SIEM Engineer - Splunk

3 - 8 years

12 - 22 Lacs

Posted:23 hours ago| Platform: Naukri logo

Apply

Work Mode

Hybrid

Job Type

Full Time

Job Description

Cyber

Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful insights to help our clients navigate the ever-changing threat landscape. Through powerful insights and managed services that simplify complexity, we enable businesses to operate with resilience, grow with confidence, and proactively manage to secure achievements.

Cyber Operate

We help organizations create a cyber minded culture, reimagine risk to uncover strategic opportunities, and become faster, more innovative, and more resilient in the face of ever-changing threats. As organizations are called upon to align their priorities and to drive core business objectives and reduce risk, our cyber and strategic risk management team helps clients focus on enterprise level risks through a wider lens.

Deloittes Detect & Respond (D&R) aims to combine sophisticated technologies and human intelligence to help the clients monitor, detect, investigate, and respond to known and unknown attacks. We help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilities. Detect and Respond team delivers service to clients through following key areas:

  • Threat detection and response
  • Attack surface management
  • Threat Intelligence
  • Threat Hunting
  • Data Protection

Work you’ll do

  • As a SIEM Engineer (SPLUNK, Sentinel, Chronicle) you will be managing and providing SIEM health and operational support, including supporting to architecture changes, tool deployments and advanced content development.
  • Perform SIEM configuration management, and troubleshooting, addressing complex issues and day to day operations management
  • Onboard security log data sources and develop new and custom parsers
  • Perform SIEM architecture assessments, content baseline assessment and design reviews
  • Deliver SIEM advisory support and education to other SOC and technology management personnel
  • Help define, implement and monitor key risk indicators and key performance indicators (KRIs/KPIs)
  • Keep abreast of latest IT security, regulatory and compliance trends to support various risk and data model
  • Security information and event management (SIEM) Use Case content functional and quality testing
  • Developing actionable use cases to detect, triage, investigate and remediate based on latest threat actor trends, including actual technical implementation of parsing log sources creating, validating and testing alerting queries to reduce false positives.
  • Enhancing and documenting existing SOC processes to increase centralized visibility in order to identify suspicious activity to reduce the mean time to detect and respond to cyber threats.
  • Assist in Use Case Roadmap development and update Use Cases in Use Case Repository
  • Coordinate with Content Engineers to support advanced Use Case development (Use Case from Roadmap as well as hunting related Use Cases)
  • Help maintain content development/deployment baseline across clients based on the maturity of the client environment as well as the latest trends in security
  • Review system security plans, network diagrams, and vulnerability and patching requirements
  • Develop scripts to simplify data collection and automate data onboarding tasks
  • Provide 24/7 on-call support (as needed)
  • Coordinate with various technical groups and attend in-person client meetings
  • Build relationships with client counterpart (i.e. Client Lead Security Engineer)

Required skills

  • Bachelor’s degree is required. Ideally in Computer Science, Cyber Security, Information Security, Engineering, Information Technology.
  • 5+ years’ experience in security information and/or technology engineering support.
  • Certified Information Systems Security Professional (CISSP), Certification in Certified Intrusion Analyst (GIAC), Continuous Monitoring (GMON), Certified Ethical Hacker (CEH) or equivalent
  • Extensive experience in security technologies such as: Security information and event management (SIEM), IDS/IPS, Data Loss Prevention (DLP), Proxy, Web Application Firewall (WAF), Endpoint detection and response (EDR), Anti-Virus, Sandboxing, network- and host- based firewalls, Threat Intelligence, Penetration Testing, etc.
  • Knowledge of Advanced Persistent Threats (APT) tactics, technics and procedures
  • Understanding of possible attack activities such as network probing/ scanning, DDOS, malicious code activity, etc
  • Understanding of common network infrastructure devices such as routers and switches
  • Understanding of basic networking protocols such as TCP/IP, DNS, HTTP
  • Detailed knowledge in system security architecture and security solutions

Preferred skills

  • Experience interpreting, searching, and manipulating data within enterprise logging solutions (e.g. SIEM, IT Service Management (ITSM) tools, workflow, and automation)
  • Ethical Hacking and Information Security certifications such as OSCP, CEH, CISSP, SANS etc.
  • SIEM certifications such as Splunk Architecture, HP ArcSight, IBM QRadar certified, etc.
  • Certifications; CISSP, CISA, CISM, GCIH, GMON, GCDA, GPEN, GCFA, GCTI
  • Excellent interpersonal and organizational skills
  • Excellent oral and written communication skills
  • Strong analytical and problem-solving skills
  • Self-motivated to improve knowledge and skills
  • A strong desire to understand the what as well as the why and the how of security incidents

Qualification

  • Bachelor’s degree is required. Ideally in Computer Science, Cyber Security, Information Security, Engineering, Information Technology.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now

RecommendedJobs for You

navi mumbai, mumbai (all areas)

hyderabad, chennai, bengaluru