SIEM Administrator
Pune, IN
IBM
For more than a century, IBM has been a global technology innovator, leading advances in AI, automation and hybrid cloud solutions that help businesses grow.
Introduction
Information and Data are some of the most important organizational assets in today’s businesses. As a Security Consultant, you will be a key advisor for IBM’s clients, analyzing business requirements to design and implement the best security solutions for their needs. You will apply your technical skills to find the balance between enabling and securing the client’s organization with the cognitive solutions that are making IBM the fastest growing enterprise security business in the world.
Your Role and Responsibilities
As a SIEM Engineer you will be responsible for implementation and deployment of new SIEM projects; and managing and providing SIEM health and operational support, including supporting to architecture changes, tool deployments and advanced detection engineering.
Key Job Details
Role:SIEM Administrator Location:Pune, IN Category:Consulting Employment Type:Full-Time Travel Required:No Travel Contract Type:Regular Company:(0063) IBM India Private Limited Req ID:726321BR
Information and Data are some of the most important organizational assets in today’s businesses. As a Security Consultant, you will be a key advisor for IBM’s clients, analyzing business requirements to design and implement the best security solutions for their needs. You will apply your technical skills to find the balance between enabling and securing the client’s organization with the cognitive solutions that are making IBM the fastest growing enterprise security business in the world.
Your Role and Responsibilities
As a SIEM Engineer you will be responsible for implementation and deployment of new SIEM projects; and managing and providing SIEM health and operational support, including supporting to architecture changes, tool deployments and advanced detection engineering.
Responsibilities
- Understand SIEM product architecture.
- Ensure up-time of SIEM components.
- Perform daily SIEM Health Check & Availability monitoring.
- Understanding logs, Log formats, identify appropriate information for Log parsing and SIEM rule creation, Log Source Review
- Suggest logging levels and baseline log sources.
- Understanding of Log sources such as Operating System, Database, Web servers, Security and Network Technologies
- SIEM Content Development Keep a track of latest patches major version upgrades released by vendors.
- Log Retention Define and manage the log retention for all integrated devices as per defined agreement.
- Data Enrichment and asset modelling.
- Custom integration – Develop parsers for non-supported log sources as per scope.
- You will be closely working with Security Operations Center (SOC), Threat Intelligence, Threat Hunt, Automation and Orchestration teams to develop and operationalize meaningful security alerting and ensuring platform health and uptime.
- SIEM (Cortex XSIAM\\Splunk, Chronicle\\Qradar\\Micro Focus ArcSight\\Microsoft Sentinel\\LogRhythm\\Nitro) configuration management, troubleshooting, addressing complex issues and day to day operations management.
- Keep abreast of latest IT security, regulatory and compliance trends to support various risk\\data models.
- Ready to work in 24×7 rotational shift model including night shift.
Required Technical and Professional Expertise
- 8 to 10 years’ relevant experience in security information and or technology engineering support.
- Experience with the following technologies : leading SIEM technologies (Cortex XSIAM\\Splunk, Chronicle\\ Qradar\\Micro Focus ArcSight\\Microsoft Sentinel\\LogRhythm\\Nitro) IDSIPS, network- and host- based firewalls, data leakage protection (DLP), common EDR platforms etc.
- Understanding of possible attack activities such as network probing scanning, DDOS, malicious code activity, exfiltration, credential access, etc.
- An understanding of the Cyber Kill Chain, the MITRE attack framework, various TTPs described within and commonly used by attackers as well as how to write detection rules for them in SIEM and EDR solution.
- Understanding of tools, technologies and logging mechanism including understanding to common network devices such as routers, switches, load balancers etc.
- Understanding of typical cloud threats and knowledge of how to detect and prevent them, cloud logging and audit capabilities and the ability to develop detection rules around these.
- Understanding of basic networking protocols such as IP, DNS, HTTP, and the network s
- Basic knowledge in system security architecture and security solutions.
Preferred Technical and Professional Expertise
- CISSP, CEH or equivalent.
Key Job Details
Role:SIEM Administrator Location:Pune, IN Category:Consulting Employment Type:Full-Time Travel Required:No Travel Contract Type:Regular Company:(0063) IBM India Private Limited Req ID:726321BR
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
1
1
0
Category:
Admin Jobs
Tags: ArcSight Automation CEH CISSP Cloud Compliance Cyber Kill Chain DDoS DNS EDR Firewalls LogRhythm Monitoring QRadar Sentinel SIEM SOC Splunk Threat intelligence TTPs
Region:
Asia/Pacific
Country:
India
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Senior Security Analyst jobsInformation System Security Officer jobsSenior Cloud Security Engineer jobsInformation Security Manager jobsInformation Security Specialist jobsSenior Cybersecurity Engineer jobsSenior Network Security Engineer jobsSecurity Consultant jobsIT Security Engineer jobsCyber Security Specialist jobsSenior Penetration Tester jobsSecurity Specialist jobsSenior Information Security Analyst jobsSenior Cyber Security Engineer jobsChief Information Security Officer jobsSystems Engineer jobsSystems Administrator jobsInformation System Security Officer (ISSO) jobsSenior Product Security Engineer jobsCloud Security Architect jobsIT Security Analyst jobsPrincipal Security Engineer jobsStaff Security Engineer jobsSecurity Operations Analyst jobsCybersecurity Specialist jobs
DevSecOps jobsKubernetes jobsEncryption jobsPowerShell jobsIDS jobsSplunk jobsSaaS jobsEDR jobsSDLC jobsIPS jobsRMF jobsSQL jobsTop Secret jobsIntrusion detection jobsBash jobsCompTIA jobsThreat detection jobsITIL jobsFinance jobsOWASP jobsDoDD 8570 jobsCRISC jobsDocker jobsActive Directory jobsBanking jobs
UNIX jobsTCP/IP jobsVPN jobsGIAC jobsTerraform jobsSANS jobsClearance Required jobsIT infrastructure jobsHIPAA jobsSOX jobsSOC 2 jobsOSCP jobsCISO jobsIndustrial jobsJavaScript jobsCCSP jobsData Analytics jobsDNS jobsSOAR jobsPolygraph jobsJira jobsAnsible jobsMITRE ATT&CK jobsCyber defense jobsGCIH jobs