Source description
About the role
Ø Develop and implement content for any SIEM platforms, including Google Chronicle, Sumologic, and Splunk. Ø Configure and fine-tune use cases, correlation, grouping, and logical rules in SIEM tools. Ø Integrate new log sources, assets with SIEM, and incremental threat intelligence feeds. Ø Draft, test, and deploy YARA and Chronicle Backstory rules. Ø Curate and update Incident Response Guides. Ø Customize SIGMA rules and maintain familiarity with the MITRE ATT&CK Framework. Ø Develop threat detection content for various datasets such as Proxy, VPN, Firewall, and DLP. Ø Aid in process development/improvement for Security Operations. Ø Recognize and propose new security controls to bridge existing gaps. Ø Chronicle Backstory/ ELK Stack/ YARA / CrowdStrike rules experience is a plus. Skills:- Security Information and Event Management (SIEM), Google Chronicle, Sumologic, Splunk and Crowdstrike