- Enterprise SIEM Architect exposure. Multiple SIEM deployement experience. SOC Domain Specialized.
- Excellent knowledge of one of the SIEM products, Qradar Sentinel, Splunk, ArcSight, etc.
- Excellent understanding and proven hands-on experience in SIEM concepts such as correlation, aggregation, normalization, and parsing
- Experience with Incident response and Security Operations Center operations
- Experience with deploying and managing a large SIEM deployment
- Excellent understanding of enterprise logging standards, with a focus on application logging
- 6 years of experience with Sentinel SIEM systems
- Excellent knowledge of adversary tactics, techniques and procedures (TTPs) and MITRE ATT&ACK; Framework
- Excellent understanding of regular expressions, development of custom/flex Parsers
- Excellent understanding of log flow from numerous services within GCP, AWS, Azure cloud and experience with integrating them with 3rd party logging tools including but not limited to Sentinel and Elastic Cloud
- Good Experience with syslog-ng i.e., configuring complex multi client-server infrastructures.
- 5+ years of network security and system security experience, supporting security event management tools (SIEMs)
- Excellent understanding of Cyber Security Operations, Incident Response processes
- Excellent understanding of web application architectures and web services