Description
You will manage and optimize security operations through advanced SIEM administration and SOAR automation.
Responsibilities
- Coordinate event collection, log management, and identity monitoring using SIEM platforms.
- Integrate SIEM, threat intelligence, and ticketing systems to build automated workflows.
- Develop custom log sources, data connectors, and parsing rules.
- Create and optimize correlation rules, detection rules, and alerts for security incidents.
- Design and manage automated response playbooks within SOAR platforms.
- Generate technical documentation and performance reports regarding SIEM/SOAR effectiveness and compliance.
Required Skills
- 5+ years of professional experience in Cybersecurity with a focus on SIEM administration.
- Subject Matter Expertise in SIEM, correlation, and log source ingestion.
- Hands-on experience deploying SIEM technologies such as Splunk or CrowdStrike.
- Strong experience with SOAR platforms and automated workflow design.
- In-depth knowledge of SIEM architecture, data collection, and alerting mechanisms.
- Experience with cloud security platforms including Azure, AWS, and GCP.
- Ability to create technical documentation and performance metrics for logging sources.
- Bachelor's degree in Cybersecurity, Computer Science, IT, or equivalent experience.