We are looking for an experienced SOC L3 / SOC L4 – SIEM / SOC Security Engineer to join our Security Operations team. The ideal candidate should have strong hands-on experience in SIEM, preferably ArcSight, security alert investigation, incident response, log analysis, EDR, Antivirus, Firewall, and threat hunting.
Key Responsibilities
Work on ArcSight SIEM for log monitoring and security alert handling.
Monitor, investigate, and respond to security alerts and incidents.
Identify True Positive and False Positive alerts.
Perform Root Cause Analysis (RCA) and prepare incident reports.
Perform SIEM alert fine-tuning to reduce false positives and improve detection.
Monitor and analyze IDS/IPS alerts.
Monitor and analyze alerts from EDR and Antivirus tools.
Analyze and manage logs from Firewall devices.
Analyze firewall, server, endpoint, and application logs.
Troubleshoot SIEM issues related to log collection, parsing, connectors, and data ingestion.
Use the MITRE ATT&CK; Framework for threat mapping and analysis.
Perform IOC-based and hypothesis-based threat hunting.
Identify suspicious activities and escalate security incidents when required.
Participate in Incident Response planning and execution.
Support continuous improvement of SOC monitoring and detection capabilities.
Required Skills
Robust knowledge of SIEM tools, preferably ArcSight.
Hands-on experience in SOC operations and security alert investigation.
Experience with EDR, Antivirus, and Firewall technologies.
Positive understanding of Incident Response and security incident investigation.
Strong knowledge of log analysis and security concepts.
Basic to good knowledge of IDS/IPS.
Familiarity with the MITRE ATT&CK; Framework.
Experience in threat hunting and IOC analysis.
Stro