12 Sep
|
Essen Vision Software's
|
India
12 Sep
Essen Vision Software's
India
Job Summary
IMMEDIATE JOINER's REQUIFRED!
We are looking for a motivated SIEM Analyst with 2–3 years of experience in ArcSight and Splunk to join our Security Operations Center (SOC) team. The candidate will be responsible for security monitoring, alert analysis, incident investigation, log management, correlation rule monitoring, and escalation of security incidents.
The ideal candidate should have hands-on experience working with ArcSight ESM and Splunk/Splunk Enterprise Security, along with a positive understanding of networking, Windows/Linux security, common cyberattacks, and incident response processes.
Key Responsibilities
- Monitor security events and alerts using ArcSight and Splunk SIEM platforms.
- Analyze and investigate security alerts, incidents, and suspicious activities.
- Perform L1/L2 SOC monitoring and incident triage.
- Investigate events from firewalls, IDS/IPS, VPN, proxy, endpoint, Active Directory, Windows/Linux servers, cloud platforms, and other security devices.
- Create and tune correlation rules, alerts, and use cases based on security requirements.
- Perform false-positive analysis and recommend appropriate tuning.
- Develop and maintain Splunk searches, dashboards, reports, and alerts using SPL.
- Work with ArcSight ESM, SmartConnectors, Logger, correlation rules, filters, and dashboards.
- Investigate authentication anomalies, malware-related alerts, brute-force attacks, privilege escalation, suspicious network activity, and other security events.
- Perform IOC investigation and enrichment using threat intelligence sources.
- Correlate events from multiple data sources to identify potential security incidents.
- Document investigation findings, evidence, root cause,
and remediation recommendations.
- Escalate confirmed or high-severity incidents to the appropriate security/incident-response teams.
- Participate in incident response and follow established SOC procedures and playbooks.
- Monitor SIEM health, data ingestion, parsing, and log-source connectivity.
- Troubleshoot missing, delayed, or incorrectly parsed logs.
- Assist with onboarding new log sources into ArcSight and Splunk.
- Prepare daily/weekly/monthly SOC reports and security metrics.
- Support compliance and audit requirements related to security monitoring and logging.
- Work with infrastructure, network, endpoint, and application teams to resolve security issues.
Technical SkillsArcSight
- ArcSight Enterprise Security Manager (ESM)
- ArcSight SmartConnectors
- ArcSight Logger
- ArcSight Console / Web interface
- Correlation rules
- Filters and queries
- Active Lists / Sessions
- Security event investigation
- Event categorization and normalization
- Use-case development and rule tuning
- Log-source onboarding and troubleshooting
Splunk
- Splunk Enterprise / Splunk Cloud fundamentals
- Splunk Enterprise Security (ES)
- SPL – Search Processing Language
- Search, reports, alerts, and dashboards
- Indexes and sourcetypes
- Data models
- Lookups
- Scheduled searches
- Correlation searches
- Notable events / security findings
- Risk-Based Alerting (RBA)
- Incident investigation and triage
- Basic Splunk administration and troubleshooting
Splunk Enterprise Security supports workflows including incident triage, investigations, response plans, threat intelligence, and risk analysis.
Pay: ₹5.00 - ₹5.50 per year
Work Location: In person
📌 Senior Analyst (India)
🏢 Essen Vision Software's
📍 India