Job Summary:
We are seeking an experienced SIEM Architect to design, implement, and manage Security Information and Event Management (SIEM) solutions across the enterprise. The ideal candidate will have deep expertise in threat detection, log management, security monitoring, and incident response, with strong hands-on experience in leading SIEM platforms such as Splunk, QRadar, ArcSight, or LogRhythm.
The candidate will collaborate with security, IT, and compliance teams to ensure enterprise-wide visibility into security events and support proactive threat management.
Key Responsibilities:
Design, implement, and manage enterprise SIEM architecture and solutions.
Lead deployment and integration of SIEM tools with multiple log sources (firewalls, endpoints, cloud, applications, databases).
Develop and fine-tune correlation rules, alerts, dashboards, and reports to detect threats.
Perform threat analysis and security monitoring to identify, investigate, and respond to security incidents.
Collaborate with SOC, IT, and application teams to define logging requirements, event normalization, and data ingestion.
Provide guidance on security policies, compliance, and best practices related to log management and monitoring.
Conduct SIEM performance optimization, tuning, and scalability assessments.
Mentor junior security engineers and provide technical leadership on SIEM-related projects.
Stay current with emerging threats, industry trends, and SIEM technologies to recommend improvements.
Required Skills & Qualifications:
9–14 years of experience in cybersecurity, with 5+ years in SIEM implementation and architecture.
Hands-on experience with SIEM platforms: Splunk, QRadar, ArcSight, LogRhythm, or similar.
Strong knowledge of security monitoring, event correlation, threat detection, and incident response.
Experience with log management, parsing, normalization, and creating dashboards and reports.
Familiarity with regulatory frameworks: ISO 27001, NIST, PCI-DSS, HIPAA, etc.
Solid understanding of networking, firewalls, endpoints, cloud environments, and authentication systems.
Scripting experience (Python, PowerShell, Bash) for automation and integration is a plus.
Strong analytical, problem-solving, and communication skills.
Experience leading technical teams and managing complex SIEM projects.
Preferred Qualifications:
Certifications: CISSP, CISM, Splunk Certified Architect, IBM QRadar Certified, or equivalent.
Experience with Cloud SIEM (Azure Sentinel, AWS Security Hub, etc.)
Experience integrating threat intelligence platforms with SIEM solutions.
Soft Skills:
Ability to work independently and as part of a cross-functional team.
Strong stakeholder management and communication skills.
Proactive in identifying security gaps and recommending solutions.