SIEM Architect
Summary
TIAG is hiring a SIEM Architect to lead the modernization of a Uniformed Services University (USU) enclave, transitioning ~150 servers from Splunk Enterprise to a government-selected cloud-native SIEM (Splunk Cloud, Microsoft Sentinel, or Google Chronicle). The architect leads two ISSEs, assists hands-on implementation, and produces DoD-aligned security baselines and logging standards.
TIAG is now hiring a SIEM Architect to support a modernization and transition initiative for a Uniformed Services University (USU) enclave. This position is based on at the customer site in Bethesda, MD in a hybrid capacity.
This role directly supports SIEM Modernization and Cloud Transition at USU. As the technical lead, the SIEM Architect will guide a team of two Information Systems Security Engineers (ISSEs) to enable and oversee the transition of approximately 150 on-premise and cloud-hosted servers from a current Splunk Enterprise environment to a modern, Government-selected cloud-native SIEM platform. While Government-Furnished Labor (GFL) primarily performs server-level implementation, the Architect will oversee the end-to-end implementation process, provide deep technical enablement, and actively assist with hands-on implementation where needed to ensure project success.
Primary Responsibilities
- Enable and oversee the implementation and transition of 150+ enterprise assets into the selected cloud-native SIEM environment.
- Assist with hands-on server-level implementation, integration, and telemetry configuration where needed to bridge capability gaps and ensure project momentum.
- Provide architectural vision and daily technical direction to two dedicated Information Systems Security Engineers (ISSEs) supporting the transition effort.
- Serve as the primary technical escalation point for complex interoperability issues, delegating routine telemetry validation and parser configuration tasks to the ISSE team.
- Lead the collaborative assessment of the current USU Splunk Enterprise environment, directing the ISSE team to document onboarded log sources, telemetry coverage, ingestion methods, and parser configurations.
- Evaluate Government-Furnished Enterprise (GFE) SIEM platforms (Splunk Cloud, Microsoft Sentinel, Google Chronicle) against the enclave's operational, security, and modernization requirements.
- Deliver a Platform Evaluation & Selection Report containing the formal technical recommendation for the platform best aligned with USU goals.
- Develop a Security Configuration Baseline for the chosen SIEM solution that aligns with DoD cybersecurity requirements, DISA STIG guidance, RMF controls, and Zero Trust principles.
- Establish enterprise-wide Logging Standards by analyzing operating system environments across the enclave.
- Define comprehensive requirements for telemetry collection, event categorization, normalization, and retention in a finalized Logging Standards Manual.
- Architect and build Reference Implementations for all supported OS categories, utilizing templates, scripts, Group Policy Objects (GPOs), and agent profiles.
- Govern the ongoing transition of the 150+ enterprise assets, ensuring the ISSEs effectively deliver day-to-day Tier 2 technical support to GFL administrators for ingestion failures, parser inconsistencies, and connectivity issues.
- Validate the telemetry pipelines established during implementation, ensuring the representative servers ("proving the pipe") demonstrate successful end-to-end event generation, ingestion, parsing, normalization, and visibility.
- Oversee technical troubleshooting workflows, root cause analysis, and operational status reporting throughout the implementation lifecycle.
- Design the operational governance framework for the future-state cloud-native monitoring environment.
- Direct the ISSE team in authoring practical Standard Operating Procedures (SOPs) for Tier 1 GFL administrators.
- Develop standardized methodologies for alert tuning, threshold tuning, suppression management, and false-positive handling to improve SOC efficiency.
- Assess existing GFL cloud operations knowledge to design targeted "delta" training focused strictly on the unique features of the newly implemented SIEM solution.
- Lead high-level instructional sessions on platform-specific querying (e.g., KQL for Microsoft Sentinel or UDM for Google Chronicle), while utilizing the ISSEs to facilitate hands-on labs.
- Certify operational readiness by verifying that GFL personnel can independently sustain day-to-day SIEM operations post-implementation.