Siem Administrator
4 months ago
Introduction
Your Role and Responsibilities
As a SIEM Engineer you will be responsible for implementation and deployment of new SIEM projects; and managing and providing SIEM health and operational support, including supporting to architecture changes, tool deployments and advanced detection engineering.
**Responsibilities**:
- Understand SIEM product architecture.
- Ensure up-time of SIEM components.
- Perform daily SIEM Health Check & Availability monitoring.
- Understanding logs, Log formats, identify appropriate information for Log parsing and SIEM rule creation, Log Source Review
- Suggest logging levels and baseline log sources.
- Understanding of Log sources such as Operating System, Database, Web servers, Security and Network Technologies
- SIEM Content Development Keep a track of latest patches major version upgrades released by vendors.
- Log Retention Define and manage the log retention for all integrated devices as per defined agreement.
- Data Enrichment and asset modelling.
- Custom integration - Develop parsers for non-supported log sources as per scope.
- You will be closely working with Security Operations Center (SOC), Threat Intelligence, Threat Hunt, Automation and Orchestration teams to develop and operationalize meaningful security alerting and ensuring platform health and uptime.
- SIEM (Cortex XSIAM\\Splunk, Chronicle\\Qradar\\Micro Focus ArcSight\\Microsoft Sentinel\\LogRhythm\\Nitro) configuration management, troubleshooting, addressing complex issues and day to day operations management.
- Keep abreast of latest IT security, regulatory and compliance trends to support various risk\\data models.
- Ready to work in 24x7 rotational shift model including night shift.
Required Technical and Professional Expertise
- 8 to 10 years' relevant experience in security information and or technology engineering support.
- Experience with the following technologies : leading SIEM technologies (Cortex XSIAM\\Splunk, Chronicle\\ Qradar\\Micro Focus ArcSight\\Microsoft Sentinel\\LogRhythm\\Nitro) IDSIPS, network
- and host
- based firewalls, data leakage protection (DLP), common EDR platforms etc.
- Understanding of possible attack activities such as network probing scanning, DDOS, malicious code activity, exfiltration, credential access, etc.
- An understanding of the Cyber Kill Chain, the MITRE attack framework, various TTPs described within and commonly used by attackers as well as how to write detection rules for them in SIEM and EDR solution.
- Understanding of tools, technologies and logging mechanism including understanding to common network devices such as routers, switches, load balancers etc.
- Understanding of typical cloud threats and knowledge of how to detect and prevent them, cloud logging and audit capabilities and the ability to develop detection rules around these.
- Understanding of basic networking protocols such as IP, DNS, HTTP, and the network s
- Basic knowledge in system security architecture and security solutions.
Preferred Technical and Professional Expertise
- CISSP, CEH or equivalent.
About Business UnitIBM Consulting is IBM’s consulting and global professional services business, with market leading capabilities in business and technology transformation. With deep expertise in many industries, we offer strategy, experience, technology, and operations services to many of the most innovative and valuable companies in the world. Our people are focused on accelerating our clients’ businesses through the power of collaboration. We believe in the power of technology responsibly used to help people, partners and the planet.
Being an IBMer means you’ll be able to learn and develop yourself and your career, you’ll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background.
Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do.
Are you ready to be an IBMer?
Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we’re also one of the biggest technology and consulting employers, with many of the Fortune 50 companies relying on the IBM Cloud to run their business.
At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computi
-
Siem Administrator
7 months ago
Pune, Maharashtra, India IBM Full timeIntroduction Your Role and Responsibilities As a SIEM Administrator, your role involves overseeing the implementation, management, and optimization of SIEM solutions within an organization's cybersecurity infrastructure. **Responsibilities**: - Install, configure, and maintain SIEM platforms and associated software. This includes setting up data...
-
Siem Administrator
7 months ago
Pune, India Softenger Full time**Job Profile**: - SIEM Administrator**Job Location**: - Pune**Experience Required**: - 2-4 yrs- SIEM Configuration: Configure and maintain the ArcSight SIEM platform to ensure it effectively collects, normalizes, and analyzes security event data.Log Management: Manage and optimize log collection and storage processes to ensure efficient storage and...
-
L2 Siem Administrator
1 day ago
Pune, Maharashtra, India Atalef.ai Full timeJob Title: L2 SIEM Administrator - LogRhythm **Location**: Pune - Customer Site (Magarpatta) Job Summary: We are seeking an experienced and proactive L2 SIEM Administrator with expertise in LogRhythm to manage, maintain, and optimize our Security Information and Event Management (SIEM) infrastructure. Key Responsibilities: LogRhythm Administration: Manage...
-
Ibm Qradar Siem Administration
7 months ago
Pune, Maharashtra, India Teleglobal International Full time**Key Responsibilities**: - Install, configure, and maintain the IBM QRadar SIEM platform to ensure efficient log collection, analysis, and threat detection. - Monitor system health, troubleshoot issues, and implement necessary updates and patches. - Analyze security events, incidents, and alerts to provide timely and effective responses. - Play a key role...
-
Administrator - Siem
3 months ago
Pune, Maharashtra, India Microland Full time**Required Skills**: Behavioral | Aptitude | Communication Technology | Cybersecurity | SOC Alert Management Technology | Cybersecurity | Vulnerability Management Technology | Cybersecurity | SIEM-SOAR Technology | Cybersecurity | End Point Security **Education Qualification**: Any Graduate **Certification Mandatory / Desirable**: Technology | IT Security...
-
Siem Admin
7 months ago
Mumbai, Maharashtra, India IBM Full timeIntroduction Your Role and Responsibilities This is level 2 role and would be responsible to support SIEM Management & content management for SIEM detection use-cases for the program. They would be overlooking technical services delivery for SOC program for your enterprise. If you thrive in a dynamic, reciprocal workplace, IBM provides an environment to...
-
Middleware Administrator for Tcs Nabard
8 months ago
Mumbai, Maharashtra, India Dixit Infotech Services Pvt. Ltd Full timeJBoss Administration - Logs monitoring. NABARD to provide necessary access and SOP's to Dixit Infotech team to fetch the JBoss logs. TCS & Dixit Infotech will integrate the in-scope JBoss instances to the SIEM tool. - Daily Health check-up of JBoss Application Server Middleware
-
Network & Systems Administrator
2 days ago
Pune, India Securonix, Inc. Full time**Description** - Securonix provides the Next-Generation Security and Information Event Management (SIEM) solution. As a recognized leader in the SIEM industry, Securonix helps some of the largest organizations globally to detect sophisticated cyber-attacks and rapidly respond to these attacks within minutes. With the Securonix SNYPR platform, organizations...
-
Security Analyst-l2
4 months ago
Pune, Maharashtra, India IBM Full timeIntroduction Your Role and Responsibilities - Responsible for Apps Installation, Troubleshooting & App host Management. - Understanding about threat scenarios, threat vectors and logs to arrive at identify new threats. - Analyse existing SIEM rules to optimize threat detection and minimize false positives. - Participate in Client SOC strategy and planning,...
-
Securityconsultant-infrastructuresecurity
6 months ago
Pune, Maharashtra, India IBM Full timeIntroduction Your Role and Responsibilities - Lead and Guide the SIEM Admin Team to deliver all the below tasks - Install, upgrade, configure, administer, and maintain our distributed SIEM QRadar platform. - Monitor and troubleshoot QRadar health issues to ensure optimal performance. - Integrate different devices with SIEM, including API integration and...
-
Security
7 months ago
Pune, Maharashtra, India IBM Full timeIntroduction Your Role and Responsibilities This is level 2 role and would be responsible to support SIEM Management & content management for SIEM detection use-cases for the program. They would be overlooking technical services delivery for SOC program for your enterprise. If you thrive in a dynamic, reciprocal workplace, IBM provides an environment to...
-
Administrator - Endpoint Security
3 months ago
Pune, Maharashtra, India Microland Full time**Required Skills**: Technology | Cybersecurity | End Point Security Technology | Cybersecurity | Vulnerability Management Technology | Cybersecurity | SIEM-SOAR Behavioral | Aptitude | Communication Technology | Cybersecurity | SOC Alert Management **Education Qualification**: Any Graduate **Certification Mandatory / Desirable**: Technology | IT Security...
-
Qradar Admin 4 to 6 Years Pan India
4 months ago
Navi Mumbai, Maharashtra, India Capgemini Full timeChoosing Capgemini means choosing a company where you will be empowered to shape your career in the way you’d like, where you’ll be supported and inspired by a collaborative community of colleagues around the world, and where you’ll be able to reimagine what’s possible. Join us and help the world’s leading organizations unlock the value of...
-
Azure Sentinel 6 to 9 Years Pan India
7 months ago
Pune, India Capgemini Full timeMust have strong experience into Solution Architecture, Design, and Implementation for Azure Cloud. - 5+ years of Experience in Enterprise SOC with focus on Incident investigation, Threat Hunting, Microsoft 365 Defender & DoS/, Azure Sentinel, Use case Building using KQL. - Required Good knowledge of SIEM, SIEM Architecture and Hybrid Integrations, Cyber...
-
Firewall Administrator
3 months ago
Vikhroli, Mumbai, Maharashtra, India Symphony Tech Solutions Full timeGreetings of the day! As discussed, we are looking for **Firewall Administrator L2+- at one of IT Company - Vikhroli ( Mumbai) Location.** Please find the JD with Company details for your reference: Specialties:IPO, Rights Issue, Exit Offer, Buyback, Registry, AGM Management (Physical & Virtual), Employee Stock Options (EmPower), Insider Trading (TrackIn),...
-
Qradar Admin 6 to 9 Years Mumbai
5 days ago
Pune, India Capgemini Full timeQradar SME Experience, Build and continuously improve SOC analytics framework. - Ensure effective designing and implementation of SIEM content filters rules expressions and other identification mechanisms of the threat and vulnerability management technologies used within the SOC Mentor and guide the First Level. - Security Analysts Provides professional...
-
Network Protection Expert
2 weeks ago
Pune, Maharashtra, India T D Newton Full timeAbout T D NewtonT D Newton is a leading organization in the field of Cyber Security. We are committed to providing our employees with ongoing training and development opportunities and a collaborative and dynamic work environment.The RoleWe are seeking a highly skilled Cyber Security Engineer to join our team in Pune. The ideal candidate will have a strong...
-
System Administrator- Security
6 months ago
Mumbai, Maharashtra, India Kyndryl Full timeWho We Are At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities. The Role As...
-
Threat Intel
4 months ago
Pune, Maharashtra, India IBM Full timeIntroduction Your Role and Responsibilities This position serves as a Cyber Threat Analyst in support of a major IBM client. This organization provides services that analyse and produce enhanced cyber security and threat intelligence information to include threats and potential threats to the customer’s personnel, information, and information systems;...
-
Cyber Security Engineer
3 weeks ago
Pune, India T D Newton Full timeUrgent requirement for Cyber Security Engineer for Pune Location.Experience : 5-10 YrsJob Location : PuneJob Description :- Planning, implementing, managing, monitoring and upgrading security measures for the protection of the organization's data, systems and networks.- Defining, implementing, and maintaining operational security processes...