About this SIEM and Data Management Engineer – Managed Security role at Thinkahead
This is a technical hands-on position that requires someone with a strong understanding of the needs of a 24/7 SOC (Security Operations Center). We are looking for a candidate with XSIAM, SIEM, log management, and security data engineering experience who will work closely with the Managed Security staff and other highly technical members across multiple teams, both within AHEAD and in client environments, to continuously improve and enhance AHEAD’s Managed Security data onboarding, normalization, storage, and optimization capabilities, with Palo Alto Cortex XSIAM serving as the primary platform.
Incumbents will possess strong technical and analytical skills while providing accurate analysis of security-related problems. They will have a well-rounded networking and infrastructure background and will be responsible for troubleshooting data ingestion issues, parser behavior, storage utilization, and client onboarding challenges. This individual is user focused and works to resolve client needs in a timely manner. These needs may involve onboarding new data sources, improving parsing and normalization, optimizing storage and retention strategies, and supporting the reliability and performance of the data pipelines that power Managed Security operations.
The SIEM and Data Management Engineer is responsible for the day-to-day management of the security data platform used by the Managed Security Team to monitor client environments and detect security threats, with a primary emphasis on Palo Alto Cortex XSIAM and supporting familiarity with platforms such as Elastic Security. This includes data source onboarding, ingestion pipeline configuration, parser development and tuning, normalization and enrichment, data tier and retention management, storage optimization, and standardization of security telemetry across client environments. The SIEM and Data Management Engineer is expected to be familiar with a wide range of security tools and understand core security and logging fundamentals.
Roles and Responsibilities
Onboard new client and internal data sources into the Managed Security SIEM environment through a variety of collection and transport methods, including API-based ingestion, syslog, agents, file-based collection, forwarders, cloud-native connectors, and other supported methods
Develop, maintain, and tune parsers, field extractions, transformations, and normalization logic to ensure incoming telemetry is usable, consistent, and aligned to Managed Security standards
Partner with Managed Security analysts, detection engineers, and client technical teams to define log source requirements for visibility, detection content, investigations, and reporting
Establish and maintain data standards for source naming, field usage, tagging, metadata, categorization, and normalization across multiple client environments
Support and optimize ingestion pipelines to ensure reliability, scale, and performance across diverse client log sources and varying data volumes
Perform troubleshooting of data collection, transport, parser, and indexing issues, including validation of connectivity, format, mapping, field extraction, and downstream search usability
Manage data tiering, storage allocation, retention strategies, and index lifecycle practices to ensure telemetry is retained appropriately and efficiently based on operational, contractual, and cost requirements
Perform storage optimization and capacity planning activities within the SIEM platform to ensure ingestion remains within contracted scope while preserving the data needed for security operations and investigations
Analyze data quality and data health across sources, including completeness, timeliness, parsing success, normalization coverage, duplication, and consistency
Identify and implement opportunities to improve data pipeline efficiency, reduce noise, eliminate unnecessary data, and improve search and analytics performance
Partner with SIEM, detection, and SOAR engineering resources to ensure standardized and enriched data supports dashboards, detections, automations, and incident workflows
Build and maintain dashboards, reports, and health checks related to ingestion performance, parser quality, storage consumption, retention compliance, and onboarding progress
Create tooling and scripts in Python or similar languages to automate onboarding checks, parser validation, data quality assessments, and platform administration tasks
Assist with the development of processes and procedures to improve onboarding consistency, parser governance, data quality, and overall Managed Security functions
Participate in client-facing security and technical meetings to support onboarding efforts, explain data requirements, review issues, and coordinate implementation activities
Position Requirements
XSIAM or SIEM administration and configuration experience with a strong emphasis on data onboarding, ingestion pipelines, parsing, normalization, and storage management
Working knowledge of common log collection and transport techniques, including API integrations, syslog, agent-based collection, file shipping, cloud connectors, webhooks, and related ingestion patterns
Experience developing or tuning parsers, field mappings, regular expressions, transformation logic, and normalization processes for security telemetry
Understanding of data lifecycle and storage concepts such as index lifecycle management, hot-warm-cold or tiered storage, retention strategy, archive considerations, and cost-performance tradeoffs
Experience performing capacity planning, storage optimization, and ingestion governance in SIEM or log management platforms
Experience writing tools to automate tasks and integrate systems in Python or another language
The ability to think creatively to find elegant solutions to complex problems
Excellent verbal and written communication skills
The desire to work both independently and collaboratively with a larger team
A willingness to be challenged along with a strong appetite for learning
2–4 years of experience in Information Security, SIEM engineering, data engineering for security operations, security operations, or related disciplines
Hands-on experience with common security technologies such as firewalls, IDS, EDR, SIEM, SOAR, IAM, cloud security tools, and infrastructure platforms that generate operational and security telemetry
Knowledge of common security analysis tools and techniques
Understanding of common security threats, attack vectors, vulnerabilities, and exploits, and the types of telemetry required to support visibility into them
Strong knowledge of regular expressions, structured and unstructured log formats, and data transformation concepts
Customer service focused and portrays energy, professionalism, and welcoming characteristics
Strong ability to work in a highly sensitive and confidential environment
Ability to meet deadlines and handle sensitive and pressured situations
Ability to identify issues and help develop strategy and tactical plans for various department initiatives
Ability to use good judgment and decision-making skills
Prefered Qualifications
Experience with data onboarding and normalization across a wide variety of network, endpoint, identity, cloud, and application log sources
Familiarity with common schemas or data models used in security analytics and event standardization
Experience supporting detection engineering and SOC operations through improved telemetry quality and consistency
Familiarity with automation of onboarding validation, parser testing, and data health monitoring
Education
Bachelor’s Degree in Computer Science, Information Security, Engineering, or related/equivalent educational or work experience
One or more of the following certifications preferred: Palo Alto Networks certifications, Elastic Certified Engineer, CISSP, GCIA, GCIH, GMON, cloud certifications, or other security/data platform related credentials