Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new prospects. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about Cybersecurity
Your work profile
Work with security teams to understand their requirements and translate them into SIEM use cases
Design, implement, and test SIEM use cases to detect specific types of security threats
Continuously optimize use cases to improve detection accuracy and reduce false positives
Develop and implement SIEM rules and correlation logic to detect security incidents
Tune alerts to minimize false positives and ensure they are actionable
Create and maintaining parsers/connectors in SIEM and SOAR
Set appropriate thresholds for alerts based on analysis and threat intelligence
Ensure data is normalized and enriched for effective correlation and analysis
Develop and maintain log parsing rules to accurately ingest and process data
Maintain detailed documentation of SIEM use cases, including design, implementation, and tuning procedures
Generate reports on the performance and effectiveness of SIEM use cases
Work closely with stakeholders, including SOC analysts, incident responders, and IT teams, to ensure use cases meet their needs
Collaborate with SIEM vendors to troubleshoot issues and implement current features
Innovate and experiment with current use case ideas to enhance the SIEM's detection capabilities
Design and develop automated workflows to address common security operations tasks and incidents
Write and maintain scripts (e.g., Python, PowerShell) t