Roles and Responsibilities :
- Design, implement, and maintain SIEM solutions to monitor and analyze security event logs from various sources.
- Develop custom scripts using Python or other programming languages to automate data processing and alerting workflows.
- Collaborate with incident response team to investigate security incidents and provide actionable insights for remediation.
- Conduct regular health checks on SIEM systems to ensure optimal performance and identify areas for improvement.
- SIEM/SOAR platform monitoring and maintenance
- Deploying use cases and improving queries through syntax changes and parsing of logs and not developing the logic for the SOC use case.
- Log ingestion and parsing
- Metric building
- Dashboard/widget building
- Log ingestion and use case monitoring
Job Requirements :
Perform regular patching and versioning upgrades on the SIEM platform
Configure forwarders to integrate various log sources with SIEM platform for log monitoring.
Ensure all Critical devices are integrated with SIEM.
Collaborate with key users to develop capabilities, content, and technical applications for security event analysis.
Create queries, dashboards, and visualization to support SOC and security analysts.
Work with Security Automation team to help support SOAR playbooks.
Collaborate cross-functionally with analysts, engineers, and data analysts to deliver continuous improvement in cyber defense.
Coordinate and perform the scheduled backups and restore activities as per backup policy.
Maintain the log baselines as per the requirements given in the log management policies and compliance requirements.
- 6-8 years of experience in Security Information & Event Management (SIEM) engineering or related field.
- Robust understanding of SOC/SOAR principles and practices.
- Proficiency in scripting languages such as Python or equivalent.