05 Aug
|
HCL Technologies
|
Chennai
05 Aug
HCL Technologies
Chennai
Lead Administrator (Support &Operations;)
Experience: Not Available to Not Available years
Location: Chennai, India
Skills: ArcSight ESM administration, SmartConnectors configuration, SIEM architecture, log management concepts, security frameworks, MITRE ATT&CK;, Kill Chain, Linux/Unix systems, network protocols, firewalls, security logs, analytical skills, other SIEM tools, Splunk, QRadar, Sentinel, Scripting, Shell, Python, Azure, AWS, ArcSight certification
Job Summary
Job Description :
1. ArcSight Platform Administration
Install, configure, and maintain ArcSight ESM components
Perform system upgrades, patching, and routine health checks
Manage ArcSight architecture including:
ESM Console
CORR Engine
Event Processing components
Ensure platform stability, availability, and compliance with operational standards
2. Log & Event Management
Onboard and integrate log sources such as:
Network devices (firewalls, routers)
Servers (Windows/Linux)
Applications and cloud platforms
Configure and manage SmartConnectors (Syslog, Database, API, File-based, etc.)
Ensure reliable log ingestion, normalization, and parsing
Monitor log flow to prevent data loss and ensure completeness
3. Use Case & Rule Management
Develop and optimize correlation rules, alerts, and filters
Perform rule tuning to minimize false positives and improve detection accuracy
Implement security use cases aligned with MITRE ATT&CK; / Cyber Kill Chain
Support SOC team by enhancing detection capabilities and incident visibility
4. Monitoring & Performance Management
Monitor SIEM platform health:
CPU, memory, storage utilization
Events Per Second (EPS) handling
Troubleshoot:
Log ingestion delays
Connector failures
Event drops or parsing issues
Optimize CORR Engine performance and storage utilization
Ensure high system performance and scalability
SENTINEL:
Log Management & Integration
Onboard data sources:
Azure (Azure AD, Defender, Activity Logs)
M365 (Defender, Exchange, SharePoint)
On-prem & 3rd party (via Syslog, CEF, Agents)
Configure Data Connectors and Data Collection Rules (DCRs)
Ensure reliable log ingestion and retention policies
Automation & SOAR
Develop Playbooks using Azure Logic Apps
Automate incident response workflows (email, ticketing, containment)
Integrate with tools like ServiceNow, Teams, Defender
? Querying & Hunting
Develop and optimize KQL (Kusto Query Language) queries
Perform threat hunting using Sentinel Workbooks
Create custom dashboards for visibility
Key Responsibilities
Job Responsibilities :
1. ArcSight Platform Administration
Install, configure, and maintain ArcSight ESM components
Perform system upgrades, patching, and routine health checks
Manage ArcSight architecture including: ESM Console
CORR Engine
Event Processing components
Ensure platform stability, availability, and compliance with operational standards
2. Log & Event Management
Onboard and integrate log sources such as:
Network devices (firewalls, routers)
Servers (Windows/Linux)
Applications and cloud platforms
Configure and manage SmartConnectors (Syslog, Database, API, File-based, etc.)
Ensure reliable log ingestion, normalization, and parsing
Monitor log flow to prevent data loss and ensure completeness
3. Use Case & Rule Management
Develop and optimize correlation rules, alerts, and filters
Perform rule tuning to minimize false positives and improve detection accuracy
Implement security use cases aligned with MITRE ATT&CK; / Cyber Kill Chain
Support SOC team by enhancing detection capabilities and incident visibility
4. Monitoring & Performance Management
Monitor SIEM platform health:
CPU, memory, storage utilization
Events Per Second (EPS) handling
Troubleshoot:
Log ingestion delays
Connector failures
Event drops or parsing issues
Optimize CORR Engine performance and storage utilization
Ensure high system performance and scalability
SENTINEL:
Log Management & Integration
Onboard data sources:
Azure (Azure AD, Defender, Activity Logs)
M365 (Defender, Exchange, SharePoint)
On-prem & 3rd party (via Syslog, CEF, Agents)
Configure Data Connectors and Data Collection Rules (DCRs)
Ensure reliable log ingestion and retention policies
Automation & SOAR
Develop Playbooks using Azure Logic Apps
Automate incident response workflows (email, ticketing, containment)
Integrate with tools like ServiceNow, Teams, Defender
? Querying & Hunting
Develop and optimize KQL (Kusto Query Language) queries
Perform threat hunting using Sentinel Workbooks
Create custom dashboards for visibility
Skill Requirements
Skill Requirement :
Robust experience in ArcSight ESM administration
Hands-on with SmartConnectors configuration and troubleshooting
Knowledge of SIEM architecture and log management concepts
Experience with security frameworks (MITRE ATT&CK;, Kill Chain)
Proficiency in Linux/Unix systems
Understanding of network protocols, firewalls, and security logs
Strong troubleshooting and analytical skills
Other Requirements
Other Requirement :
Experience in other SIEM tools (Splunk, QRadar, Sentinel)
Scripting knowledge (Shell/Python)
Exposure to cloud security monitoring (Azure/AWS logs)
ArcSight certification (preferred)
📌 Lead Administrator (Support &Operations) (Chennai)
🏢 HCL Technologies
📍 Chennai