SIEM Engineer II
Securonix
IndiaremotePosted 1 month ago
Skill Required
SIEM-EngineeringCybersecurity-ArchitectureSecurity-OperationsProfessional-ServicesSIEM-ImplementationSIEM-EngineerSIEM-Platform-Security-EngineerSIEM-SpecialistSenior-SIEM-ConsultantSIEMMachine LearningCybersecurityEngineeringnetworkingShell ScriptingObservabilitySnowflakeWiresharksecurityPythonHadoopdesignAzureCloudAIFulltime
Key highlights
- Minimum 4+ years of experience in information security and SIEM
- Strong knowledge of SIEM solutions such as Splunk, Qradar, ArcSight, Logrhythm and Exabeam
- Health insurance sum insured INR 7,500,000
- Personal accident sum insured INR 10,000,000
- Term life insurance 5× base pay
- Preferred 3‑4+ years of UEBA deployment experience
Role overview
The SIEM Engineer II position is an integral part of our Professional Services team. In this role, you will work with our customers, supporting our mission to help them quickly and completely adopt our Security Operating Platform, leaving them more secure.
Responsibilities
- Lead end-to-end SIEM implementation or integrations in a customer environment
- Understand customer business requirements and the threat landscape applicable to their industry’s vertical sector to develop tailored use cases for security and incident monitoring
- Coordinate with customers to deploy collectors and agents in the on-premises network for data collection and forwarding
- Work with customers to design and implement secure data flow into the Securonix cloud, following industry-standard best practices
- Coordinate with service delivery managers, management, engineering, maintenance, and operational support teams to ensure timely delivery
- Develop content, use cases, data models, dashboards, and connectors to support custom user requirements
- Troubleshoot end-to-end network and infrastructure issues during data onboarding
- Deploy and integrate the Securonix SOAR solution with the customer infrastructure for response orchestration
- Engage with customers and internal product development teams to gather user requirements, suggest new product features, and help improve existing ones
- Training and enabling customers and partners for successful adoption
Requirements
- 4+ years of experience in information security and SIEM field
- Strong understanding of SIEM solutions such as Splunk, Qradar, ArcSight, Logrhythm and Exabeam
- Experience deploying SIEM across multiple customers
- Good understanding of MITRE ATT&CK matrices, kill chains and other attack models
- Strong communication skills and customer facing experience
- Strong knowledge of scripting languages such as Python and Powershell
- Industry certifications such as CISSP and CISM
- Candidate must have SIEM and SOAR software expertise and be willing to train on the Securonix platform and products
Nice to have
- BS in Computer Science, Information Systems, or CyberSecurity
- 3-4+ years of experience in UEBA deployment
- Working knowledge of machine learning in cybersecurity
- Working knowledge of cloud technologies such as Amazon, Azure and Google
- Good understanding of log collection methodologies and aggregation techniques such as Syslog‑NG, syslog, Nxlog, Windows Event Forwarding
- Good understanding of Hadoop ecosystem and Apache technologies
- Experience integrating endpoint security and host-based intrusion detection solutions
- Experience with network forensics and toolsets such as Wireshark, PCAP, tcpdump
Benefits
- Health Insurance with a total sum insured of INR 7,50,000 (coverage includes self, spouse, 2 kids, dependent parents, or parents‑in‑law)
- Personal Accident coverage with a total sum insured of INR 10,00,000
- Term Life Insurance with a sum assured for employees of 5× fixed base pay
Additional details
- Securonix is a cybersecurity unicorn featured in CRN's 2024 Security 100 list and backed by Vista Equity Partners
- Securonix Unified Defense SIEM is an AI‑reinforced, cloud‑native solution built on a cybersecurity mesh architecture leveraging Snowflake Data Cloud for scalability and performance
- The platform offers 365 days of 'hot' data for rapid search and investigation, threat content‑as‑a‑service, proactive defense through continuous peer and partner collaboration, and a fully integrated Threat Detection, Investigation and Response (TDIR) experience
- Securonix serves more than 1,000 customers worldwide, including 10% of the Fortune 100, and has a network of 150+ partners and Managed Security Service Providers (MSSPs)
- Core values: Winning as One Team, Customer Driven Innovation, Agility in Action
- Securonix provides equal employment opportunities (EEO) to all employees and applicants, complying with applicable federal, state and local non‑discrimination laws
- Securonix prohibits unlawful employee harassment based on protected characteristics and does not accept unsolicited headhunter or agency submissions or pay fees without prior agreement
- Originally posted on Himalayas