Jump to content

COMPLETE Security Specialist- SIEM Admin

22 days ago


 Share

Job Opportunity Details

Type

Full Time

Salary

Not Telling

Work from home

No

Weekly Working Hours

Not Telling

Positions

Not Telling

Working Location

Pune, Pune, Maharashtra, India   [ View map ]
Introduction
At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most challenging problems? If so, lets talk.

Your Role and Responsibilities
The Security Analyst monitors security events from the various SOC entry channels (SIEM, Tickets, Email and Phone), based on the security event severity, escalate to managed service support teams, tier2 information security specialists, and/or customer as appropriate to perform further investigation and resolution.

Responsibilities:
  • Good knowledge of SIEM, SIEM Architecture, SIEM health check.
  • Deployment of SIEM in customer environment.
  • Audit the SIEM in the customer environment.
  • Troubleshoot issues regarding SIEM and other SOC tools.
  • Good verbal/written communication skills.
  • Build of use case for the customer.
  • Data archiving and backup and data purging configuration as per need and compliance.
  • Raising change management tickets for SOC Administration activities like Patch upgrade for SIEM, onboarding log sources etc.
  • Helping L2 and L1 with required knowledge base details and basic documentations.
  • Co-ordination with L2 and SOC Monitoring team for troubleshooting issues and highlighting them to clients for further resolution and escalation.
  • High ethics, ability to protect confidential information.
  • Troubleshooting at device and connector/agent end to fix the anomaly reported by other team and observed on day to day basis.
  • Building of incident reports, advisories and review if SLA has been met for Incident alerting and Incident closure.
  • Update and maintain SOC knowledge base for new security incidents and docs.
  • Creation of daily status report sheet and submit to SOC manager for review.
  • Review advisories and make necessary detection measures.
  • Provide analysis and trending of security log data from a large number of security devices.
  • Troubleshooting non-reporting devices fix and maintain device status.
  • Working with OEM (Tool support) in a way to resolve the issue or incident raised.
  • Administration of Windows and Unix servers.
  • Building Parser for the SIEM using regex.
  • Ready to work on 24/7 shifts to support client requirement.


Required Technical and Professional Expertise
  • 5 to 8 Years of Experience in SOC and min. 3 years on Qradar SIEM Engineering
  • Exposure to next generation SOC (2.0)
  • Escalation point for L2 and Soc Monitor team.
  • Ability to drive call and summarizing it post discussion.
  • Handsome experience in SIEM administration and Event flow architecture and different types of logs generated by devices like Windows, Proxy, Network Devices, Database…etc.
  • Good Understanding of Firewall, IDP/IPS, SIEM functioning (Generalize HLD as well as LLD).
  • Deep understanding on Windows, DB, Mail cluster, VM and Linux commands.
  • Knowledge of network protocols TCP/IP and ports.
  • Team Spirit and working ideas heading to resolution of issues.


Preferred Technical and Professional Expertise
  • Qualifications like CISA, CISM, CISSP, CEH, SANS or any other recognized qualification in Cybersecurity (SIEM/Qradar certification) will be preferred.
  • Thorough knowledge in SIEM tool and experience in networking, Cloud security experience will be preferred.
  • You love collaborative environments that use agile methodologies to encourage creative design thinking and find innovative ways to develop with cutting edge technologies
  • Ambitious individual who can work under their own direction towards agreed targets/goals and with creative approach to work
  • Intuitive individual with an ability to manage change and proven time management
  • Proven interpersonal skills while contributing to team effort by accomplishing related results as needed
  • Up-to-date technical knowledge by attending educational workshops, reviewing publications

More Information

Application Details

  • Organization Details
    IBM IN
 Share


User Feedback

Recommended Comments

There are no comments to display.

Join the conversation

You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Add a comment...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...