Executes the lifecycle of security information and event management (SIEM) rules, reports, and dashboards to present actionable threats to Intrusion Analysts by refining existing rule logic; collaborating with Intrusion Analysts, Dynamic Defense Engineers, and Senior SIEM Engineers; creating new rules and reports; and removing outdated rules and reports.
Maintains security information and event management (SIEM) infrastructure by monitoring metrics for efficiency and effectiveness; performing software and hardware upgrades; creating and managing documentation related to incident and change tracking; maintaining existing SIEM documentation; participating in pager rotation for on call support; opening trouble tickets with vendors; and following up to ensure resolution of open trouble tickets.
Educates and partners with internal customer teams (for example, Compliance, Cybersecurity Risk Assessment, Infrastructure) to ensure appropriate threat monitoring by gathering information about system and software solutions in accordance with company audit trail standards.
Supports senior engineers in architecture and engineering design by contributing to strategy and design meetings; and acquiring new data feeds.
Outlined below are the required minimum qualifications for this position. If none are listed, there are no minimum qualifications.Minimum Qualifications: Bachelor’s degree in Computer Science, Information Technology, Engineering, Computer Information Systems, or related field and 2 years' experience in information technology or related field within the last 6 years OR 4 years' experience in information technology or related field within the last 6 years. 1 year's experience with a log analysis/SIEM product (for example, Splunk, ArcSight, Qradar, Nitro) OR 1 year's experience with manual security log review and analysis (for example, Windows Event Log, Linux Syslog).
Outlined below are the optional preferred qualifications for this position. If none are listed, there are no preferred qualifications.Corporate Security, Customer Care, Information Security, Information Technology, Security - Executive Protection, SupportCCNA - Cisco Certified Network Administrator - Certification, CISA - Certified Information Systems Auditor - Certification, CISSP - Certified Information Systems Security Professional - Certification, GCIH - GIAC Certified Incident Handler - Certification