SIEM Architect

Posted 5 Days Ago
Be an Early Applicant
20814, Bethesda, MD, USA
In-Office
130K-150K Annually
Expert/Leader
Information Technology • Security
The Role
Lead SIEM modernization and cloud transition for 150+ enterprise assets at a DoD university enclave. Evaluate Splunk Cloud, Microsoft Sentinel, and Google Chronicle; establish logging standards, security baselines, telemetry architectures, and operational governance. Direct two ISSEs, oversee implementation and troubleshooting, develop SOPs and training, tune alerts, and certify operational readiness. Ensure alignment with DISA STIGs, RMF controls, Zero Trust principles, and federal cybersecurity requirements.
Summary Generated by Built In

TIAG is now hiring a SIEM Architect to support a modernization and transition initiative for a Uniformed Services University (USU) enclave. This position is based on at the customer site in Bethesda, MD in a hybrid capacity.

This role directly supports SIEM Modernization and Cloud Transition at USU. As the technical lead, the SIEM Architect will guide a team of two Information Systems Security Engineers (ISSEs) to enable and oversee the transition of approximately 150 on-premise and cloud-hosted servers from a current Splunk Enterprise environment to a modern, Government-selected cloud-native SIEM platform. While Government-Furnished Labor (GFL) primarily performs server-level implementation, the Architect will oversee the end-to-end implementation process, provide deep technical enablement, and actively assist with hands-on implementation where needed to ensure project success.   

Primary Responsibilities

  • Enable and oversee the implementation and transition of 150+ enterprise assets into the selected cloud-native SIEM environment. 
  • Assist with hands-on server-level implementation, integration, and telemetry configuration where needed to bridge capability gaps and ensure project momentum.
  • Provide architectural vision and daily technical direction to two dedicated Information Systems Security Engineers (ISSEs) supporting the transition effort.
  • Serve as the primary technical escalation point for complex interoperability issues, delegating routine telemetry validation and parser configuration tasks to the ISSE team.
  • Lead the collaborative assessment of the current USU Splunk Enterprise environment, directing the ISSE team to document onboarded log sources, telemetry coverage, ingestion methods, and parser configurations. 
  • Evaluate Government-Furnished Enterprise (GFE) SIEM platforms (Splunk Cloud, Microsoft Sentinel, Google Chronicle) against the enclave's operational, security, and modernization requirements. 
  • Deliver a Platform Evaluation & Selection Report containing the formal technical recommendation for the platform best aligned with USU goals. 
  • Develop a Security Configuration Baseline for the chosen SIEM solution that aligns with DoD cybersecurity requirements, DISA STIG guidance, RMF controls, and Zero Trust principles. 
  • Establish enterprise-wide Logging Standards by analyzing operating system environments across the enclave. 
  • Define comprehensive requirements for telemetry collection, event categorization, normalization, and retention in a finalized Logging Standards Manual. 
  • Architect and build Reference Implementations for all supported OS categories, utilizing templates, scripts, Group Policy Objects (GPOs), and agent profiles. 
  • Govern the ongoing transition of the 150+ enterprise assets, ensuring the ISSEs effectively deliver day-to-day Tier 2 technical support to GFL administrators for ingestion failures, parser inconsistencies, and connectivity issues. 
  • Validate the telemetry pipelines established during implementation, ensuring the representative servers ("proving the pipe") demonstrate successful end-to-end event generation, ingestion, parsing, normalization, and visibility. 
  • Oversee technical troubleshooting workflows, root cause analysis, and operational status reporting throughout the implementation lifecycle. 
  • Design the operational governance framework for the future-state cloud-native monitoring environment. 
  • Direct the ISSE team in authoring practical Standard Operating Procedures (SOPs) for Tier 1 GFL administrators. 
  • Develop standardized methodologies for alert tuning, threshold tuning, suppression management, and false-positive handling to improve SOC efficiency. 
  • Assess existing GFL cloud operations knowledge to design targeted "delta" training focused strictly on the unique features of the newly implemented SIEM solution. 
  • Lead high-level instructional sessions on platform-specific querying (e.g., KQL for Microsoft Sentinel or UDM for Google Chronicle), while utilizing the ISSEs to facilitate hands-on labs. 
  • Certify operational readiness by verifying that GFL personnel can independently sustain day-to-day SIEM operations post-implementation.

Qualifications

Required Experience:

  • 8–10+ years of overall cybersecurity and IT experience, with at least 5 years serving as a SIEM Architect, Senior Engineer, or technical implementation lead.
  • Demonstrated architectural and implementation expertise in deploying and optimizing Splunk Enterprise, Splunk Cloud, Microsoft Sentinel, and Google Chronicle. 
  • Proven ability to lead a technical team (e.g., ISSEs, SOC analysts) while overseeing and assisting with large-scale log onboarding and transition projects.
  • Deep understanding of Federal and DoD compliance frameworks, including DISA STIGs, Risk Management Framework (RMF), and Zero Trust principles. 
  • Proficiency in scripting and configuration management tools to design and deploy reusable implementation artifacts (GPOs, agent profiles). 
  • Strong technical writing skills to produce comprehensive governance documentation, Logging Standards Manuals, and operational SOPs. 
  • Ability to facilitate technical workshops, present comparative analyses to executive stakeholders, and deliver hands-on technical training to operations personnel.
  • Secret Clearance
  • CompTIA Security+ Certification

TIAG is an equal opportunity employer and federal contractor or subcontractor.  Consequently, the parties agree that, as applicable, they will abide by the requirements of 41 CFR 60-1.4(a), 41 CFR 60-300.5(a), and 41 CFR 60-741.5(a)  and employment decisions shall be based solely on merit and without regard disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. TIAG takes proactive steps to employ and advance in employment qualified individuals without regard to disability or protected veteran status.  The parties also agree that, as applicable, they will abide by the requirements and may be subject and required to take action pursuant to the following laws and accompanying regulations:

The Vietnam Era Veterans Readjustment Assistance Act of 1974, as amended (and its implementing regulations at 41 C.F.R. 60-300);
Section 503 of the Rehabilitation Act of 1973, as amended (and its implementing regulations at 41 C.F.R 60-741); and 
Executive Order 13496 (and its implementing regulations at 29 C.F.R. part 471, Appendix A to Subpart A).

Skills Required

  • 8-10+ years of overall cybersecurity and IT experience
  • At least 5 years as a SIEM Architect, Senior Engineer, or technical implementation lead
  • Architectural and implementation expertise with Splunk Enterprise, Splunk Cloud, Microsoft Sentinel, and Google Chronicle
  • Experience leading technical teams and overseeing large-scale log onboarding and transition projects
  • Deep understanding of DISA STIGs, Risk Management Framework (RMF), and Zero Trust principles
  • Proficiency in scripting and configuration management tools for reusable implementation artifacts, including GPOs and agent profiles
  • Strong technical writing skills for governance documentation, logging standards, and operational SOPs
  • Ability to facilitate technical workshops, present comparative analyses, and deliver hands-on technical training
  • Secret Clearance
  • CompTIA Security+ Certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Reston, VA
348 Employees
Year Founded: 1999

What We Do

Delivering transformative technology solutions for the public sector and across the Department of Defense, TIAG drives modernization through synergistic processes and unique approaches. Our people are brilliant, well-credentialed business and technology experts who provide nimble, creative solutions to multidimensional problems. Our collective expertise results in refined, comprehensive services that truly make a difference. Customers choose TIAG because we drive genuine innovation and deliver value beyond the scope of work — ranging from complex enterprise-wide solutions to stand-alone custom projects. At TIAG, our greatest asset is our people. Our commitment to taking care of our employees inspires the dedication and longevity of our teams, ensuring success and continuity for client initiatives. TIAG’s strategic quality control management system and processes amplify our company-wide focus on excellence — ensuring the highest degree of management processes, solutions and work products we create and deliver for our customers. TIAG works to achieve and enhance our prestigious certifications for the ISO 9001:2015 Standard and for CMMI® (Capability Maturity Model® Integration) for Services (SVC) Level 3.

Similar Jobs

Optum Logo Optum

Healthcare Advocate - Field-Based Position

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Bethesda, MD, USA
160000 Employees
73K-130K Annually

CDW Logo CDW

Technical Writer

Information Technology
Remote or Hybrid
US
15100 Employees
64K-89K Annually

Pfizer Logo Pfizer

Senior Manager, HTA, Value and Evidence (HV&E), Genitourinary Cancer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
30 Locations
121990 Employees
139K-232K Annually

PNC Bank Logo PNC Bank

Product Owner

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
91K-203K Annually

Similar Companies Hiring

Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account