SIM Architect
Listed on 2026-07-30
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations, Information & Knowledge Management
Koniag Data Solutions, LLC, a Koniag Government Services company is seeking a SIM Architect to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust clearance.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
Koniag Data Solutions seeks an experienced Security Information Management (SIM) Architect to support the design, development, and implementation of security information management architectures, strategies, and solutions in support of the U.S. Small Business Administration (SBA). The ideal candidate is a senior‑level cybersecurity and architecture professional with deep expertise in security information management, SIEM platforms, log management, security analytics, and the integration of security data sources within complex federal government environments.
This individual will serve as the subject matter expert and technical leader for SBA's security information management architecture, driving the strategic design, implementation, and continuous improvement of SBA's security data collection, correlation, analysis, and reporting capabilities to support effective detection, response, and compliance activities across the enterprise.
The SIM Architect will serve as the senior technical lead and SME for security information management architecture and implementation at the SBA, working closely with SBA's IT leadership, security operations teams, network and infrastructure teams, application teams, and external partners to design, build, and continuously improve a robust and scalable security information management capability that supports SBA's cybersecurity mission and federal compliance requirements.
Principalresponsibilities will include but are not limited to:
- Serve as the senior SME and technical lead for security information management architecture at the SBA, providing expert guidance, strategic direction, and technical leadership on all aspects of SBA's SIEM platform, log management infrastructure, security analytics capabilities, and related security data management solutions.
- Develop, maintain, and continuously refine SBA's security information management architecture strategy, roadmap, and implementation plan, ensuring alignment with NIST cybersecurity frameworks, FISMA requirements, federal continuous monitoring mandates, and SBA's overall cybersecurity strategy.
- Lead the design and development of comprehensive security information management architectural solutions encompassing log collection and aggregation, data normalization and enrichment, security event correlation, threat detection, security analytics, and reporting capabilities across SBA's enterprise IT environment.
- Assess SBA's current SIEM platform, log management infrastructure, and security data management capabilities against current and emerging requirements, identifying gaps, risks, and prioritized opportunities for architectural improvement and capability enhancement.
- Lead the design, configuration, and optimization of SBA's SIEM platform, ensuring it is architected to effectively collect, normalize, correlate, and analyze security data from all relevant sources across SBA's on‑premises, cloud, and hybrid IT environments.
- Develop and maintain comprehensive security information management architecture documentation including reference architectures, data flow diagrams, log source onboarding guides, correlation rule development standards, and other required technical artifacts.
- Lead the development and implementation of SIEM correlation rules, detection logic, and alerting configurations, ensuring they are aligned with current threat intelligence, the MITRE ATT&CK framework, and SBA's specific risk environment and detection requirements.
- Oversee the onboarding and integration of new log sources and security data feeds into SBA's SIEM platform, developing and enforcing standards for log source onboarding, data normalization, and data quality management.
- Collaborate with SBA's SOC, incident response, and cyber defense teams to ensure the security information management architecture effectively supports threat detection, investigation, and response activities, and continuously refine detection capabilities based on operational experience and lessons learned.
- Lead the design and implementation of security analytics capabilities within SBA's security information management environment, including the development of dashboards, reports, and metrics that provide actionable security insights for both operational teams and SBA senior leadership.
- Support the integration of threat intelligence feeds and platforms into SBA's SIEM architecture, ensuring threat intelligence is effectively operationalized to enhance detection and response capabilities.
- Provide expert guidance on the architecture and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).