Source description
About the role
Key Responsibilities: SIEM Implementation & Management: Configure and manage Google Chronicle SIEM and other leading SIEM technologies such as Splunk, QRadar, LogRhythm, Nitro . Security Event Analysis: Monitor, analyze, and respond to security events, ensuring effective detection and mitigation of threats. Threat Hunting & Incident Response: Identify attack patterns and respond to potential threats using the Cyber Kill Chain, MITRE ATT&CK framework, and various TTPs . Detection & Prevention: Develop custom detection rules in SIEM and EDR solutions to mitigate security risks. Cloud Security Monitoring: Detect and prevent cloud-based threats , leveraging cloud logging and audit capabilities. Network & Security Infrastructure: Understand and analyze security logs from network devices, IDS/IPS, firewalls, DLP solutions, and EDR platforms . Security Best Practices: Maintain awareness of emerging threats and vulnerabilities, recommending improvements to security posture. 24x7 Support: Work in shifts on a rotating basis to ensure continuous security monitoring and response. Required Skills & Qualifications: Bachelor's degree in computer science, Information Systems, Cybersecurity, or related field (or equivalent work experience). Certifications: CISSP, CEH, or equivalent cybersecurity certifications. 3-5 years of experience in security information & technology engineering support . Hands-on experience with SIEM tools like Google Chronicle, Splunk, QRadar, LogRhythm, Nitro . Deep understanding of security attack activities such as network probing, DDoS, malware, exfiltration, credential access . Familiarity with logging mechanisms and security data from network devices, firewalls, IDS/IPS, cloud services . Experience with network protocols (IP, DNS, HTTP) and knowledge of network stack components. Understanding of Cloud Security Threats and the ability to develop detection rules for cloud-based environments. Strong analytical and problem-solving skills , with a proactive security mindset. Excellent communication and collaboration skills to work with security teams and stakeholders.
More at NUBES OPUS LLC