SIEM Implementation & Management: Deploy, configure, and maintain SIEM platforms (Splunk, QRadar, ArcSight, LogRhythm).
Log Source Integration: Integrate diverse log sources, develop custom parsers, and tune rules for accurate detection.
Detection Rules: Create, test, and optimize detection rules, correlation logic, and alerts based on threat models and business risks.
Collaboration: Work closely with SOC and Incident Response teams to enhance investigative workflows.
Automation & Scripting: Use Python, PowerShell, or similar scripting languages for automation, dashboard creation, and custom reporting.
Threat Visibility: Improve monitoring coverage and ensure proactive detection of advanced threats.
Documentation: Maintain technical documentation, detection playbooks, and compliance reports.
Requirements
Qualifications
Bachelor’s degree in Computer Science, Information Technology, or related discipline.
Minimum 8+ years of experience in SIEM engineering, security monitoring, or SOC environments.
Strong knowledge of SIEM platforms and log management.
CertificationsÂ
Splunk Certified Architect.
GCIA (GIAC Certified Intrusion Analyst).
Equivalent SIEM/security certifications.
Learn more about this Employer on their Career Site
