×
Register Here to Apply for Jobs or Post Jobs. X

Senior SIEMSOAR Architect

Job in Richmond, Henrico County, Virginia, 23214, USA
Listing for: BAA CONSULTING
Full Time position
Listed on 2026-09-16
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Network Security
Salary/Wage Range or Industry Benchmark: 140000 - 180000 USD Yearly USD 140000.00 180000.00 YEAR
Job Description & How to Apply Below

Benefits:

  • 401(k)
  • Employee discounts
  • Health insurance
  • Paid time off
  • Competitive salary
About the Role

BAA Consulting is seeking a talented and driven Senior SIEM/SOAR Architect to join our growing cybersecurity team in Richmond, VA. In this high-impact role, you will design, architect, deploy, configure, and optimize advanced Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solutions for enterprise and Federal clients.

Responsibilities
  • Architect, deploy, configure, and optimize enterprise SIEM and SOAR platforms, with a strong emphasis on Microsoft Sentinel
  • Lead the design and implementation of SIEM/SOAR architectures, including log ingestion, data connectors, data normalization, retention strategies, and security monitoring capabilities
  • Develop, configure, and operationally tune Microsoft Sentinel analytics rules, workbooks, automation rules, playbooks, and detection use cases
  • Develop and tune correlation rules, playbooks, and automated incident response workflows
  • Lead threat detection engineering efforts, including use case development, log source onboarding, and detection optimization
  • Support and implement Federal cybersecurity logging and monitoring requirements, including OMB M-21-31 EL2 requirements or equivalent Federal logging maturity standards
  • Collaborate with SOC and cybersecurity operations teams to improve incident response processes and reduce mean time to detect (MTTD) and mean time to respond (MTTR)
  • Conduct security assessments and provide strategic and technical recommendations for SIEM/SOAR architecture and operational improvements
  • Integrate threat intelligence feeds, security tools, APIs, and third-party technologies into automated SOAR workflows
  • Develop automation using scripting and orchestration technologies to improve security operations efficiency
  • Mentor junior engineers and serve as a senior technical subject matter expert (SME) on SIEM, SOAR, security operations, and detection engineering technologies
  • Communicate complex technical security concepts and recommendations to technical and non-technical stakeholders
Required Qualifications

Candidates must meet the following minimum qualifications:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a closely related field
  • Four (4) additional years of relevant specialized hands-on experience may be considered in lieu of a qualifying bachelor's degree
  • Five (5) or more years of hands-on SIEM and/or SOAR experience involving the design, implementation, configuration, administration, engineering, or operational support of enterprise security operations platforms
  • At least two (2) years of direct, hands-on Microsoft Sentinel experience, including:
    • Architecture and solution design
    • Deployment and implementation
    • Configuration and administration
    • Log source and data connector integration
    • Analytics rule and detection engineering
    • Automation and orchestration
    • Operational tuning and optimization
  • Demonstrated experience supporting OMB Memorandum M-21-31 Event Logging Maturity Level 2 (EL2) requirements, or equivalent Federal cybersecurity logging, monitoring, and logging maturity requirements
  • Active certification in at the time of offer:
    • Microsoft Certified:
      Cybersecurity Architect Expert (SC-100)
    • Microsoft Certified:
      Security Operations Analyst Associate (SC-200)
    • Certified Information Systems Security Professional (CISSP)
  • Strong experience with SIEM/SOAR architecture, log management, security event correlation, data normalization, and security telemetry
  • Experience developing and tuning security detection use cases, correlation rules, and automated response workflows
  • Strong understanding of cybersecurity frameworks and methodologies, including MITRE ATT&CK, NIST Cybersecurity Framework, NIST guidance, and the Cyber Kill Chain
  • Experience integrating security tools, threat intelligence feeds, APIs, and third-party technologies into SIEM/SOAR environments
  • Proficiency in one or more scripting or automation languages, such as Python, Power Shell, or Bash
  • Excellent written and verbal communication skills, including the ability to present complex security concepts to technical and non-technical stakeholders
Preferred Qualifications
  • Experience supporting Federal government cybersecurity, SOC, or enterprise security operations environments
  • Experience implementing Federal logging, monitoring, and cybersecurity requirements
  • Experience with additional SIEM/SOAR platforms such as Splunk, IBM QRadar, Palo Alto Cortex…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary