Required Technical Skill Set
- Ability to gather and understand Security requirements for use case/detection rule creation
- Expertise in creating and modifying detection rules, correlation rules and alerting mechanisms.
- Skills in fine-tuning and optimizing use cases/detection rules for performance and accuracy.
- Deep understanding of cybersecurity principles, threats and mitigation techniques.
- Solid skills in analyzing security data and logs to identify patterns and anomalies.
- Strong understanding of log collection, normalization and analysis.
Competencies (Technical/Behavioral Competency)
Must-Have
- Experience configuring SIEM platforms
- Proficiency in various OS environments such as Windows, Linux and Unix.
- Ability to configure log sources, parse logs and understanding correlation rules.
- Familiarity with Cyber Kill Chain and MITRE ATT&CK; Framework and how to leverage in Security Operations
- Familiarity with ETL solutions
- Understanding of network architecture and network security fundamentals.
- Proficiency in scripting languages (e.g., Python, Bash,
PowerShell)
Good-to-Have
- Certified in Security +, Splunk Certified Phantom Admin, IBM Certified Deployment Skilled, Cortex XSOAR Engineer, Azure Security Engineer or any other SOAR/ Cloud related Certifications.
- Previous experience in a Security operations or similar environment.
Responsibility of / Expectations from the Role
1 Lead the deployment and implementation of SIEM solutions, ensuring they meet organizational security requirements.
2 Integrate various log sources into the SIEM platform, ensuring comprehensive data collection and analysis.
3 Performing updates and patches to SIEM Systems and ensuring system scalability and availability.
4 Integrating SIEM with other security tools and ensuring seamless dataflow and interoperability.
5 Document configurations, processes, and procedures related to the SIEM platform to ensure clarity and consistency.
6 Creating dashboards and custom r