10794 - IT - ADMIN - Security Architect - Consultant
Security Architect - Consultant
Location - Columbia SC (100% Remote)
Duration - 12 Months
Start Date - 25 May 2026
Last Date of submission - 5 May 2026
The State of South Carolina is looking for a Security Analyst - Consultant (SOAR Engineer)
Why is this position open: New role supporting statewide security automation via the state SOAR platform across South Carolina s state agencies (Division of Information Security)
Work Location: Fully Remote
Candidate Location: No SC residency required. Open to nationwide candidates.
PREFERENCE WILL BE GIVEN TO A CANDIDATE WHO CAN WORK ONSITE OVER HYBRID AND OVER FULL-TIME REMOTE (ON-SITE AS NEEDED).
Required skills
Education - Bachelors Degree in an Information Technology or Information Security related field; 8+ years of experience in security architecture may be substituted in lieu of education
5+ years of experience with automation platforms or SOAR solutions
5+ years of experience in supporting large IT environments and/or system deployments
Experience with scripting and automation (Python, Bash, PowerShell, or similar)
Experience with Rest API's, JSON, and YAML
Familiarity with MITRE ATT & CK framework
Experience working in multi-tenancy environment; multi-agency or enterprise service projects
Preferred skills
Certification - CISSP, CISA, CISO or equivalent advanced security certifications (CEH, OSCP, GPEN)
Certification - Vendor certifications in SOAR or Automation technologies
Experience creating automations within the Cortex XSOAR platform
Knowledge of security monitoring use cases and incident response support.
Resources local to Columbia, SC or surrounding city in South Carolina are preferred
SCOPE OF THE PROJECT: THE POSITION WILL WORK AS A CONSULTING SECURITY ORCHESTRATION, AUTOMATION, AND RESPONSE ENGINEER WITHIN THE DIVISION OF INFORMATION SECURITY. THIS ROLE WILL FOCUS ON PLAYBOOK DEVELOPMENT AND ORCHESTRATION, WORKFLOW AUTOMATION, AND LOGIC OPTIMIZATION WITHIN THE STATE SOAR PLATFORM. THEY WILL ALSO BUILD AND MAINTAIN INTEGRATIONS BETWEEN THE STATE SOAR PLATFORM, SIEM, EDR, FIREWALLS, AND OTHER NECESSARY SECURITY TOOLS. ENGAGING DIRECTLY WITH STATE AGENCIES TO PROMOTE, SUPPORT, AND IMPROVE ADOPTION OF CENTRALIZED SECURITY SERVICES IS A KEY FOCUS. THE ENGAGEMENT IS EXPECTED TO BE NEEDED FOR 12 MONTHS WITH THE POSSIBILITY OF EXTENSION.
DAILY DUTIES / RESPONSIBILITIES:
PREFERENCE WILL BE GIVEN TO A CANDIDATE WHO CAN WORK ONSITE OVER HYBRID AND OVER FULL-TIME REMOTE (ON-SITE AS NEEDED).
- PROVIDE TECHNICAL EXPERTISE AND EXPERIENCE IN CREATING EFFICIENT AUTOMATION WORKFLOWS.
- DEVELOP, IMPLEMENT AUTOMATIONS AND OPTIMIZE EXISTING AUTOMATIONS IN RESPONSE TO SECURITY ALERTS AND INCIDENTS.
- BUILD AND MAINTAIN INTEGRATIONS WITH THE SOAR PLATFORM.
- CREATE CUSTOM SCRIPTS WHEN REQUIRED TO PROVIDE FUNCTIONALITY NOT SUPPORTED OUT OF THE BOX INTEGRATIONS.
- DOCUMENT PROCESSES, RUNBOOKS, AND TROUBLESHOOTING STEPS RELATED TO THE SOAR AND INTEGRATIONS.
- PROACTIVELY COORDINATE WITH ENGINEERING, SOC, AND IR SUPPORT AS NEEDED TO MEET GOALS.
- OTHER DUTIES AS NEEDED.
ADDITIONAL SKILLS/DUTIES:
- EXPERIENCE WITH DASHBOARD CREATION AND REPORTING.
- EXCELLENT COMMUNICATION AND CUSTOMER SERVICE SKILLS FOR AGENCY-FACING ENGAGEMENT.