Description

SIEM Engineer

Remote Job |   2024-05-28 10:37:38

Apply Now

Share Job 

Job Code : 129862

Position: SIEM Engineer

Location: Remote

Duration: 6+ Months; Strong potential for extension into 2025

 

Our client in the financial services domain is seeking a candidate to help grow and improve the Cyber Development and Testing team. The team handles the end-to-end process of the development of new security use cases. This function touches many different teams and requires both a wide and deep understanding of several different information security concepts and how they function and apply to a corporate enterprise environment. The candidate should have an established background in information security and should have experience with both the development and testing of security cases that serves a large organization.

The candidate will be assisting the US Cyber Threat Detection Lead in the organization’s migration to cloud. This entails the testing of existing use cases, testing of new use cases, development of new use cases in the new Cloud SIEM tenant, facilitating requests between entities, and generally being available to assist with any activities related to Threat Detection.

Required Skills:

  • Splunk (developer-level)
  • AWS (intermediate). Familiarity with AWS CloudTrail and GuardDuty is a huge plus
  • JIRA (or any agile based platform)

 

Additional Skills: Financial/Banking experience is a plus

Required Experience:
- 3-4 years of experience
- Security log analysis
- Analysis of use case requirements
- Creating efficient and performant correlation search queries which will become security use cases, reports, or dashboards
- Recognizing and identifying patterns in data that will drive decision-making
- Designing, implementing, and executing testing procedures for new and existing security alerts
- Communicating effectively across several different teams and entities
- Effective communication as to the status of weekly, monthly, and quarterly project deadlines and deliverables
- Effective, precise, and detailed documentation in regard to the development and testing of security use cases

Ideal candidate will have:
- Splunk (developer-level)
- AWS (intermediate). Familiarity with AWS CloudTrail and GuardDuty is a huge plus
- JIRA (or any agile based platform)

Key Skills
Education

Any Graduate