More jobs:
Job Description & How to Apply Below
We are seeking a Senior SIEM Engineer responsible for designing, implementing, and managing SIEM solutions to enhance security monitoring, threat detection, and incident response capabilities. The ideal candidate will have strong expertise in SIEM platforms such as Splunk, Microsoft Sentinel, or similar technologies, with experience in security integrations, log management, detection engineering, and SOC operations. The role will focus on optimizing SIEM capabilities, supporting security improvements, and collaborating with stakeholders to strengthen overall security posture.
Responsibilities- Designing, reviewing, implementing, testing, maintaining, and troubleshooting SIEM deployments and infrastructures.
- Responsible for managing arrangements of dependencies and pre-requisites for SIEM projects e.g., connectivity, storage, licenses, and other equipment).
- Responsible for implementing changes to the SIEM infrastructure (including patches, updates, and upgrades) and performing SIEM Health Checks; and for creating technically relevant detailed reports to track solution effectiveness and performance.
- Manage SIEM Appliance or Virtual Appliance (including OS and SIEM software).
- Configure backups, verify custom reports, manage log source groups, and validate log sources.
- Add/Remove log sources. Troubleshoot issues with log sources or systems with system owners and vendors, and report system defects and product enhancement / feature requests with vendors as needed.
- Be responsible for development of integrations, connectors, and parsers for new event sources.
- Implementing security monitoring rules in a SIEM tooling, according to the business needs.
- Assist with fully optimizing the SIEM system capabilities and identifying opportunities for automation to improve SIEM effectiveness and efficiency.
- Create rules and reports for compliance and audit requirements and create and manage Watch Lists for current threats.
- Create engineering and security documentation for internal and external needs including high level and low-level design of SIEM infrastructure, as-built documentation and documentation for custom connectors/parsers and integrations.
- Assist with designing and documenting work processes within the SOC.
- Responsible for mentoring and training of Junior SIEM Engineers.
- Perform other duties as assigned.
A minimum of 5 years of experience in Security Engineering, with at least 3 years of experience managing SIEM solutions.
Required Skills- Proven experience in designing and implementing SIEM solutions.
- Proven experience in integrating security tools such as AV, AAA, Firewall, DLP, and IDS/IPS into SIEM solutions.
- Proven experience in implementing SIEM monitoring with cloud systems, including:
- AWS Cloud Trail
- AWS Guard Duty
- AWS VPC Flow Logs
- Azure Activity Logs
- Azure AD/Entra
-in Logs - Microsoft Defender for Cloud
- GCP Cloud Audit Logs
- GCP VPC Flow Logs
- OCI Audit Logs
- OCI Cloud Guard
- Proven experience with SIEM technologies such as Splunk, Microsoft Sentinel, Google Sec Ops, etc.
- Demonstrated understanding of Information Security regulations, frameworks, and requirements, with the ability to map a client’s security needs to an appropriate SIEM solution.
- Solid understanding of Information Security and Networking.
- Proven experience with scripting/query languages relevant to SIEM data onboarding, such as Python, Regex, SPL, and KQL.
- Outstanding time management and organizational skills.
- Ability to work on-call, including nights and weekends, as required.
- Proven capability to learn quickly and deliver to a high standard within deadlines.
- Strong organizational skills with the ability to prioritize tasks from multiple stakeholders.
- Excellent written and verbal communication skills.
- Ability to relay complex…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×