Job Openings
Security Implementation role - SIEM -Splunk
About the job Security Implementation role - SIEM -Splunk
Job Title: SIEM Lead (Splunk)
Experience: 10-12 Years
Job Overview:
As a SIEM Lead, you will play a crucial role in protecting the organization's IT infrastructure by leveraging Security Information and Event Management (SIEM) solutions. You will be responsible for optimizing, maintaining, and enhancing SIEM solutions, preferably Splunk, ensuring they effectively detect, investigate, and respond to security incidents within a Security Operations Center (SOC) environment.
Key Responsibilities:
- Manage and optimize the SIEM platform, including configuration, log source management, rule development, and performance tuning.
- Design, develop, and implement security correlation rules and alerts to detect potential threats and suspicious activities.
- Conduct security incident investigations using SIEM, analyze logs, and determine root causes.
- Collaborate with the security team to develop and implement incident response procedures and playbooks.
- Create and manage Knowledge Objects required for a SOC environment.
- Utilize SOAR (Security Orchestration, Automation, and Response) tools to automate incident response tasks and workflows.
- Stay updated on the latest SIEM technologies, threat intelligence, and security best practices.
- Provide technical guidance and support to the security team on SIEM-related matters.
- Participate in security assessments and vulnerability management initiatives.
- Document SIEM processes, procedures, and configurations.
Qualifications & Skills:
- 7-8 years of experience working with SIEM solutions, preferably Splunk. Additional experience with MS Sentinel, LogRhythm, ArcSight, or QRadar is a plus.
- Proven expertise in developing and implementing security correlation rules and alerts.
- Strong knowledge of security incident investigation and response methodologies (e.g., DFIR).
- Experience with SOAR tools (preferably Phantom) and security automation concepts.
- Excellent analytical and problem-solving abilities.
- Strong communication and collaboration skills.
- Ability to work both independently and as part of a team.
- Passion for cybersecurity with a keen interest in staying updated on emerging threats and vulnerabilities.
Preferred Qualifications:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Certifications such as Certified Splunk Administrator (CSA) or any Splunk certification; other SIEM certifications would be an advantage.
- Hands-on experience with SIEM solutions in cloud environments.
- Experience working in a Security Operations Center (SOC) environment.
- Strong understanding of security orchestration, automation, and response (SOAR) tools.
If you are a cybersecurity professional with expertise in SIEM solutions and a passion for security, we invite you to apply and be part of a dynamic security team.
--