- Ability to gather and understand Security requirements for use case/detection rule creation
- Expertise in creating and modifying detection rules, correlation rules and alerting mechanisms.
- Skills in fine-tuning and optimizing use cases/detection rules for performance and accuracy.
- Deep understanding of cybersecurity principles, threats and mitigation techniques.
- Strong skills in analyzing security data and logs to identify patterns and anomalies.
- Strong understanding of log collection, normalization and analysis.
Competencies (Technical/Behavioral Competency)
Must-Have
- Experience configuring SIEM platforms
- Proficiency in various OS environments such as Windows, Linux and Unix.
- Ability to configure log sources, parse logs and understanding correlation rules.
- Familiarity with Cyber Kill Chain and MITRE ATT&CK; Framework and how to leverage in Security Operations
- Familiarity with ETL solutions
- Understanding of network architecture and network security fundamentals.
- Proficiency in scripting languages (e.g., Python, Bash, PowerShell)
Good-to-Have
- Certified in Security +, Splunk Certified Phantom Admin, IBM Certified Deployment Professional,
Cortex XSOAR Engineer, Azure Security Engineer or any other SOAR/ Cloud related Certifications.
- Previous experience in a Security operations or similar setting.
Responsibility of / Expectations from the Role
1 Lead the deployment and implementation of SIEM solutions, ensuring they meet organizational security requirements.
2 Integrate various log sources into the SIEM platform, ensuring comprehensive data collection and analysis.
3 Performing updates and patches to SIEM Systems and ensuring system scalability and availability.
4 Integrating SIEM with other security tools and ensuring seamless dataflow and interoperability.
5 Document configurations, processes, and procedures related to the SIEM platform to ensure clarity and consistency.
6 Creating dashboards and custom reports for metrics and health monitoring.
7 Ensure the SIEM platform complies with relevant security standards and regulations.
8 Troubleshoot log collection and integration problems.
9 Monitor the performance of the SIEM platform, identifying and resolving any issues that arise.