Required Technical Skill Set
- Ability to gather and understand Security requirements for use case / detection rule creation
- Expertise in creating and modifying detection rules, correlation rules and alerting mechanisms.
- Skills in fine-tuning and optimizing use cases / detection rules for performance and accuracy.
- Deep understanding of cybersecurity principles, threats and mitigation techniques.
- Strong skills in analyzing security data and logs to identify patterns and anomalies.
- Strong understanding of log collection, normalization and analysis.
Competencies (Technical / Behavioral Competency)
Must-Have
Experience configuring SIEM platformsProficiency in various OS environments such as Windows, Linux and Unix.Ability to configure log sources, parse logs and understanding correlation rules.Familiarity with Cyber Kill Chain and MITRE ATT&CK Framework and how to leverage in Security OperationsFamiliarity with ETL solutionsUnderstanding of network architecture and network security fundamentals.Proficiency in scripting languages (e.g., Python, Bash, PowerShell)Good-to-Have
Certified in Security +, Splunk Certified Phantom Admin, IBM Certified Deployment Professional, Cortex XSOAR Engineer, Azure Security Engineer or any other SOAR / Cloud related Certifications.Previous experience in a Security operations or similar environment.Responsibility of / Expectations from the Role
1 Lead the deployment and implementation of SIEM solutions, ensuring they meet organizational security requirements.
2 Integrate various log sources into the SIEM platform, ensuring comprehensive data collection and analysis.
3 Performing updates and patches to SIEM Systems and ensuring system scalability and availability.
4 Integrating SIEM with other security tools and ensuring seamless dataflow and interoperability.
5 Document configurations, processes, and procedures related to the SIEM platform to ensure clarity and consistency.
6 Creating dashboards and custom reports for metrics and health monitoring.
7 Ensure the SIEM platform complies with relevant security standards and regulations.
8 Troubleshoot log collection and integration problems.
9 Monitor the performance of the SIEM platform, identifying and resolving any issues that arise.
Skills Required
Cyber Security