OPENTEXT - THE INFORMATION COMPANY OpenText is a global leader in information management where innovation creativity and collaboration are the key components of our corporate culture As a member of our team you will have the opportunity to partner with the most highly regarded companies in the world tackle complex issues and contribute to projects that shape the future of digital transformation AI-First Future-Driven Human-Centered At OpenText AI is at the heart of everything we do powering innovation transforming work and empowering digital knowledge workers We re hiring talent that AI can t replace to help us shape the future of information management Join us Your Impact We are part of OpenText Cybersecurity Enterprise division specializing in Threat Detection and Response Domain Our product helps security operations teams to efficiently and effectively preempt and respond to threats that matter with proactive threat hunting real-time threat detection and response automation We are seeking a detail-oriented and technically proficient Lead Analystto join our team This role is critical in ensuring accurate enrichment of security events enabling effective threat detection correlation alerting and reporting across the SIEM platform What the role offers Lead a team of analysts responsible for SIEM categorization and enrichment efforts Drive continuous improvement in processes tooling and automation Oversee development and maintenance of categorization mappings for diverse log sources using taxonomy standards Manage onboarding of new log sources analyze categorize security event in accordance with SIEM standards Monitor upcoming changes in log sources Ensure consistent normalization of events to support scalable use case development and alerting Review and approve categorization logic ensuring alignment with detection frameworks and operational priorities Collaborate with CMDB IAM and asset management teams to integrate and maintain contextual data sources Ensure context mappings are accurate relevant and optimized for correlation and prioritization with full AUP coverage Troubleshoot and resolve categorization and enrichment issues in production environments Maintain documentation version control and audit readiness for all AUP artifacts Mentor team members and foster a culture of technical excellence and collaboration Act as the primary point of contact for stakeholders across various governance teams What you need to succeed Bachelor s or Master s degree in Computer Science Cybersecurity or related field 8 years of experience with ArcSight or similar SIEM platforms with at least 2 years in a lead or senior role Deep understanding of SIEM event taxonomy storage formats and standards Proven experience in log source onboarding event normalization and metadata enrichment Solid leadership communication and stakeholder management skills Proficiency in scripting Python Bash and version control Git for automation and data parsing Excellent analytical and problem-solving skills Strong communication and documentation abilities Experience with other SIEM platforms Splunk QRadar etc and log management tools Knowledge of cybersecurity frameworks MITRE ATT NIST etc Exposure to threat detection and incident response workflows OpenText s efforts to build an inclusive work environment go beyond simply complying with applicable laws Our Employment Equity and Diversity Policy provides direction on maintaining a working environment that is inclusive of everyone regardless of culture national origin race color gender gender identification sexual orientation family status age veteran status disability religion or other basis protected by applicable laws If you need assistance and or a reasonable accommodation due to a disability during the application or recruiting process please contact us athr opentext com Our proactive approach fosters collaboration innovation and personal growth enriching OpenText s vibrant workplace