- Building, tuning and looking after SIEM content such as rules, dashboards, and reports, making sure threats don’t get missed.
- Keeping an eye on the data, spotting issues early and helping us respond quickly.
- Working side by side with Analysts, Architects, PMs and Engineers to make sure the SIEM content hits the mark.
- Bringing the latest threat intel, vulnerabilities and attack methods into our set-up.
- Helping to shape and maintain security standards and procedures.
- Solid hands-on experience with SIEM tools like Splunk, Sentinel or QRadar.
- A good grip on security best practices and standards (ISO 27001/27002, PCI DSS).
- Familiarity with frameworks such as NIST, ISO and CIS.
- Comfortable scripting in Python, PowerShell and regex.
- The ability to work across multiple projects and still keep the detail sharp.