SIEM Engineer II
Job description
About the role
As a , you will play a crucial role in enhancing our security information and event management (SIEM) capabilities. This position is designed for individuals who have a solid background in cybersecurity and are eager to tackle complex security challenges. You will be responsible for implementing, maintaining, and optimizing SIEM solutions to ensure the security of our systems and data. Your expertise will help us identify and respond to potential threats effectively, contributing to a safer digital environment for our clients.
Key facts
What you'll do
- Design, implement, and manage SIEM solutions to monitor and analyze security events across the organization.
- Collaborate with cross-functional teams to gather requirements and ensure the SIEM system meets organizational needs.
- Develop and maintain use cases for threat detection, ensuring they are aligned with industry best practices and regulatory requirements.
- Conduct regular reviews and updates of SIEM configurations to enhance detection capabilities and reduce false positives.
- Analyze security incidents and alerts generated by the SIEM system, providing timely and accurate incident response.
- Create and maintain documentation related to SIEM processes, configurations, and incident response procedures.
- Train and mentor junior team members on SIEM best practices, tools, and methodologies.
- Stay updated on the latest cybersecurity threats, vulnerabilities, and trends to ensure the SIEM system is equipped to handle emerging risks.
- Participate in security assessments and audits to evaluate the effectiveness of the SIEM system and recommend improvements.
- Collaborate with external vendors and partners to integrate additional security tools and technologies into the SIEM ecosystem.
- Provide regular reports and metrics on security incidents, trends, and the overall effectiveness of the SIEM system to management.
- Assist in the development of security policies and procedures related to SIEM operations and incident response.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A minimum of 3 years of experience in a cybersecurity role, with a focus on SIEM technologies.
- Proficiency in SIEM tools such as Securonix, Splunk, or similar platforms.
- Strong understanding of security frameworks and standards, including NIST, ISO 27001, and CIS.
- Experience with scripting and automation tools to enhance SIEM functionality and reporting.
- Knowledge of network protocols, threat detection methodologies, and incident response processes.
- Excellent analytical and problem-solving skills, with a keen attention to detail.
- Strong communication skills, both verbal and written, to effectively convey technical information to non-technical stakeholders.
- Ability to work independently and as part of a team in a fast-paced environment.
- Relevant certifications such as CISSP, CISM, or CEH are highly desirable.
Nice to have
- Familiarity with cloud security principles and technologies, particularly in AWS or Azure environments.
- Experience with machine learning and AI applications in cybersecurity.
- Knowledge of compliance requirements such as GDPR, HIPAA, or PCI-DSS.
- Previous experience in a security operations center (SOC) environment.
- Understanding of endpoint detection and response (EDR) solutions.
Skills & tools
- Proficient in security information and event management (SIEM) tools.
- Familiar with scripting languages such as Python, PowerShell, or Bash.
- Knowledge of intrusion detection systems (IDS) and intrusion prevention systems (IPS).
- Experience with vulnerability assessment tools and methodologies.
- Familiarity with ticketing systems and incident management processes.
Practical notes
- The specific location for this position is currently unspecified.
- The salary is competitive and will be determined based on the candidate's experience and qualifications.
- Visa sponsorship options are available for qualified applicants, making this an inclusive opportunity for international candidates.
Join Securonix as a SIEM Engineer II and be part of a dynamic team dedicated to protecting our clients' digital assets. Your expertise will be instrumental in shaping our security posture and driving innovation in our SIEM capabilities. If you are passionate about cybersecurity and eager to make a difference, we encourage you to apply today.