06 Aug
|
Athena Bharatjobs
|
Noida
06 Aug
Athena Bharatjobs
Noida
Role & responsibilities
Key Responsibilities
1. SIEM Administration & Management
- Deploy, configure, and maintain SIEM tools (e.g., Splunk, QRadar, Sentinel, LogRhythm, ArcSight).
- Integrate diverse log sources including servers, firewalls, endpoints, cloud platforms, and applications.
- Ensure log ingestion, parsing, correlation, and normalization are functioning correctly.
2. Security Monitoring & Threat Detection
- Monitor security alerts, identify suspicious behavior, and escalate potential incidents.
- Develop, refine, and tune correlation rules, detection use cases, dashboards, and alerts.
- Perform threat hunting using SIEM datasets to uncover anomalous activity.
3. Incident Response Support
- Assist in triage, investigation, and response to cybersecurity incidents.
- Provide detailed event analysis and support forensic investigations.
- Document findings and recommend remediation actions.
4. Optimization & Continuous Improvement
- Fine-tune SIEM rules to reduce false positives and improve detection capability.
- Perform health checks, performance tuning, and version upgrades.
- Work closely with SOC, Infra, Cloud, and App teams to enhance visibility and event quality.
5. Compliance & Reporting
- Support compliance frameworks (ISO 27001, SOC2, PCI-DSS, etc.) through proper log retention and reporting.
- Generate weekly/monthly dashboards, KPIs, and executive-level reports.
Required Skills & Qualifications
- Bachelors degree in Computer Science, Information Security, or related field (preferred, not mandatory).
- Hands-on experience with at least one SIEM platform.
- Robust understanding of:
- Security event logs (Windows/Linux)
- Network security fundamentals
- Firewalls, proxies, IDS/IPS, EDR, cloud logs
- Threat detection and MITRE ATT&CK;
- Knowledge of scripting (Python, PowerShell, Bash) is an advantage.
- Understanding of incident response and forensic concepts.
📌 Siem Administrator (Noida)
🏢 Athena Bharatjobs
📍 Noida