Security Architect - SIEM # 26-17159 at US Tech Solutions
Columbia, SC
$83.33–$86.2/hrfrom the description
Jul 16, 2026
Columbia, SC
Jul 21, 2026
What this job asks for AI summary
A 12-month contract role focused on engineering and operating Palo Alto Cortex XSIAM and Cortex XDR within a large, multi-tenant enterprise environment supporting a round-the-clock SOC. Day-to-day work spans platform configuration, detection engineering, log pipeline management via Cribl, playbook development, and analyst support across tiers. Suits an experienced security engineer with hands-on SIEM/XDR and data pipeline expertise.
Senior level · 5+ years · Remote · Contract
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 20,400 people nationally plausibly meet what this posting asks for (information security analysts). range 6,000–30,600
Applicant volume Heavy — This req sits in a large pool with little in its requirements to thin it, and auto-apply tools fire at everything in the occupation. Applying early and leading with the rare skills below is what gets read.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (12)
The posting states a Bachelor's degree in IT or information security is required, but explicitly allows substitution of eight years of relevant work experience in lieu of the degree — the degree requirement is therefore set to None.
The role-level experience gate is five years supporting large IT environments; an additional eight-year substitution path is mentioned only as an alternative to the degree, not as a separate role requirement.
The SOC classification is a judgement call: the role is primarily a SIEM/XDR platform engineer embedded in a SOC, which sits between Information Security Analysts (15-1212) and the broader 'Computer Occupations, All Other' (15-1299) bucket. 15-1212 was chosen because the dominant day-to-day work — detection engineering, threat hunting, incident response support, and security platform operations — aligns most closely with that occupation.
Palo Alto Cortex XSIAM and Cortex XDR are listed as the top-ranked required skills and are central to the entire scope; both are marked as hard gates.
Cribl appears in both the required skills section (log pipeline design, parsing, normalization, enrichment, routing) and the preferred section (hands-on administration and optimization). The required-section mention is the controlling gate.
Python and Bash are listed together as scripting language examples ('such as Python and Bash'); Python is emitted as the primary skill with Bash in alternatives, reflecting that either satisfies the requirement.
'Detection engineering' and 'security playbooks' are named capabilities explicitly required in the required skills section; they are retained as skills because they represent concrete, named security engineering disciplines rather than generic soft skills.
CISSP, Security+, and GIAC certifications appear only under Preferred Education/Certifications and are marked preferred accordingly. Palo Alto Cortex and Cribl certifications are similarly preferred.
The posting lists Columbia, SC as a location but explicitly states the role is 100% remote and open to nationwide candidates; no metro is set per caller instruction.
Ignored 4 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Palo Alto Cortex XSIAM, Palo Alto Cortex XDR, detection engineering, log pipeline design.
Posting is for a contract engagement — the market benchmarks below price full-time roles, so read the comp comparison with that in mind.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.