Role Overview:
The SIEM Engineer will be responsible for designing, implementing, administering, and optimizing SIEM platforms and security monitoring capabilities across enterprise and cloud environments. The role involves managing log sources, integrations, detection rules, system health, and security monitoring while supporting compliance and SOC operations.
Key Responsibilities:
- Design, implement, maintain, and troubleshoot SIEM infrastructure and deployments.
- Manage SIEM platforms such as Splunk, Microsoft Sentinel, or Google SecOps.
- Integrate security technologies including Firewalls, AV, AAA, DLP, IDS/IPS, and other security tools.
- Onboard and manage log sources, connectors, parsers, and custom integrations.
- Develop and maintain security monitoring rules, alerts, reports, watchlists, and compliance use cases.
- Integrate and monitor cloud security logs across AWS, Azure, GCP, and OCI environments.
- Perform SIEM health checks, upgrades, patching, backups, optimization, and troubleshooting.
- Develop SIEM queries and scripts using technologies such as SPL, KQL, Python, and Regex.
- Prepare technical designs, documentation, health reports, and solution-related deliverables.
- Support SOC processes, automation initiatives, and continuous improvement of SIEM capabilities.
- Mentor junior SIEM engineers and collaborate with internal teams, clients, and technology vendors.
Requirements:
- Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field.
- 5+ years of experience in Security Engineering, with at least 3 years of hands-on SIEM experience.
- Strong knowledge of information security, networking, security monitoring, and relevant security frameworks.
- Hands-on experience with at least one major SIEM platform such as Splunk, Microsoft Sentinel, or Google SecOps.
- Strong experience in SIEM architecture, implementation, administration, integrations, and log management.
- Experience with cloud security monitoring and cloud-native log sources.
- Strong analytical, troubleshooting, communication, and stakeholder management skills.
- Ability to work in an on-call environment, including nights or weekends when required.
Preferred -
- MSSP/MDR experience and regional experience.
- Experience managing multiple SIEM technologies.
- Relevant SIEM certifications such as Splunk, Microsoft Sentinel, or Google SecOps certifications.
- Experience with SIEM automation, custom parsers, connectors, and security use-case development.