Mid-level (3 to 4 years), Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
FinTech, Payments, CybersecurityIndustries
Requirements
Bachelor's degree in Computer Science, Information Security, or related field (or related work experience)
Typically minimum 2 years of relevant experience
Responsibilities
Build and maintain security alert content: Design, create, and manage effective alert content within the SIEM platform to identify potential security incidents, ensuring high-quality, accurate detection of threats across the network and systems
Maintain the SIEM environment: Oversee the day-to-day operations of the SIEM system, ensuring it runs smoothly, troubleshooting and resolving issues to maintain optimal performance and security
Keep up to date with knowledge of emerging threats: Continuously monitor the cybersecurity landscape for emerging threats, vulnerabilities, and attack techniques to update alerting rules and maintain the relevance of security detection
Work with Risk-Based Alerting (RBA): Implement and fine-tune risk-based alerting strategies, ensuring that the SIEM platform effectively prioritizes alerts based on potential impact, minimizing noise and increasing the focus on critical threats
Work directly with the Security Automation Team: Collaborate closely with the Security Automation Team to integrate automated processes for alert management, response, and remediation, enhancing efficiency and reducing the time to mitigate risks
Build and maintain applicable documentation: Create and update detailed documentation for alerting configurations, processes, and procedures, ensuring transparency and consistency in security operations
Participate in strategic planning and development of the SIEM environment: Contribute to the long-term vision and strategy for the SIEM platform, including capacity planning, scalability, and the implementation of new technologies or methodologies to improve security monitoring
Integrate new data sources into the SIEM system: Identify, assess, and implement relevant data sources to enhance the SIEM’s detection capabilities, expanding visibility across diverse systems, applications, and network devices
Collaborate with cross-functional teams: Work with security architects, incident response teams, and other stakeholders to align the SIEM environment with organizational security goals and ensure smooth collaboration during security incidents
Ensure compliance with security standards and best practices: Regularly review and ensure that all alerting and SIEM configurations comply with internal security standards, industry best practices, and relevant regulatory requirements, maintaining the integrity of the security posture