- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 hour ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Job Overview
This position involves taking charge of designing, deploying, and overseeing Security Information and Event Management (SIEM) solutions. The focus is on enhancing security monitoring, threat detection, and managing incident response to improve the organization's security framework. Candidates should have strong expertise with SIEM platforms such as Splunk, Microsoft Sentinel, or equivalent technologies, encompassing capabilities in security integrations, log data administration, crafting detection rules, and Security Operations Center (SOC) functions. The role is centered on refining SIEM utility, bolstering security measures, and collaborating with relevant teams to strengthen the security posture.
Key Duties and Responsibilities
- Architect, implement, test, maintain, and troubleshoot SIEM infrastructure and deployments.
- Handle all dependencies and prerequisites for SIEM projects, including connectivity, storage, licensing, and equipment management.
- Execute updates, patches, and upgrades to the SIEM infrastructure, conduct regular health assessments, and produce comprehensive reports tracking performance and effectiveness.
- Manage physical or virtual SIEM appliances, including operating systems and SIEM software components.
- Configure backup procedures, verify custom reports, manage log source grouping, and validate data sources.
- Administer SIEM user accounts with tasks such as creation, modification, and deletion.
- Add or remove log sources, troubleshoot related issues in coordination with system owners and vendors, and demand system upgrades or feature enhancements when necessary.
- Develop integrations, connectors, and parsers for new event sources to enrich SIEM data collection.
- Create and implement security monitoring rules aligned with business requirements.
- Enhance SIEM system capabilities to maximize effectiveness and identify automation opportunities.
- Formulate rules and reports that satisfy compliance and audit requirements and maintain watchlists for emerging threats.
- Produce detailed engineering and security documentation including system design, as-built records, custom connectors, and integration guides.
- Assist in defining and documenting SOC operational procedures.
- Mentor and train junior SIEM engineers to build team expertise.
- Perform additional responsibilities as assigned.
Required Qualifications and Experience
- Degree in Engineering, Computer Science, Economics, or a closely related field.
- At least five years of experience in security engineering, with a minimum of three years managing SIEM solutions.
- Proven capability in designing and executing SIEM systems.
- Experience integrating various security technologies such as antivirus, AAA, firewalls, DLP, and IDS/IPS within SIEM frameworks.
- Expertise applying SIEM monitoring in cloud environments including AWS, Azure, Google Cloud Platform, and Oracle Cloud Infrastructure.
- Proficiency with SIEM platforms like Splunk, Microsoft Sentinel, and Google SecOps.
- Strong understanding of information security laws, standards, and mapping these needs to SIEM implementations.
- Solid knowledge of information security principles and networking fundamentals.
- Hands-on experience with scripting and query languages relevant to SIEM data ingestion, including Python, Regular Expressions, SPL, and KQL.
- Excellent organizational and time management skills.
- Availability for On-Call duties during nights or weekends as needed.
- Ability to meet tight deadlines and deliver quality work.
- Capable of prioritizing multi-stakeholder tasks effectively.
- Superior communication skills, both written and verbal, with the ability to explain complex technical topics to non-technical parties.
- Strong analytical skills with a focus on root cause analysis and problem resolution.
- Ability to manage high-demand, customer-focused environments involving multiple internal and external stakeholders.
Preferred Skills and Experience
- Experience working in the Gulf region.
- Background with Managed Security Service Providers (MSSP) or Managed Detection and Response (MDR) providers.
- Exposure to deploying and administering multiple SIEM platforms.
- Relevant certifications such as Splunk, Microsoft Sentinel, or Google SecOps administration and management.
Level
Senior
Minimum education
Bachelor's Degree