over 4+ years of experience with arc sight
understanding and proven hands-on experience in siem concepts such as correlation, aggregation, normalization, and parsing
experience with deploying and managing a large siem deployment
excellent understanding of enterprise logging standards, with a focus on application logging
excellent understanding of regular expressions, development of custom/flex parsers
excellent unix shell scripting skills
excellent understanding of cyber security operations, incident response processes
excellent understanding of web application architectures and web services
system administration experience in a windows and unix environment
experience in using scripting languages to automate tasks and manipulate data.
good-to-have skills:
siem vendor certifications
programming experience
advanced knowledge of content creation concepts and best practices
academic qualifications:
bachelor’s degree in engineering, computer science, information security, or information systems
key performance indicators:
develop advanced siem correlation rules, reports and dashboards to detect emerging threat
manage, develop and tune the scripts that integrate siem
create technical documentation around the content deployed to the siem
monitor the impact of deploying new content to the health and performance of the siem
lead logging from multi-tier applications into the enterprise logging platforms
develop specific content necessary to implement security use cases and transform into correlation queries, templates, reports, rules, alerts, dashboards, and workflow
develop advanced reports to meet the requirements of key stakeholders
collaborate with key stakeholders within gis and cyber security to develop specific use cases to address specific business needs
collaborate with application owners to define and establish logging standards to address various governance requirements.
location: bengaluru urban, karnataka, india
notice period: 30 days
job type: tech
expected ctc: ₹ 12 - 14 lpa
experience: 4 - 6 years