Security event detection, triage and threat analysis for complex and/or escalated security events
Provide log/network/malware/device analysis and making recommendations for remediation of security vulnerability conditions
Recognize potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information
Ensure threat intelligence feeds are appropriately utilized by security devices within CUSTOMER?s infrastructure
Manage CUSTOMER?s SIEM administration & fine-tuning/ optimization related activities
Provide on-job training to CUSTOMER?s Information Security resources
B. Qualifications:
Experience with SIEM solution including log management configuration, log correlation, log analysis, and log archival processes
Experience in monitoring and analyzing data feeds of events and logs from firewalls, routers, and other network devices or hosts for security violations.
Research and document threats and their behavior.
Knowledge in all aspects of cyber threat management including cyber forensics, incident response, antivirus & patch management.
Hands-on experience on Splunk tool
Hands-on experience on onboarding / integrating log sources with SIEM
Ability to create/develop use cases to detect attacks and suspicious activities
Ability to handle the day to day administration and troubleshooting for SIEM.