SIEM Administrator
Hybrid
Blue Mantis
Blue Mantis is a leading systems integrator and cloud services company helping clients move toward software-defined, hyper-converged, and hybrid cloud infrastructure models to drive IT transformation.
SIEM Administrator
Department: Blue Mantis
Employment Type: Full Time
Location: Hybrid
Description
The SIEM Administrator is a critical and essential member of our 24x7 Security Operations team, responsible for the configuration of SIEM integrations, development and tuning of detection models, and customization of dashboards and reports. The ideal candidate is a passionate technologist, with a background in SIEM development and administration. The candidate should be familiar with various threat attack methods and frameworks, such as MITRE ATT&CK®. The SIEM administrator must be a strong collaborator capable of working collaboratively with penetration testing consultants, security analysts, threat hunters, and intelligence analysts to develop and refine the SIEM models.Key Responsibilities
- Operates and maintains SIEM tools and components, such as log aggregators, forwarders, and data observability systems.
- Develops, tests, implements, and tunes new threat detection models.
- Develops content that enables cybersecurity personnel to take the maximum advantage of existing tool capabilities, including SOAR workflows, integrations, and automated tasks.
- Collaborates across cybersecurity roles and teams to integrate SIEM components with cybersecurity enrichment and analysis platforms and systems management tools.
- Creates and maintains architectural documentation and operational procedures that describe the scope, purpose, configuration, use and maintenance of the SIEM tools and environments.
Skills, Knowledge & Expertise
- 3+ years of experience working with a SIEM solution.
- Basic understanding of TCP/IP, DNS, DHCP, SMTP, FTP, and HTTP.
- Knowledge of SQL queries, having handled MYSQL or any RDBMS.
- Skill with scripting languages such as Python, Perl or Bash is a plus.
- Be a positive team player.
- Be a self-starter and take initiative.
- Ability to perform research, read documentation, and independently learn new skills.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
3
0
0
Category:
Admin Jobs
Tags: Bash DNS MITRE ATT&CK MySQL Pentesting Perl Python RDBMS Scripting SIEM SMTP SOAR SQL TCP/IP Threat detection
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Systems Security Officer jobsSenior Cloud Security Engineer jobsInformation System Security Officer jobsSenior Cybersecurity Engineer jobsInformation Security Specialist jobsInformation Security Manager jobsSenior Network Security Engineer jobsSecurity Consultant jobsCyber Security Specialist jobsIT Security Engineer jobsSecurity Specialist jobsSenior Information Security Analyst jobsSenior Penetration Tester jobsIT Security Analyst jobsSenior Cyber Security Engineer jobsSystems Engineer jobsChief Information Security Officer jobsSystems Administrator jobsStaff Security Engineer jobsInformation System Security Officer (ISSO) jobsPrincipal Security Engineer jobsThreat Intelligence Analyst jobsSenior Product Security Engineer jobsCloud Security Architect jobsInformation Systems Security Engineer jobs
GDPR jobsEncryption jobsPowerShell jobsDevSecOps jobsEDR jobsSaaS jobsIDS jobsSplunk jobsSDLC jobsRMF jobsIPS jobsTop Secret jobsSQL jobsIntrusion detection jobsBash jobsThreat detection jobsActive Directory jobsCompTIA jobsDoDD 8570 jobsITIL jobsOWASP jobsDocker jobsBanking jobsCRISC jobsUNIX jobs
Finance jobsTCP/IP jobsClearance Required jobsGIAC jobsCISO jobsIndustrial jobsTerraform jobsHIPAA jobsIT infrastructure jobsSOC 2 jobsSANS jobsJavaScript jobsVPN jobsOSCP jobsCCSP jobsMITRE ATT&CK jobsSOAR jobsJira jobsDNS jobsSOX jobsData Analytics jobsPolygraph jobsNIST 800-53 jobsGCIH jobsSecurity strategy jobs