ControlCase
Website:
controlcase.com
Company:
https://www.linkedin.com/company/controlcase
Industries: IT Services and IT Consulting
Job details:
Position Summary
The Appliance Integration Consultant is responsible for analyzing, designing, and structuring log flow architecture to onboard customer environments onto ControlCase's SIEM / XDR and VULNERABILITY MANAGEMENT cloud platform, and for collecting the evidence required to support customer certification efforts. This is a hands-on, customer-facing technical role requiring working knowledge of systems, networking, and cloud infrastructure, along with the ability to communicate clearly and confidently with customers while integrating a wide range of asset types, including:
- Network devices – firewalls, routers, switches, hypervisors, and other security appliances.
- Windows and Linux servers (all major distributions).
- Active Directory, LDAP, and DNS servers.
- macOS systems (basic).
- Applications and databases, on-premises or cloud-hosted.
- APIs, agents, tokens, and web services.
- Cloud environments – AWS, Azure, Google Cloud, Oracle Cloud, Digital Ocean (basic).
Key Responsibilities
Customer Onboarding & Platform Integration:
- Lead end-to-end onboarding of new customer environments onto the SIEM / XDR / VULNERABILITY MANAGEMENT cloud platform, including scoping, planning, and execution of log source integration.
- Configure and troubleshoot platform components – agents, APIs, tokens, web services, and log forwarders – across heterogeneous customer environments.
- Design and structure log flow architecture to ensure reliable, complete data ingestion from all relevant asset types.
- Analyze customer network topology and asset inventory to determine the appropriate integration approach for each environment.
Solution Administration & Optimization
- Manage platform user accounts and access – create, modify, and deactivate – in line with customer and internal policy.
- Create and maintain client-specific watch lists and data sources to support threat identification.
- Own major solution changes within client environments, ensuring changes are tested, documented, and rolled out accurately and with minimal disruption.
- Validate log sources, optimize platform functionality, and produce analytical reports on integration health and coverage.
- Evaluate and integrate new products and technologies with the platform as they become available.
Compliance, Evidence & Audit Support
- Deploy and maintain audit rules and log retention configurations to meet customer compliance requirements (e.g., PCI DSS, ISO 27001, SOC 2, NIST, GDPR).
- Collect, organize, and submit evidence required for customer certification and audit cycles.
- Map customer security and compliance need to the appropriate SIEM/XDR configuration.
Documentation, Process & Automation
- Develop custom documentation, runbooks, and workflow diagrams to standardize onboarding and operational processes.
- Apply knowledge of parsing rules, filters, and regular expressions to build and refine log parsers.
- Identify and build automation that reduces the time required for operational changes and initial platform deployment.
Customer & Cross-Functional Engagement
- Serve as the primary technical point of contact for assigned customers, building strong working relationships.
- Troubleshoot technical issues end-to-end: identify root cause, resolve, and advise customers on steps to prevent recurrence.
- Collaborate with SOC analysts, engineers, and data science teams to drive continuous improvement of detection and monitoring capabilities.
- Mentor and train engineers and customers on platform use and best practices.
- Manage product enhancement and feature requests with technology vendors.
Professional Development
- Stay current on the evolving threat landscape and emerging detection methodologies, including MITRE ATT&CK and the Cyber Kill Chain.
- Attend vendor-specific meetings, training, and conferences to maintain technical and professional currency.
Required Qualifications
Bachelor's degree or diploma in Information Technology, Computer Applications, Engineering, or a related field.
Required Experience:
- Minimum 2 years of experience in systems/network administration or technical support.
- Minimum 2 years of experience in managed services, information security, or a SOC environment.
- Minimum 2 years of experience in direct client/customer communication.
Technical Skills
- Working knowledge of SIEM/XDR technologies (e.g., Rapid7, LogRhythm, QRadar, or similar).
- Intermediate proficiency in Windows and Linux (all major distributions); working familiarity with macOS.
- Solid understanding of network topology and architecture across on-premises, data center, and cloud environments (AWS, Azure, GCP, Oracle Cloud etc).
- Knowledge of log forwarders, parsing rules, regular expressions, and basic scripting. • Familiarity with network/traffic analysis tools (e.g., tcpdump, Wireshark, Ngrep etc.).
- Understanding of compliance frameworks such as PCI DSS, NIST, SOC 2, GDPR, and ISO 27001.
Core Competencies
- Strong written, verbal, and listening communication skills, with the ability to explain technical concepts to non-technical stakeholders.
- Analytical and methodical approach to troubleshooting and root-cause analysis.
- Ability to manage multiple customer environments and competing priorities simultaneously.
- Self-driven, with a continuous-improvement mindset.
Preferred Qualifications (Good to Have)
- Exposure to infrastructure/deployment automation tools (e.g., Ansible, Chef, Terraform).
- Knowledge of MITRE ATT&CK and Cyber Kill Chain frameworks.
- Prior experience supporting compliance certification audits (PCI DSS, ISO, SOC 2).
- Experience mentoring junior engineers or training customers on technical platforms.
Work Environment
Customer-facing technical role that may require flexibility across time zones to support global customer environments. (Note that this is not Customer support).
Click on Apply to know more.