Experience : 8+ years
Location : Airoli,Mumbai
Role : Permanent
Work Model : work Office
Deploy, configure, and maintain SIEM platforms (Securonix, Sentinel, LogRhythm, Rapid7, Splunk).
Integrate various data sources, including firewalls, endpoints, servers, cloud services, and applications.
Develop and maintain parsers, custom log ingestion scripts, and connectors.
Create and fine-tune correlation rules, alerts, and dashboards to identify suspicious or malicious activity.
Develop detection logic for both known and unknown threats using behavioral analytics and threat intelligence.
Collaborate with SOC analysts to ensure alerts are actionable and reduce false positives.
Support security incident investigations through log analysis and event correlation.
Work closely with cybersecurity, IT, and compliance teams to ensure log retention and auditing requirements are met.
Create and maintain documentation for configurations, standard operating procedures, and playbooks.
Security Professional • India