Columbia, SCremote

Salary
Posted
Jul 15, 2026
Location
Columbia, SC
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A 12-month remote contract role embedded within a state government Division of Information Security, focused on engineering and administering Palo Alto Cortex XSIAM and Cortex XDR across a large, multi-tenant environment. Day-to-day work spans detection content development, automation, log pipeline design via Cribl, multi-tenant onboarding, and operational support for a 24x7 SOC. The role also involves incident response, threat hunting, playbook creation, and participation in a monthly on-call rotation.

Senior level · Remote · Contract

Must have (6)
Cortex XDRSIEMCriblLinuxscriptingdashboards
Nice to have (3)
threat huntingincident responseSOAR/playbooks

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
Linux65%SIEM55%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (13)

Compensation is listed as 'DOE' (Depends on Experience) — no figures are given.

The posting title is 'Consultant' but the position is described internally as 'Security Architect – Consultant – SIEM Engineer'; the role's scope (large-scale multi-tenant enterprise SOC, strategic planning, continuous improvement) supports a Senior classification.

Palo Alto Cortex XSIAM and Cortex XDR are explicitly called out as the primary focus and are treated as hard gates; generic 'Palo Alto' and 'SIEM' experience are also required by the scope description.

Cribl (data modeling, log pipeline design, parsing, normalization, enrichment, ingestion) is described as an important secondary requirement within the main scope — treated as a hard gate.

Scripting languages are required but no specific language is named; 'scripting' is retained as the skill name.

'Dashboards and reporting' appear as part of the required operational duties within the scope description.

Threat hunting, incident response, and playbook/runbook authoring appear in the scope narrative as part of the role's duties but are not isolated as discrete gating requirements — listed as preferred.

The role is 100% remote per the posting; preference is given to local (South Carolina) candidates who can attend occasional on-site meetings, but no residency is required and nationwide candidates are accepted.

CJIS certification is required post-hire on an annual basis; a 7-year background check, credit check, MVR, 10-panel drug screen, E-Verify, and SLED check are mandatory pre-employment screens.

The SOC code is Medium-confidence: the role blends SIEM/XDR engineering (15-1212) with elements of security architecture and SOC operations; 15-1299 is the runner-up given the engineering/architecture depth.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Palo Alto Cortex XSIAM, log pipeline design.

Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗