SIEM Administrator

Pune, IN

IBM

For more than a century, IBM has been a global technology innovator, leading advances in AI, automation and hybrid cloud solutions that help businesses grow.

View all jobs at IBM

Apply now Apply later

Introduction
Information and Data are some of the most important organizational assets in today’s businesses. As a Security Consultant, you will be a key advisor for IBM’s clients, analyzing business requirements to design and implement the best security solutions for their needs. You will apply your technical skills to find the balance between enabling and securing the client’s organization with the cognitive solutions that are making IBM the fastest growing enterprise security business in the world.

Your Role and Responsibilities
As a SIEM Engineer you will be responsible for implementation and deployment of new SIEM projects; and managing and providing SIEM health and operational support, including supporting to architecture changes, tool deployments and advanced detection engineering.

Responsibilities

  • Understand SIEM product architecture.
  • Ensure up-time of SIEM components.
  • Perform daily SIEM Health Check & Availability monitoring.
  • Understanding logs, Log formats, identify appropriate information for Log parsing and SIEM rule creation, Log Source Review
  • Suggest logging levels and baseline log sources.
  • Understanding of Log sources such as Operating System, Database, Web servers, Security and Network Technologies
  • SIEM Content Development Keep a track of latest patches major version upgrades released by vendors.
  • Log Retention Define and manage the log retention for all integrated devices as per defined agreement.
  • Data Enrichment and asset modelling.
  • Custom integration – Develop parsers for non-supported log sources as per scope.
  • You will be closely working with Security Operations Center (SOC), Threat Intelligence, Threat Hunt, Automation and Orchestration teams to develop and operationalize meaningful security alerting and ensuring platform health and uptime.
  • SIEM (Cortex XSIAM\\Splunk, Chronicle\\Qradar\\Micro Focus ArcSight\\Microsoft Sentinel\\LogRhythm\\Nitro) configuration management, troubleshooting, addressing complex issues and day to day operations management.
  • Keep abreast of latest IT security, regulatory and compliance trends to support various risk\\data models.
  • Ready to work in 24×7 rotational shift model including night shift.


Required Technical and Professional Expertise

  • 8 to 10 years’ relevant experience in security information and or technology engineering support.
  • Experience with the following technologies : leading SIEM technologies (Cortex XSIAM\\Splunk, Chronicle\\ Qradar\\Micro Focus ArcSight\\Microsoft Sentinel\\LogRhythm\\Nitro) IDSIPS, network- and host- based firewalls, data leakage protection (DLP), common EDR platforms etc.
  • Understanding of possible attack activities such as network probing scanning, DDOS, malicious code activity, exfiltration, credential access, etc.
  • An understanding of the Cyber Kill Chain, the MITRE attack framework, various TTPs described within and commonly used by attackers as well as how to write detection rules for them in SIEM and EDR solution.
  • Understanding of tools, technologies and logging mechanism including understanding to common network devices such as routers, switches, load balancers etc.
  • Understanding of typical cloud threats and knowledge of how to detect and prevent them, cloud logging and audit capabilities and the ability to develop detection rules around these.
  • Understanding of basic networking protocols such as IP, DNS, HTTP, and the network s
  • Basic knowledge in system security architecture and security solutions.


Preferred Technical and Professional Expertise

  • CISSP, CEH or equivalent.

Key Job Details
Role:SIEM Administrator Location:Pune, IN Category:Consulting Employment Type:Full-Time Travel Required:No Travel Contract Type:Regular Company:(0063) IBM India Private Limited Req ID:726321BR

Apply now Apply later
  • Share this job via
  • 𝕏
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0
Category: Admin Jobs

Tags: ArcSight Automation CEH CISSP Cloud Compliance Cyber Kill Chain DDoS DNS EDR Firewalls LogRhythm Monitoring QRadar Sentinel SIEM SOC Splunk Threat intelligence TTPs

Region: Asia/Pacific
Country: India

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.