24 Sep
|
Fujitsu
|
Bengaluru
Link to apply for job- https://www.jobs.global.fujitsu.com/job/Security-Technician/11384-en_US/
-
- Administer and maintain the SIEM platform to ensure high availability and optimal performance.
- Configure, onboard, and normalize logs from various security devices and applications.
- Develop, modify, and optimize SIEM correlation rules, dashboards, reports, and alerts.
- Perform SIEM health checks, capacity planning, and performance tuning.
- Troubleshoot log collection, parsing, and indexing issues.
- Integrate security technologies including:
- Firewalls
- IDS/IPS
- Endpoint Detection & Response (EDR)
- Antivirus solutions
- Email Security Gateways
- Active Directory
- DNS
- Proxy Servers
- Cloud Security platforms
- Work closely with SOC Analysts to improve detection capabilities and reduce false positives.
- Monitor SIEM infrastructure, storage utilization, EPS (Events Per Second), and system performance.
- Implement log retention and archival policies in accordance with compliance requirements.
- Perform SIEM platform upgrades, patching, backup, and disaster recovery activities.
- Develop automation scripts where applicable using PowerShell or Python.
- Create and maintain operational documentation, SOPs, and knowledge articles.
- Participate in incident investigations by providing log analysis and technical support.
- Coordinate with infrastructure, application,
and security teams for log source onboarding and issue resolution.
Required Technical Skills
- 5 to 10 years and Strong hands-on experience with one or more SIEM platforms:
- Microsoft Sentinel
- Splunk Enterprise Security
- IBM QRadar
- ArcSight
- LogRhythm
- Knowledge of Syslog, Windows Event Logs, CEF, JSON, XML, and API integrations.
- Strong understanding of TCP/IP networking, DNS, DHCP, VPN, and common security protocols.
- Experience with Kusto Query Language (KQL), SPL, or AQL based on the SIEM platform.
- Knowledge of MITRE ATT&CK; framework.
- Understanding of security monitoring, threat detection, and incident response processes.
- Familiarity with cloud environments such as Microsoft Azure, AWS, or Google Cloud Platform.
- Experience with scripting using PowerShell, Python, or Bash.
- Robust analytical, troubleshooting, and documentation skills.
- Experience with SOAR platforms.
- Knowledge of Microsoft Defender XDR.
- Understanding of threat intelligence platforms.
- Experience with automation and orchestration.
- Familiarity with compliance standards such as ISO 27001, PCI-DSS, HIPAA, or NIST.
Certifications (Preferred)
- Microsoft SC-200
- Microsoft AZ-500
- CompTIA Security+
- GIAC Certifications
- Certified Information Systems Security Professional (CISSP)
- CEH (Certified Ethical Hacker)
- ECIH ( Incident Handler)
📌 SIEM Security Technician (Bengaluru)
🏢 Fujitsu
📍 Bengaluru