarders, cloud-native connectors, and other supported methods
  • Develop, maintain, and tune parsers, field extractions, transformations, and normalization logic to ensure incoming telemetry is usable, consistent, and aligned to Managed Security standards
  • Partner with Managed Security analysts, detection engineers, and client technical teams to define log source requirements for visibility, detection content, investigations, and reporting
  • Establish and maintain data standards for source naming, field usage, tagging, metadata, categorization, and normalization across multiple client environments
  • Support and optimize ingestion pipelines to ensure reliability, scale, and performance across diverse client log sources and varying data volumes
  • Perform troubleshooting of data collection, transport, parser, and indexing issues, including validation of connectivity, format, mapping, field extraction, and downstream search usability
  • Manage data tiering, storage allocation, retention strategies, and index lifecycle practices to ensure telemetry is retained appropriately and efficiently based on operational, contractual, and cost requirements
  • Perform storage optimization and capacity planning activities within the SIEM platform to ensure ingestion remains within contracted scope while preserving the data needed for security operations and investigations
  • Analyze data quality and data health across sources, including completeness, timeliness, parsing success, normalization coverage, duplication, and consistency
  • Identify and implement opportunities to improve data pipeline efficiency, reduce noise, eliminate unnecessary data, and improve search and analytics performance
  • Partner with SIEM, detection, and SOAR engineering resources to ensure standardized and enriched data supports dashboards, detections, automations, and incident workflows
  • Build and maintain dashboards, reports, and health checks related to ingestion performance, parser quality, storage consumption, retention compliance, and onboarding progress
  • Create tooling and scripts in Python or similar languages to automate onboarding checks, parser validation, data quality assessments, and platform administration tasks
  • Assist with the development of processes and procedures to improve onboarding consistency, parser governance, data quality, and overall Managed Security functions
  • Participate in client-facing security and technical meetings to support onboarding efforts, explain data requirements, review issues, and coordinate implementation activities
Position Requirements
  • Experience with Palo Alto Networks Cortex XSIAM, with a strong emphasis on data onboarding, data pipeline management, parsing, normalization, and platform data operations; experience with Elastic Security and its components is also valuable
  • XSIAM or SIEM administration and configuration experience with a strong emphasis on data onboarding, ingestion pipelines, parsing, normalization, and storage management
  • Working knowledge of common log collection and transport techniques, including API integrations, syslog, agent-based collection, file shipping, cloud connectors, webhooks, and related ingestion patterns
  • Experience developing or tuning parsers, field mappings, regular expressions, transformation logic, and normalization processes for security telemetry
  • Understanding of data lifecycle and storage concepts such as index lifecycle management, hot‑warm‑cold or tiered storage, retention strategy, archive considerations, and cost‑performance tradeoffs
  • Experience performing capacity planning, storage optimization, and ingestion governance in SIEM or log management platforms
  • Experience writing tools to automate tasks and integrate systems in Python or another language
  • The ability to think creatively to find elegant solutions to complex problems
  • Excellent verbal and written communication skills
  • The desire to work both independently and collaboratively with a larger team
  • A willingness to be challenged along with a strong appetite for learning
  • 2–4 years of experience in Information Security, SIEM engineering, data engineering for security operations, security operations, or related disciplines
  • Hands‑on experience with common security technologies such as firewalls, IDS, EDR, SIEM, SOAR, IAM, cloud security tools, and infrastructure platforms that generate operational and security telemetry
  • Knowledge of common security analysis tools and techniques
  • Understanding of common security threats, attack vectors, vulnerabilities, and exploits, and the types of telemetry required to support visibility into them
  • Strong knowledge of regular expressions, structured and unstructured log formats, and data transformation concepts
  • Customer service focused and portrays energy, professionalism, and welcoming characteristics
  • Strong ability to work in a highly sensitive and confidential environment
  • Ability to meet deadlines and handle sensitive and pressured situations
  • Ability to identify issues and help develop strategy and tactical plans for various department initiatives
  • Ability to use good judgment and decision‑making skills
Preferred Qualifications
  • Experience with Palo Alto Cortex XSIAM in multi‑tenant Managed Security or MSSP environments
  • Experience with data onboarding and normalization across a wide variety of network, endpoint, identity, cloud, and application log sources
  • Familiarity with common schemas or data models used in security analytics and event standardization
  • Experience supporting detection engineering and SOC operations through improved telemetry quality and consistency
  • Familiarity with automation of onboarding validation, parser testing, and data health monitoring
  • Education
  • Bachelor’s Degree in Computer Science, Information Security, Engineering, or related/equivalent educational or work experience
  • One or more of the following certifications preferred: Palo Alto Networks certifications, Elastic Certified Engineer, CISSP, GCIA, GCIH, GMON, cloud certifications, or other security/data platform related credentials

$120,000 - $160,000 a year

The compensation range indicated in this posting reflects the On‑Target Earnings (“OTE”) for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate’s relevant experience, qualifications, and geographic location.

Why AHEAD

Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.

We fuel growth by stacking our office with top‑notch technologies in a multi‑million‑dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.

USA Employment Benefits include
  • Medical, Dental, and Vision Insurance
  • 401(k)
  • Paid company holidays
  • Paid time off
  • Paid parental and caregiver leave
  • Plus more! See benefits https://www.aheadbenefits.com/ for additional details.
Use of AI

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, assessing responses, or to capture recordings and create transcriptions or summaries during interviews. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans.

If you would like more information about how your data is processed, please refer to the Candidate Privacy Notice or contact us at privacy@ahead.com.

You may opt‑out of the review or analysis of your application and resume by AI tools by using the General Application. Please include the role you wish to apply for in the Additional Information field. You may also choose to opt‑out of recording and transcription at any time, including after joining an interview. Candidates will not be penalized for choosing to opt‑out.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technical Account Manager, Managed Services Security
Technical Account Manager, Managed Services Security

AHEAD • United States

Hybrid
USD 150,000 - 210,000
Medical insurance
401(k)
Paid time off
+2
Technical Account Manager, Managed Services Security
Technical Account Manager, Managed Services Security

AHEAD • Chicago (IL)

On-site
USD 150,000 - 155,000
SOAR and AI Engineer - Managed Security
SOAR and AI Engineer - Managed Security

Thinkahead • United States

On-site
USD 110,000 - 165,000
Medical, Dental, Vision Insurance
401(k) matching
Paid holidays and PTO
+1
Forward Deployed Engineer - AI SOC
Forward Deployed Engineer - AI SOC

Thinkahead • United States

On-site
USD 140,000 - 210,000
Medical, Dental, Vision Insurance
401(k)
Paid holidays
+2
Forward Deployed Engineer - AI SOC
Forward Deployed Engineer - AI SOC

AHEAD • United States

On-site
USD 120,000 - 180,000
Medical, Dental, and Vision Insurance
401(k)
Paid time off
+1
SOAR and AI Engineer - Managed Security
SOAR and AI Engineer - Managed Security

AHEAD • Chicago (IL)

On-site
USD 120,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+3
Principal Technical Consultant - Network Security
Principal Technical Consultant - Network Security

AHEAD • Northern (KY)

Hybrid
USD 210,000 - 240,000
Medical Insurance
401(k) Plan
Paid Holidays
+1
Principal Technical Consultant - Network Security
Principal Technical Consultant - Network Security

AHEAD • United States

On-site
USD 210,000 - 240,000
Medical, Dental, Vision Insurance
401(k)
Paid time off
+1
Managing Director Security Sales - West
Managing Director Security Sales - West

AHEAD • Seattle (WA)

On-site
USD 180,000 - 280,000
Health benefits
401(k) plan
Paid time off
+3
Managing Director Security Sales - West
Managing Director Security Sales - West

AHEAD • San Jose (CA)

On-site
USD 180,000 - 280,000