×
Register Here to Apply for Jobs or Post Jobs. X

Principal Consultant - SIEM | Remote, CAN

Remote / Online - Candidates ideally in
Toronto, Ontario, C6A, Canada
Listing for: Optiv
Remote/Work from Home position
Listed on 2026-08-09
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Network Security
Salary/Wage Range or Industry Benchmark: 140000 - 190000 CAD Yearly CAD 140000.00 190000.00 YEAR
Job Description & How to Apply Below

The Principal SIEM Consultant will be pivotal to problem definition, requirements discovery, and overall SIEM solution design, guiding teams through complex security analytics and operations engagements. This individual will drive the technical relationship with customers and partners by providing advanced SIEM architecture, implementation, integration, and operational leadership across modern platforms including Google Sec Ops, Microsoft Sentinel, Crowd Strike NG-SIEM, and Palo Alto XSIAM.

Acts as an industry leader and champion of technical excellence in Security Information and Event Management (SIEM), delivering exceptional services and support to strategic clients and setting the bar for others to aspire to.

How you'll make an impact
  • Work with customers to articulate business, security operations, and detection requirements and translate those needs into effective SIEM use cases, architectures, and operational models.
  • Architect and validate SIEM solutions to ensure the customer's risk reduction, visibility, and detection engineering objectives are met.
  • Lead SIEM platform design, deployment, migration, and optimization efforts across Google Sec Ops, Microsoft Sentinel, Crowd Strike NG-SIEM, and Palo Alto XSIAM.
  • Assist with development of SIEM and SOC transformation engagement plans that enable customers to execute detection, response, and analytics strategies.
  • Rationalize SIEM, logging, and security analytics technologies against business requirements, risk posture, cost constraints, and operational maturity.
  • Serve as a recognized expert in SIEM architecture, log onboarding, detection engineering, UEBA, SOAR integration, and SOC operations.
  • Lead and mentor other consultants on complex SIEM programs, providing technical direction and quality oversight across engagements.
  • Able to present to large technical and executive audiences; speaks as an authority on SIEM strategy and security operations.
  • Confidently handles difficult technical and strategic questions, consistently gaining trust and support from client stakeholders.
  • Able to adapt and evolve SIEM delivery methodologies based on client maturity, platform capabilities, and operational constraints.
  • Maintains broad awareness of the cybersecurity, SOC, and security analytics technology landscape beyond SIEM alone.
  • Contributor to industry groups, thought leadership initiatives, whitepapers, or publications related to SIEM, SOC, or security operations.
What we're looking for
  • Bachelor's degree and approximately 10–15 years of related information security or technology consulting experience.
  • Approximately 8–10 years of hands-on security architecture experience with a strong focus on SIEM and security operations platforms.
  • Deep expertise in SIEM concepts including log collection and normalization, detection engineering, alerting strategy, content lifecycle management, SOC workflows, and integration with SOAR and EDR platforms.
  • Strong practical experience with one or more modern SIEM platforms such as Google Sec Ops, Microsoft Sentinel, Crowd Strike NG-SIEM, and Palo Alto XSIAM.
  • Strong understanding of adjacent security domains including incident response, threat detection, vulnerability management, data classification, and security governance.
  • Understanding of the professional services business and the organizational impact of technical and delivery decisions.
  • Solid understanding of networking (TCP/IP, OSI model), operating systems (Windows, Linux/UNIX), cloud platforms, and modern security technologies (EDR, NDR, firewalls, IDS/IPS).
  • Familiarity with scripting and automation languages commonly used in SIEM environments (e.g., KQL, Python, Power Shell, YAML).
  • Strong understanding of regulatory and compliance requirements impacting security monitoring and log retention, including PCI DSS, GLBA, GDPR, and U.S. state privacy laws.
  • Proven experience integrating SIEM platforms into complex enterprise and cloud environments, including log pipelines, APIs, and security tooling ecosystems.
  • Willingness to travel to meet client needs.
  • Valid driver's license in the U.S. and a valid passport required.
  • The successful candidate must hold or be willing to pursue relevant…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary