SIEM Automation Engineer

Entelligence LLC

Yesterday
Secret
Unspecified
Unspecified
SIEM Automation Engineer (On-Site/Office)

Entelligence is seeking a SIEM Engineer to support our clients. The successful candidate must be able to work in a cross-functional environment and interact with representatives from Entelligence and the end-user.

The Consultantwill function as the Palo Alto products Subject Matter Expert (SME) and will interact directly with the customer's personnel. The Engineer will serve as the technical expert on executive-level project teams within the customer providing technical direction, interpretation, and alternatives. The Engineer contributes to the development of new principles and concepts, works on unusually complex technical problems and provides solutions which are highly innovative and ingenious.

Key Responsibilities
  • Work with technical lead to develop log ingestion strategy
  • Contribute to detection strategy based on industry best practices
  • Detail step by step process to ingest high quality log sources
  • Perform log source monitoring and optimization
  • Create high quality correlation rules
  • Tune log sources and correlation rules
  • Be an SME for SIEM, Correlation and Log Source Ingestion
  • Recognize opportunities where automation can improve analyst alert handling
  • Collaborate with internal and external teams to ensure product adoption
  • Create technical documentation detailing SIEM aspects of the engagement
  • Travel to customer meetings and workshops as needed (10%)

What You Bring

  • Strong communication (written and verbal) and presentation skills, both internally and externally
  • Fluent English is a requirement - Any other language is a plus
  • 6+ years of deploying and integrating (SIEM) to enterprise to large enterprise-level
  • Coordinating and conducting event collection, log management, event management, compliance automation, and identity monitoring activities using (SIEM) platforms
  • The ability to create and develop correlation and detection rules, within a (SIEM) to support alerting capabilities
  • Experience working with and deploying a variety of SIEM technologies (i.e Splunk, IBM QRadar)
  • A proven ability to offer suggestions on detection strategy based on customer requirements
  • Strong Regular Expression skills
  • Ability to understand logs, locating and understanding 3rd party documentation where needed
  • Familiarity with reports on the status of the SIEM to include metrics on items such as number of logging sources - log collection rate, and other performance metrics
  • Knowledge of Security Analysis & Response a plus, including both endpoint, network & cloud based environments
  • 4 years experience with Security Operation Centers tooling and processes
  • Relevant bachelor's degree or industry recognized qualifications (CISSP, GIAC, SIEM Vendor Qualification etc)
  • Ability to read and understand technical design documentation
  • Ability to create technical design documentation

BENEFITS

  • Competitive base salary
  • Medical, dental, vision and life insurance
  • Vacation, sick time and paid holidays
  • Matching 401(k) program

Keywords: SOC, XSOAR/SOAR, Python, SIEM/XSIAM, Automation, EDR/XDR, Engineer, Cortex, Palo Alto, Cyber Security

Entelligence helps fast-growing technology companies scale smarter and grow faster through our innovative Ensourcing Platform. By delivering turnkey technical services under your brand, we integrate elite talent into your team and processes-accelerating product adoption, reducing churn, and driving enterprise value without added headcount or complexity.

Guided by our purpose to elevate the lives of our people, customers, and community, we are committed to our Big Hairy Audacious Goal (BHAG) of feeding 1 billion people in the next decade. Proudly CertifiedTM by Great Place to Work® and recognized as a Fortune Best Place to Work, we transform businesses and lives.
//HEREFISH
window.hfDomain = “https://api.herefish.com”;
window.hfAccountId = "461cee80-4d87-4951-9972-95772bebe59f";
(function() {
var hf = document.createElement("script"); hf.type = "text/javascript"; hf.async = true;
hf.src = window.hfDomain + "scripts/hf.js";
var s = document.getElementsByTagName("script")[0]; s.parentNode.insertBefore(hf, s);
})();
group id: ENTEL
N
Name HiddenRecruiter

Match Score

Powered by IntelliSearch™
Create an account or Login to see how closely you match to this job!

Similar Jobs


Clearance Level
Secret