
ColorTokens - Platform Engineer - SIEM
3 weeks ago
Job Title : Platform Engineer
About ColorTokens
At ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape.
Breaches happenbut with our cutting-edge ColorTokens Xshield platform, companies can minimize the impact of breaches by preventing the lateral spread of ransomware and advanced malware.
We enable organizations to continue operating while breaches are contained, ensuring critical assets remain protected.
Our innovative platform provides unparalleled visibility into traffic patterns between workloads, OT/IoT/IoMT devices, and users, allowing businesses to enforce granular micro-perimeters, swiftly isolate key assets, and respond to breaches with agility.
Recognized as a Leader in the Forrester Wave : Microsegmentation Solutions (Q3 2024), ColorTokens safeguards global enterprises and delivers significant savings by preventing costly Overview :
Colortokens is looking for a Junior Platform Administrator to assist in managing, maintaining, and optimizing our NextGen Security Information and Event Management (SIEM) platform.
The ideal candidate will support the day-to-day operations, help onboard customer log sources, troubleshoot integration issues, and provide technical assistance to the security operations team.This role is ideal for a motivated professional with 3+ years of experience in SIEM administration, security operations, or log management.
Key Responsibilities :
SIEM Platform Administration :
- Assist in deploying, configuring, and maintaining the NextGen SIEM platform (e.g., Stellar Cyber, Splunk, Sentinel, QRadar, Chronicle, Exabeam).
- Perform basic updates and patches to ensure platform security and functionality.
- Monitor SIEM health, performance, and uptime under the guidance of senior administrators.
Log Source Management :
- Onboard new log sources and validate data ingestion.
- Help troubleshoot log ingestion, parsing, and formatting issues.
- Maintain log retention policies for compliance.
Rule and Use Case Management :
- Support the development and deployment of detection rules, correlation use cases, and alerts.
- Tune existing use cases to minimize false positives.
- Work closely with security analysts to refine alerting strategies.
Integration and Automation :
- Assist in integrating SIEM with other security tools (e.g., EDR, microsegmentation, vulnerability scanners).
- Work on basic automation tasks using scripting (Python, PowerShell) to enhance SIEM efficiency.
Platform Security and Compliance :
- Support role-based access control (RBAC) and platform security policies.
- Help ensure SIEM adheres to compliance standards like SOC2, ISO 27001.
- Participate in periodic security audits.
Network Debugging & Troubleshooting :
- Have a basic understanding of TCP/IP, networking concepts, and protocols.
- Assist in debugging network connectivity issues related to SIEM log ingestion.
- Use basic network troubleshooting tools .
Collaboration and Support :
- Work alongside SOC analysts, threat hunters, and security engineers.
- Provide basic technical support for SIEM users.
- Assist in training and documentation for security teams.
Performance Monitoring and Optimization :
- Monitor storage and indexing performance to ensure optimal operations.
- Report any performance issues to senior administrators.
- Contribute to platform health reports and alerting metrics.
Incident Support :
- Assist SOC teams in log analysis, incident response, and forensic investigations.
- Ensure log data is readily available for security incidents.
Education and Certifications :
- Bachelors degree in Computer Science, Information Security, or a related field.
- Certifications (Preferred but not mandatory) :
a. Splunk Certified User/Admin
b. Microsoft Certified : Security Operations Analyst Associate
c. QRadar Certification
d. Any SIEM-related certification
Experience :
- 3+ years of experience in SIEM administration, security operations, or log management.
- Hands-on experience with at least one SIEM platform (e.g., Stellar Cyber, Splunk, Sentinel, Chronicle, Exabeam).
- Basic knowledge of log ingestion, rule creation, and data parsing.
- Exposure to scripting (Python, PowerShell) for automation.
- Basic understanding of TCP/IP networking concepts and network debugging.
Technical Skills :
- Understanding of log formats, Syslog, JSON, XML, and data pipelines.
- Basic knowledge of querying languages (KQL, SPL, AQL).
- Familiarity with SIEM integration with security tools like EDR, SOAR, NDR.
- Awareness of MITRE ATT&CK, NIST, or CIS security frameworks.
- Basic experience with network troubleshooting tools (ping, traceroute, netcat (nc)).
Soft Skills :
- Strong problem-solving and troubleshooting abilities.
- Good verbal and written communication skills.
- Ability to work collaboratively in a security operations environment.
Preferred Skills :
- Basic understanding of cloud-based security solutions (AWS, Azure, Google Cloud).
- Exposure to SOAR tools (e.g., Cortex XSOAR, Splunk Phantom).
- Interest in machine learning-based anomaly detection for SIEM.
Key Metrics for Success :
- Successful onboarding of log sources.
- Improvement in log ingestion and parsing accuracy.
- Contribution to fine-tuning detection rules.
- Timely resolution of SIEM-related support requests.
- Ability to identify and troubleshoot basic network connectivity issues
-
ColorTokens - Platform Administrator - SIEM
2 weeks ago
Bengaluru, Karnataka, India Colortokens Full timeJob Title : Platform Administrator NextGen SIEM. Location : Bangalore (on site). Experience Level : 8+ ColorTokens : At ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape.Breaches happenbut with our cutting-edge ColorTokens Xshield platform, companies can minimize the impact of breaches...
-
ColorTokens - Senior SOC Analyst - SIEM
3 weeks ago
Bengaluru, Karnataka, India Colortokens Full timeJob Title : SOC Analyst L2. Location : Bangalore (on site). Experience Level : 4 to 8 years. The candidate must be willing to work in rotational shifts 24/7. About ColorTokens : At ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happenbut with our cutting-edge ColorTokens...
-
SIEM Administrator
3 weeks ago
Bengaluru, Karnataka, India ColorTokens Inc. Full timeJob Title: Platform Administrator – NextGen SIEM Location: Bangalore (on site) Experience Level: 3+ years About ColorTokens At ColorTokens , we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge ColorTokens Xshield platform , companies can minimize the...
-
SIEM Administrator
3 weeks ago
Bengaluru, Karnataka, India ColorTokens Inc. Full timeJob Title: Platform Administrator – NextGen SIEMLocation: Bangalore (on site)Experience Level: 3+ yearsAbout ColorTokensAt ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge ColorTokens Xshield platform, companies can minimize the impact of...
-
ColorTokens - Software Engineer - SaaS
4 weeks ago
Bengaluru, Karnataka, India Colortokens Full timeAbout the job : Job Title : Software Engineer Xshield Security PlatformLocation : Bangalore, India (Onsite)About ColorTokens :At ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape.Breaches happenbut with our cutting-edge ColorTokens Xshield platform, companies can minimize the impact of...
-
ColorTokens - Senior Software Engineer -
3 weeks ago
Bengaluru, Karnataka, India Colortokens Full timeAbout ColorTokensAt ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape.Breaches happenbut with our cutting-edge ColorTokens Xshield platform, companies can minimize the impact of breaches by preventing the lateral spread of ransomware and advanced malware.We enable organizations to continue...
-
ColorTokens - VAPT Engineer - Cyber Security
3 weeks ago
Bengaluru, Karnataka, India Colortokens Full timeAbout ColorTokens : At ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happenbut with our cutting-edge ColorTokens Xshield platform, companies can minimize the impact of breaches by preventing the lateral spread of ransomware and advanced malware. We enable organizations to...
-
Bengaluru, Karnataka, India Colortokens Full timeJob Title: Accounts Receivable Specialist Order to Cash. Location: Bangalore (on site). Experience Level: 5+ years. Education: B.Com / CA / MBA (Finance). About ColorTokens. At ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen-but with our cutting-edge ColorTokens Xshield-...
-
Bengaluru, Karnataka, India ColorTokens Inc. Full timeJob Title: Software Engineer – Xshield Security PlatformLocation: Bangalore, India (Onsite)About ColorTokensAt ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge ColorTokens Xshield platform, companies can minimize the impact of breaches by...
-
Software Engineer – Xshield Security Platform
4 weeks ago
Bengaluru, Karnataka, India ColorTokens Inc. Full timeJob Title: Software Engineer – Xshield Security PlatformLocation: Bangalore, India (Onsite)About ColorTokensAt ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge ColorTokens Xshield platform, companies can minimize the impact of breaches by...