Optiv Logo

Optiv

Principal Consultant - SIEM | Remote, CAN

Posted 13 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Toronto, ON, CAN
Expert/Leader
In-Office or Remote
Hiring Remotely in Toronto, ON, CAN
Expert/Leader
Lead SIEM architecture, implementation, integration, and operations across modern platforms. Translate customer requirements into detection use cases and operational models, mentor teams, drive SOC transformation, integrate SIEM with SOAR/EDR, and present strategy to technical and executive audiences.
The summary above was generated by AI

The Principal SIEM Consultant will be pivotal to problem definition, requirements discovery, and overall SIEM solution design, guiding teams through complex security analytics and operations engagements. This individual will drive the technical relationship with customers and partners by providing advanced SIEM architecture, implementation, integration, and operational leadership across modern platforms including Google SecOps, Microsoft Sentinel, CrowdStrike NG‑SIEM, and Palo Alto XSIAM. 

Acts as an industry leader and champion of technical excellence in Security Information and Event Management (SIEM), delivering exceptional services and support to strategic clients and setting the bar for others to aspire to. 

 

How you'll make an impact 

 

• Work with customers to articulate business, security operations, and detection requirements and translate those needs into effective SIEM use cases, architectures, and operational models. 

• Architect and validate SIEM solutions to ensure the customer’s risk reduction, visibility, and detection engineering objectives are met. 

• Lead SIEM platform design, deployment, migration, and optimization efforts across Google SecOps, Microsoft Sentinel, CrowdStrike NG‑SIEM, and Palo Alto XSIAM. 

• Assist with development of SIEM and SOC transformation engagement plans that enable customers to execute detection, response, and analytics strategies. 

• Rationalize SIEM, logging, and security analytics technologies against business requirements, risk posture, cost constraints, and operational maturity. 

• Serve as a recognized expert in SIEM architecture, log onboarding, detection engineering, UEBA, SOAR integration, and SOC operations. 

• Lead and mentor other consultants on complex SIEM programs, providing technical direction and quality oversight across engagements. 

• Able to present to large technical and executive audiences; speaks as an authority on SIEM strategy and security operations. 

• Confidently handles difficult technical and strategic questions, consistently gaining trust and support from client stakeholders. 

• Able to adapt and evolve SIEM delivery methodologies based on client maturity, platform capabilities, and operational constraints. 

• Maintains broad awareness of the cybersecurity, SOC, and security analytics technology landscape beyond SIEM alone. 

• Contributor to industry groups, thought leadership initiatives, whitepapers, or publications related to SIEM, SOC, or security operations. 

 

What we're looking for 

 

• Bachelor’s degree and approximately 10–15 years of related information security or technology consulting experience. 

• Approximately 8–10 years of hands-on security architecture experience with a strong focus on SIEM and security operations platforms. 

• Deep expertise in SIEM concepts including log collection and normalization, detection engineering, alerting strategy, content lifecycle management, SOC workflows, and integration with SOAR and EDR platforms. 

• Strong practical experience with one or more modern SIEM platforms such as Google SecOps, Microsoft Sentinel, CrowdStrike NG‑SIEM, and Palo Alto XSIAM. 

• Strong understanding of adjacent security domains including incident response, threat detection, vulnerability management, data classification, and security governance. 

• Understanding of the professional services business and the organizational impact of technical and delivery decisions. 

• Solid understanding of networking (TCP/IP, OSI model), operating systems (Windows, Linux/UNIX), cloud platforms, and modern security technologies (EDR, NDR, firewalls, IDS/IPS). 

• Familiarity with scripting and automation languages commonly used in SIEM environments (e.g., KQL, Python, PowerShell, YAML). 

• Strong understanding of regulatory and compliance requirements impacting security monitoring and log retention, including PCI DSS, GLBA, GDPR, and U.S. state privacy laws. 

• Proven experience integrating SIEM platforms into complex enterprise and cloud environments, including log pipelines, APIs, and security tooling ecosystems. 

• Willingness to travel to meet client needs. 

• Valid driver’s license in the U.S. and a valid passport required. 

• The successful candidate must hold or be willing to pursue relevant certifications such as CISSP, CISM, CISA, or SIEM‑specific platform certifications. 

• Strong interpersonal, leadership, and client‑facing skills. 

• Strong written and presentation skills with the ability to clearly communicate complex SIEM and SOC concepts to technical and executive audiences. 

• Possess a high standard of integrity and confidentiality. 

  • #LI-GN1 

What you can expect from Optiv

  • A company committed to our inclusive value through our Employee Resource Groups

  • Work/life balance

  • Professional training resources

  • Creative problem-solving and the ability to tackle unique, complex projects

  • Volunteer Opportunities. “Optiv Chips In” encourages employees to volunteer and engage with their teams and communities.

  • The ability and technology necessary to productively work remotely/from home (where applicable)

EEO Statement

Optiv is an equal opportunity employer. All qualified applicants for employment will be considered without regard to race, color, religion, sex, gender identity or expression, sexual orientation, pregnancy, age 40 and over, marital status, genetic information, national origin, status as an individual with a disability, military or veteran status, or any other basis protected by federal, state, or local law.

Optiv respects your privacy. By providing your information through this page or applying for a job at Optiv, you acknowledge that Optiv will collect, use, and process your information, which may include personal information and sensitive personal information, in connection with Optiv’s selection and recruitment activities.  For additional details on how Optiv uses and protects your personal information in the application process, click here to view our Applicant Privacy Notice. If you sign up to receive notifications of job postings, you may unsubscribe at any time.

Optiv Mississauga, Ontario, CAN Office

6715 Millcreek Dr, Units 5-6, Mississauga, Canada, L5N 5V2

Similar Jobs

42 Minutes Ago
Remote or Hybrid
Canada
Senior level
Senior level
Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
The Enterprise Account Executive will focus on acquiring new business in the insurance sector, managing client relationships, and collaborating with sales teams to enhance reach.
Top Skills: CRMSalesforce
An Hour Ago
Remote or Hybrid
ON, CAN
Senior level
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead and execute incident response engagements, perform host and network forensics across Windows, macOS, and Linux, conduct basic malware analysis and reverse engineering, develop hunting methods, produce reports and remediation plans, engage with legal and executives, and contribute thought leadership and public-facing content.
Top Skills: AIAWSAzureBroGCPLinuxmacOSSuricataWindowsZeek
2 Hours Ago
Easy Apply
Remote
Canada
Easy Apply
Expert/Leader
Expert/Leader
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Lead Motive's strategy and execution to enter and scale Mexico, the UK, and Canada and evaluate further international expansion. Own go-to-market roadmaps, localization, demand generation, partnerships, and budget allocation. Build and manage a small regional team and agency partners, align cross-functional stakeholders, define success metrics and reporting, run test-and-learn experiments, and present commercial outcomes to executive leadership.

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account