Lead Administrator (Support &Operations) (Chennai)

Lead Administrator (Support &Operations) (Chennai)

05 Aug
|
HCL Technologies
|
Chennai

05 Aug

HCL Technologies

Chennai

Lead Administrator (Support &Operations;)

Experience: Not Available to Not Available years

Location: Chennai, India

Skills: ArcSight ESM administration, SmartConnectors configuration, SIEM architecture, log management concepts, security frameworks, MITRE ATT&CK;, Kill Chain, Linux/Unix systems, network protocols, firewalls, security logs, analytical skills, other SIEM tools, Splunk, QRadar, Sentinel, Scripting, Shell, Python, Azure, AWS, ArcSight certification

Job Summary
Job Description :
1. ArcSight Platform Administration
Install, configure, and maintain ArcSight ESM components
Perform system upgrades, patching, and routine health checks
Manage ArcSight architecture including:
ESM Console
CORR Engine
Event Processing components
Ensure platform stability, availability, and compliance with operational standards

2. Log & Event Management
Onboard and integrate log sources such as:
Network devices (firewalls, routers)
Servers (Windows/Linux)
Applications and cloud platforms
Configure and manage SmartConnectors (Syslog, Database, API, File-based, etc.)
Ensure reliable log ingestion, normalization, and parsing
Monitor log flow to prevent data loss and ensure completeness

3. Use Case & Rule Management
Develop and optimize correlation rules, alerts, and filters
Perform rule tuning to minimize false positives and improve detection accuracy
Implement security use cases aligned with MITRE ATT&CK; / Cyber Kill Chain
Support SOC team by enhancing detection capabilities and incident visibility

4. Monitoring & Performance Management
Monitor SIEM platform health:
CPU, memory, storage utilization
Events Per Second (EPS) handling
Troubleshoot:
Log ingestion delays
Connector failures
Event drops or parsing issues
Optimize CORR Engine performance and storage utilization
Ensure high system performance and scalability
SENTINEL:
Log Management & Integration
Onboard data sources:




Azure (Azure AD, Defender, Activity Logs)
M365 (Defender, Exchange, SharePoint)
On-prem & 3rd party (via Syslog, CEF, Agents)
Configure Data Connectors and Data Collection Rules (DCRs)
Ensure reliable log ingestion and retention policies
Automation & SOAR
Develop Playbooks using Azure Logic Apps
Automate incident response workflows (email, ticketing, containment)
Integrate with tools like ServiceNow, Teams, Defender
? Querying & Hunting
Develop and optimize KQL (Kusto Query Language) queries
Perform threat hunting using Sentinel Workbooks
Create custom dashboards for visibility

Key Responsibilities
Job Responsibilities :
1. ArcSight Platform Administration
Install, configure, and maintain ArcSight ESM components
Perform system upgrades, patching, and routine health checks
Manage ArcSight architecture including: ESM Console
CORR Engine
Event Processing components
Ensure platform stability, availability, and compliance with operational standards

2. Log & Event Management
Onboard and integrate log sources such as:
Network devices (firewalls, routers)
Servers (Windows/Linux)
Applications and cloud platforms
Configure and manage SmartConnectors (Syslog, Database, API, File-based, etc.)
Ensure reliable log ingestion, normalization, and parsing
Monitor log flow to prevent data loss and ensure completeness

3. Use Case & Rule Management
Develop and optimize correlation rules, alerts, and filters




Perform rule tuning to minimize false positives and improve detection accuracy
Implement security use cases aligned with MITRE ATT&CK; / Cyber Kill Chain
Support SOC team by enhancing detection capabilities and incident visibility

4. Monitoring & Performance Management
Monitor SIEM platform health:
CPU, memory, storage utilization
Events Per Second (EPS) handling
Troubleshoot:
Log ingestion delays
Connector failures
Event drops or parsing issues
Optimize CORR Engine performance and storage utilization
Ensure high system performance and scalability
SENTINEL:
Log Management & Integration
Onboard data sources:
Azure (Azure AD, Defender, Activity Logs)
M365 (Defender, Exchange, SharePoint)
On-prem & 3rd party (via Syslog, CEF, Agents)
Configure Data Connectors and Data Collection Rules (DCRs)
Ensure reliable log ingestion and retention policies
Automation & SOAR
Develop Playbooks using Azure Logic Apps
Automate incident response workflows (email, ticketing, containment)
Integrate with tools like ServiceNow, Teams, Defender
? Querying & Hunting
Develop and optimize KQL (Kusto Query Language) queries
Perform threat hunting using Sentinel Workbooks
Create custom dashboards for visibility

Skill Requirements
Skill Requirement :
Robust experience in ArcSight ESM administration
Hands-on with SmartConnectors configuration and troubleshooting
Knowledge of SIEM architecture and log management concepts
Experience with security frameworks (MITRE ATT&CK;, Kill Chain)
Proficiency in Linux/Unix systems
Understanding of network protocols, firewalls, and security logs
Strong troubleshooting and analytical skills

Other Requirements
Other Requirement :
Experience in other SIEM tools (Splunk, QRadar, Sentinel)
Scripting knowledge (Shell/Python)
Exposure to cloud security monitoring (Azure/AWS logs)
ArcSight certification (preferred)

📌 Lead Administrator (Support &Operations) (Chennai)
🏢 HCL Technologies
📍 Chennai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: lead administrator (support &operations) (chennai) / chennai

Subscribe to this job alert:

Get the latest job offers by email for: lead administrator (support &operations) (chennai) / chennai