
Python Expert with SIEM/SOC
3 days ago
2 weeks ago Be among the first 25 applicants
Get AI-powered advice on this job and more exclusive features.
Direct message the job poster from SADDLEBACK CONSULTING LIMITED
SIEM/SOC/XSIAM ENGINEER & CLOUD SECURITY ENGINEER
Note: PYTHON IS A MUST HAVE
Job Type: Contract (12 months)
Job Description
Collaborate with the technical lead to devise a comprehensive log ingestion strategy
Contribute to the development of detection strategies based on industry best practices
Articulate a step-by-step process to ensure the ingestion of high-quality log sources
Monitor and optimize log sources for optimal performance
Create meticulous and effective correlation rules
Fine-tune log sources and correlation rules to enhance system efficiency
Serve as the subject matter expert (SME) in SIEM, correlation, and log source ingestion
Serve as a trusted advisor to end customers, offering consultative guidance and expertise in optimizing the utilization of Cortex XSIAM
Leverage your in-depth knowledge of SIEM and SOC practices to assess customer needs, provide tailored recommendations, and assist in the formulation of effective security strategies
Collaborate closely with customers to understand their unique challenges and objectives, translating them into actionable steps that enhance their security posture
Identify opportunities to enhance analyst alert handling through automation
Foster collaboration with internal and external teams to drive product adoption
Produce technical documentation detailing SIEM aspects of the engagement
Occasionally travel to customer meetings and workshops (up to 10% of the time)
Qualifications
Exceptional written and verbal communication and presentation skills, for both internal and external interactions
5+ years of hands-on experience in deploying and integrating SIEM solutions within enterprise to large enterprise-level environments
Proficiency in coordinating and conducting event collection, log management, event management, compliance automation, and identity monitoring using SIEM platforms
Ability to conceive and develop correlation and detection rules in SIEM systems to enable effective alerting
Proven experience in providing consultative services to end customers within the realm of cybersecurity, particularly in SIEM and SOC domains
Demonstrated ability to comprehend customer requirements, analyze complex security environments, and deliver strategic recommendations that align with their goals
Strong expertise in Regular Expressions (Regex)
Skill in understanding logs and locating relevant third-party documentation when required
Knowledge of generating reports on SIEM status, including metrics like logging source count, log collection rate, and other performance indicators
Understanding of Security Analysis & Response, encompassing endpoint, network, and cloud-based environments is a plus
Proficient in comprehending and creating technical design documentation
5+ years of experience with Security Operations Centers (SOC) tooling and processes
5+ years of hands-on experience in deploying and integrating endpoint security solutions within enterprise to large enterprise-level environments.
Relevant bachelor's degree or equivalent military experience or industry-recognized qualifications (CISSP, GIAC, SIEM Vendor Qualification, etc.), is a plus
About Us
Saddleback Solutions
offer Consultancy and Professional Services to our Partners and Clients. We partner Palo Alto Networks, Juniper Networks and Arista worldwide, and we indirectly Partner AWS, so there are always lots of varying opportunities that come up.
We have long standing and close relationships with our consultants and our partners so we can represent you fully. We offer free training for all our consultants should they wish to expand their knowledge and profiles while with us.
We have an education services arm also, so our consultants once qualified can also offer their services running workshops or bootcamps between projects or even full time.
We will support you the best way we know how.
Seniority level
Mid-Senior level
Employment type
Contract
#J-18808-Ljbffr
-
SOC Engineer
2 days ago
Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full time**Duties & Responsibilities** - Provide engineering supporting an SOC environment in areas relating to Advanced Analytics domain - Approve junior engineer requests and assignment of work to the various junior engineers - Plan work activities for engineering team and provide engineering support - Plan, test and deploy patches for SOC systems - Work with...
-
SOC Analyst
1 week ago
Singapore INFINITE COMPUTER SOLUTIONS PTE LTD Full time**Job Summary**: We are looking for a Level 1 SOC Analyst to monitor and respond to security alerts. You will be the first point of contact for identifying potential security incidents and escalating them as needed. This is a great role for someone starting their career in cybersecurity. **Key Responsibilities**: - Monitor security alerts using tools like...
-
SOC Analyst
2 days ago
Singapore OX Consultancy Full timejob Title:SOC Analyst L2: (10+ Yrs of exp) Location:Singapore/Onsite job Title :SOC Analyst L2: (10+ Yrs of exp) The primary function of an L2 Analyst is to ensure that the SOC team is performing its Items functions as required and to trouble shoot problematic incidents and events. In summary, the L2 Analyst shall also act as the technical...
-
SOC Manager
7 days ago
Singapore GATEWAY SEARCH PTE. LTD. Full time**Responsibilities** - Responsible for the success of the Managed Security Services. - Design, build, operate and maintain the Security Operations Center (SOC). - Attain and maintain SOC certifications. - Well-versed in technologies such as SIEM, EDR, SOAR, Network Analytics, Endpoint Analytics, Threat Intelligence, Threat Intelligence Platform. - Train and...
-
L2 SOC Analyst
2 weeks ago
Singapore INSYGHTS SECURITY PTE. LTD. Full timeAbout the Role We are seeking a skilled and self-motivated Level 2 SOC Analyst to take a leading role in cyber threat operations within our MSSP SOC environment. This role also involves operating as a Subject Matter Expert (SME) and mentoring junior L1 analysts. As a key member of our Security Operations Center, you will play a critical role in...
-
L2 SOC Analyst
2 weeks ago
Singapore INSYGHTS SECURITY PTE. LTD. Full timeAbout the Role We are seeking a skilled and self-motivated Level 2 SOC Analyst to take a leading role in cyber threat operations within our MSSP SOC environment. This role also involves operating as a Subject Matter Expert (SME)and mentoring junior L1 analysts. As a key member of our Security Operations Center, you will play a critical role in monitoring,...
-
Siem & Automation Engineer
2 days ago
Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full timeOur SIEM & Automation team works closely with other security analysts to deliver security content to monitor security threats, and automate the escalation / response for our customers. You will play a part in the team to research, design, architect and implement security use case and automation playbooks. **Key Responsibilities** - Carry out implementation,...
-
SOC Analyst
2 days ago
Singapore Flare Consulting Full time $90,000 - $120,000 per yearJob Description – SOC AnalystPosition OverviewWe are seeking a SOC Analyst to join our cybersecurity operations team. The ideal candidate will be responsible for monitoring, detecting, investigating, and escalating security threats across our enterprise environment. This role requires strong analytical skills, hands-on technical expertise in SIEM and...
-
SOC Engineer
2 weeks ago
Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full time**Duties & Responsibilities** - Provide engineering supporting an SOC environment in areas relating to Advanced Analytics domain - Approve junior engineer requests and assignment of work to the various junior engineers - Plan work activities for engineering team and provide engineering support - Plan, test and deploy patches for SOC systems - Work with...
-
L2 SOC Analyst
2 weeks ago
Singapore INSYGHTS SECURITY PTE. LTD. Full timeAbout the Role We are seeking a skilled and self-motivated Level 2 SOC Analyst to take a leading role in cyber threat operations within our MSSP SOC environment. This role also involves operating as a Subject Matter Expert (SME) and mentoring junior L1 analysts. As a key member of our Security Operations Center, you will play a critical role in monitoring,...