Security Information and Event Management (SIEM) Engineer
TechBiz Global
WorldwideremotePosted 2 days ago
Skill Required
SIEM-EngineeringCybersecuritySecurity-EngineeringInfosecSecurity-OperationsSecurity-Information-And-Event-Management-(SIEM)-SpecialistSIEM-Platform-Security-EngineerSIEM-EngineerInformation-Security-EngineerSIEM-AnalystSecurity-Operations-EngineerInformation-Systems-Security-EngineerSecurity-Analytics-EngineerSecurity-Monitoring-EngineerSenior-Information-Security-EngineerSecurity EngineersecuritySIEMandQuery Optimizationrelated fieldElasticsearchEngineeringanalyticalautomationShell ScriptingObservabilityFirewallPythondesignContract
Key highlights
- 5-8 years of hands‑on SIEM engineering experience required.
- Must be proficient with QRadar, Splunk, Microsoft Sentinel, and Elastic Stack.
- One‑month contract project.
- Strong scripting skills (Python, PowerShell, Bash) required.
- Preferred certifications include IBM QRadar Certified, Splunk Certified Architect, Elastic Certified Engineer.
- Bachelor’s degree in Computer Science, IT, Cybersecurity, or equivalent experience required.
Role overview
We are seeking for client for a one month project highly skilled and experienced SIEM Engineer with 5-8 years of hands‑on experience working on Security Information and Event Management (SIEM) tools such as QRadar, Splunk, Microsoft Sentinel, Elastic Stack (Elasticsearch, Logstash, Kibana), and other SIEM platforms. The candidate will be responsible for the design, deployment, configuration, and management of SIEM solutions, ensuring efficient monitoring and proactive threat detection across the organization. This role involves collaboration with security teams to optimize incident detection, analysis, and response processes.
Responsibilities
- Design, deploy, and configure SIEM solutions, including Elastic Stack (Elasticsearch, Logstash, Kibana), Wazuh, QRadar, Splunk & Microsoft Sentinel.
- Integrate various log sources (e.g., firewalls, IDS/IPS, network devices, applications), OT/IOT into the SIEM platform.
- Develop and fine‑tune correlation rules, dashboards, and alerts for proactive threat detection.
- Perform system upgrades, patches, and manage the overall health of the SIEM environment.
- Ensure proper log ingestion from multiple data sources, including Elasticsearch and Kibana, and troubleshoot any logging issues.
- Maintain data retention policies, manage storage, and optimize SIEM performance.
- Monitor and analyze system and security logs for anomalies, potential threats, or suspicious activities.
- Configure and maintain Elasticsearch clusters for log storage and search functionality.
- Utilize Kibana to create custom dashboards, visualizations, and reports for security monitoring.
- Work with Logstash or other log shippers for effective data parsing and enrichment before SIEM ingestion.
Requirements
- 5-8 years of experience working in SIEM engineering and administration roles.
- Proven expertise with SIEM platforms like QRadar, Splunk, Microsoft Sentinel, and Elastic Stack (Elasticsearch, Logstash, Kibana).
- Experience in integrating and managing log sources from diverse systems and platforms.
- Strong understanding of security incident detection, threat analysis, and response processes.
- Proficiency in SIEM platform management, rule creation, and performance tuning.
- Hands‑on experience with Elastic Stack (Elasticsearch, Logstash, Kibana) for log management, search, and security monitoring.
- Strong scripting abilities (e.g., Python, PowerShell, Bash) for automation.
- Knowledge of security protocols, network traffic analysis, and intrusion detection systems.
- Experience working with security frameworks such as MITRE ATT&CK, NIST, or CIS.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent experience).
- Strong problem‑solving and analytical thinking abilities.
- Excellent communication skills to convey complex technical concepts to stakeholders.
- Ability to work independently or in a team with minimal supervision.
Nice to have
- SIEM‑related certifications (e.g., IBM QRadar Certified, Splunk Certified Architect, Elastic Certified Engineer).
- Security certifications such as CISSP, CISM, or CEH.
Additional details
- Company: TechBiz Global, a leading recruitment and software development company with headquarters in Germany and a globally distributed team.
- The role is for a one‑month project.
- Originally posted on Himalayas.