This role is for a SIEM (Security Information and Event Management) professional who is responsible for the administration, maintenance, and monitoring of a SIEM tool. The ideal candidate will have strong skills in log collection, alert management, and reporting, ensuring the security of the organization's systems through proactive analysis and timely response to security events.
Responsibilities
- Log and Context Data Collection : Collect all logs, including operational and custom application logs. Configure various technology devices using agent-based and agentless methods, and set up ODBC settings.
- Administration and Maintenance : Configure device hosts, perform daily health checks of the SIEM tool, and coordinate with vendors for operational or hardware issues. Create and modify complex rules and queries, and configure and modify alerts.
- Monitoring and Analysis : Daily monitoring of dashboards and alerts. Escalate alerts, log tickets, and assign them to the appropriate owners as per the defined process. Analyze critical logs and follow up on tickets until closure.
- Alerting and Notification : Configure alerts and notifications for all critical events of onboarded technology. Modify existing alerts and notify the Information Security team of any operational issues.
- Reporting : Daily monitoring of reports. Configure and schedule reports, dashboards, and specific compliance reports as per requirements.
- Log Retention : Retain logs as per the defined process.
- Troubleshooting : Troubleshoot all errors within the SIEM tool.
Skills
Required Skills :
Proficiency in log and context data collection from various sources.Experience in configuring different technology devices using agent-based and agentless methods .Strong skills in administration and maintenance of SIEM tools, including daily health checks and vendor coordination.Expertise in creating and modifying complex rules and queries by aggregating multiple conditions.Experience in monitoring and analyzing alerts and dashboards.Knowledge of alerting and notification configuration for critical events.Ability to configure and customize reports and dashboards.Understanding of log retention processes.Strong troubleshooting skills to resolve errors within the SIEM tool.Knowledge of proposed SLA and penalty clauses related to SIEM operations.Skills Required
Siem, Siem Tools, Reporting, Data Collection, Monitoring Plan, System Administration, Troubleshooting