Job Summary The role is focused on the maintenance, adaptation, expansion and management of all internally used Security Tools of the company, as well as any 3rd party external tools, while keeping transparent communication with all company tribes.
Responsibilities
Develop and enhance current and future SIEM solutions.
Ingest non-standard log sources to SIEM. Adapt log filtering and parsing configurations to the required use case.
Optimise SIEM usage in coordination with SOC team.
Manage SIEM availability monitoring.
Further develop the company security tools integrations.
Perform proof of concept implementation of future security solutions.
Requirements
Proficiency in ELK Stack:
ElasticSearch, Kibana, Logstash, FileBeat, AuditBeat, PacketBeat
Valuable understanding of Linux OS
Familiarity with configuration automation tool such as Ansible
Positive understanding of security principles and frameworks including
MITRE ATT&CK;, ISO 27001, ZTA, CSA CCM.