
Platformadministrator - Nextgen Siem
4 days ago
Job Title: Platform Administrator - NextGen SIEM
Location: Bangalore (on site)
About ColorTokens
At ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge ColorTokens Xshield platform, companies can minimize the impact of breaches by preventing the lateral spread of ransomware and advanced malware. We enable organizations to continue operating while breaches are contained, ensuring critical assets remain protected.
Our innovative platform provides unparalleled visibility into traffic patterns between workloads, OT/IoT/IoMT devices, and users, allowing businesses to enforce granular micro-perimeters, swiftly isolate key assets, and respond to breaches with agility. Recognized as a Leader in the Forrester Wave: Microsegmentation Solutions (Q3 2024), ColorTokens safeguards global enterprises and delivers significant savings by preventing costly disruptions.
Our culture
We foster an environment that values customer focus, innovation, collaboration, mutual respect, and informed decision-making. We believe in alignment and empowerment so you can own and drive initiatives autonomously.
Self-starters and high-motivated individuals will enjoy the rewarding experience of solving complex challenges that protect some of world’s impactful organizations - be it a children’s hospital, or a city, or the defense department of an entire country.
Company Overview:
Position Overview:
Key Responsibilities:
SIEM Platform Administration
- Deploy, configure, and maintain the NextGen SIEM platform (e.g., Stellar Cyber, Splunk, Sentinel, QRadar, Chronicle, Exabeam etc).
- Perform regular updates, patches, and upgrades to ensure platform security and functionality.
- Monitor platform health, performance, and availability, ensuring optimal uptime.
Log Source Management
- Troubleshoot and resolve issues related to log ingestion, parsing, and formatting.
- Maintain log retention policies in alignment with compliance requirements.
Rule and Use Case Management
- Develop, deploy, and fine-tune detection rules, correlation use cases, and alerts.
- Continuously update use cases based on emerging threats, business needs, or compliance mandates.
- Collaborate with SMEs and SOC analysts to refine detection capabilities and reduce false positives.
Integration and Automation
- Integrate the SIEM platform with other security tools (EDR, microsegmentation solution, vulnerability scanners, etc.).
- Design and implement automation workflows for incident detection, investigation, and response.
Platform Security and Compliance
- Enforce platform access control policies, ensuring role-based access and least privilege principles.
- Ensure the SIEM adheres to regulatory compliance standards (e.g., SOC2, ISO 27001).
- Conduct regular audits and ensure the platform is free of vulnerabilities.
Collaboration and Support
- Work closely with SOC analysts, threat hunters, and engineers to align the SIEM capabilities with security goals.
- Provide technical support to users of the SIEM platform.
- Offer training and documentation for security teams on effective SIEM usage.
- Be available round the clock in case of any incidents with the platform
Performance Monitoring and Optimization
- Monitor and optimize storage and indexing performance.
- Proactively identify bottlenecks and improve platform scalability.
- Generate reports on platform performance and alerting effectiveness.
Incident Support
- Assist the SOC team with root cause analysis and advanced investigations.
- Ensure forensic data is readily available during incident response.
Education and Certifications:
- Bachelor’s degree in Computer Science, Information Security
- Relevant certifications such as Splunk Certified Admin, Microsoft Certified: Security Operations Analyst Associate, QRadar Certification, or similar NextGen SIEM certifications are highly desirable along with CISSP
**Experience**:
- 8+ years of experience in managing SIEM platforms (traditional or NextGen).
Strong hands-on experience with at least one NextGen SIEM platform (e.g., Stellar Cyber, Splunk, Sentinel, Chronicle, Exabeam).
- Experience with log management, rule creation, and data onboarding.
- Familiarity with scripting languages (e.g., Python, PowerShell) for automation.
Technical Skills:
- In-depth understanding of log formats, protocols (e.g., Syslog, JSON, XML), and data pipelines.
- Proficiency in querying languages (e.g., KQL, SPL, AQL).
- Experience with integration of SIEMs with security tools like EDR, SOAR, NDR, and threat intelligence platforms.
- Knowledge of security frameworks such as MITRE ATT&CK, NIST, or CIS.
Preferred Skills:
- Familiarity with cloud-based security solutions (e.g., AWS, Azure, Google Cloud).
- Experience in implementing machine learning or anomaly detection in SIEM use cases.
- Exposure to SOAR tools (e.g., Palo Alto Cortex XSOAR, Splunk Phantom).
Key Metrics for S
-
Platform Administrator
3 days ago
Bengaluru, Karnataka, India Colortokens Full time**Job Title**:Platform Administrator - NextGen SIEM **About ColorTokens** At **ColorTokens**, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge **ColorTokens Xshield platform**, companies can minimize the impact of breaches by preventing the lateral spread...
-
Platform Administrator
3 days ago
Bengaluru, Karnataka, India ColorTokens Full time**Job Title**:Platform Administrator - NextGen SIEM **About ColorTokens** At **ColorTokens**, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge **ColorTokens Xshield platform**, companies can minimize the impact of breaches by preventing the lateral spread...
-
Platform Administrator
4 days ago
Bengaluru, Karnataka, India Colortokens Full timeJob Title: Platform Administrator - NextGen SIEM Location: Bangalore (on site) About ColorTokens At ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge ColorTokens Xshield platform, companies can minimize the impact of breaches by preventing the...
-
Sr. Solutions Consultant
6 days ago
Bengaluru, Karnataka, India Opentext Full time US$ 1,00,000 - US$ 1,50,000 per yearYour Impact:Solution Consultants collaborate with and support Account Managers and provide specialist expertise to the sales teams. Use specialized technical solution knowledge and skills to prospect, technically qualify opportunities and help Sales Representatives win the opportunity. May have named accounts allocated, cover a designated geography. They...
-
Principal Product Manager
3 weeks ago
Bengaluru, Karnataka, India Securonix Full timeAt Securonix, we're on a mission to secure the world by staying ahead of cyber threats, reinforcing all layers of our platform with AI capabilities. Our Securonix Unified Defense SIEM provides organizations with the first and only AI-Reinforced solution built with a cybersecurity mesh architecture on a highly scalable data cloud. Enhanced by Securonix EON's...
-
Principal Product Manager
6 days ago
Bengaluru, Karnataka, India Securonix Full time ₹ 7,50,000 - ₹ 10,00,000 per yearAt Securonix, we're on a mission to secure the world by staying ahead of cyber threats, reinforcing all layers of our platform with AI capabilities. Our Securonix Unified Defense SIEM provides organizations with the first and only AI-Reinforced solution built with a cybersecurity mesh architecture on a highly scalable data cloud. Enhanced by Securonix EON's...
-
Chief Enterprise Security Specialist
18 hours ago
Bengaluru, Karnataka, India beBeeSecurity Full timeJob OverviewAs a seasoned security expert, you will play a pivotal role in safeguarding our enterprise's digital assets. Your primary responsibility will be to maintain and enhance our Web Application Firewall (WAF) configurations to ensure optimal security posture.Key Responsibilities:Maintain and refine WAF configurations to adhere to best practices across...
-
Senior Security Platform Engineer
4 days ago
Bengaluru, Karnataka, India NTT DATA, Inc. Full time ₹ 1,04,000 - ₹ 13,08,780 per yearMake an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.Your day at NTT DATAThe Senior...
-
Thomson Reuters
6 days ago
Bengaluru, Karnataka, India Thomson Reuters International Services Pvt Ltd Full time ₹ 9,00,000 - ₹ 12,00,000 per yearInformation Security and Risk Management (ISRM) organization is seeking a Senior Security Engineer to join our growing Security Engineering team. This candidate will join a team that manages our Web Application Firewall (WAF) solutions and network IDS/IPS, with a particular focus on the implementation of Cloudflare & cloud-native WAF services across our...