SOC Architect

Openkyber•Columbia, SC
•Remote

About The Position

We are seeking a hands-on, senior-level Security Engineer/Architect Consultant to join the Division of Information Security (DIS) at the South Carolina Department of Administration. This contract role focuses on developing enterprise cybersecurity automations, building custom security tools, integrating IAM/SOAR platforms, managing Linux security sensors/collectors, and supporting the 24x7 Security Operations Center (SOC).

Requirements

  • Bachelor's degree in IT, Computer Science, Software Engineering, or Information Security OR 8+ years of equivalent relevant work experience.
  • 5+ years of experience supporting large IT environments, security deployments, software development, and systems administration.
  • Demonstrated experience building response workflows and API integrations using Python, PowerShell, Bash, REST APIs, JSON, YAML, and Vendor SDKs.
  • Hands-on Linux administration, deployment, patching, service management, containerization (Docker), and sensor maintenance.
  • In-depth knowledge of incident response, networking, access control, DNS security (e.g., Cisco Umbrella/Secure Access concepts), rate limiting/API throttling, and data ingestion workflows.
  • 7-Year Standard Background Check
  • Credit History Check (Full credit check during initial hiring process)
  • Motor Vehicle Record (MVR) / Driving Record Check
  • E-Verify Verification
  • SLED (South Carolina Law Enforcement Division) Check
  • Candidate must obtain and retain annual CJIS certification upon onboarding.

Nice To Haves

  • CISSP, Security+, GIAC (GSECIAIH), or specialized Linux/Python/Cloud/IAM certifications.
  • Hands-on generalist experience supporting multi-tenant, shared-services, or managed-service enterprise environments.
  • Experience with Palo Alto Networks, Proofpoint, Tenable, Cribl, WhatsUp Gold, or equivalent enterprise security platforms.

Responsibilities

  • Design, build, deploy, and support Python-based automations, internal web applications, REST APIs, SDKs, CLI tools, and automated incident response workflows (alert enrichment, triage, containment, escalation, and reporting).
  • Develop custom tools for CVE vetting, vulnerability enrichment, prioritization tracking, and security decision support.
  • Deploy, patch, configure, optimize, and troubleshoot Linux-based OS environments hosting security sensors, log collectors, Docker containers, and data-processing pipelines.
  • Provide secondary operational engineering support for DSPM, ASM, IAM, SIEM, SOAR, XDR, email security, endpoint protection, and network security tools (e.g., Palo Alto Networks, Proofpoint, Tenable, Cribl, WhatsUp Gold).
  • Manage user provisioning/deprovisioning workflows, RBAC, service accounts, API credentials, and identity-based system integrations.
  • Create playbooks, runbooks, and documentation; provide technical escalation support to 24x7 SOC analysts and incident responders.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service