Engineering Specialist

  • Noida
  • Birlasoft

About the Job: We are seeking a highly motivated and experienced SIEM SME to join our security team. In this role, you will play a pivotal role in strengthening our organization's security posture by implementing and managing a SIEM solution. You will be responsible for the entire SIEM lifecycle, from initial selection and configuration to ongoing monitoring, analysis, and optimization.


Job Title: SIEM Engineer


Location: Hyderabad, Bangalore, Mumbai, Noida, Chennai, Pune


Educational Background : Post graduation/bachelor’s degree in computer science, or Engineering.


Key Responsibilities :


Participate in the selection and evaluation of SIEM solutions based on business needs and security requirements.

Lead the implementation and configuration of the chosen SIEM solution.

Develop and maintain comprehensive log collection strategies from various security devices, applications, and systems.

Configure and manage SIEM rules for real-time threat detection, incident correlation, and anomaly identification.

Design and implement Security Orchestration, Automation, and Response (SOAR) workflows for automated incident response.

Create critical security dashboards and reports to provide real-time insights into security posture and potential threats.

Develop and maintain use cases for effective SIEM monitoring and incident response.

Analyze SIEM data to identify potential security incidents, investigate suspicious activity, and escalate critical issues.

Stay up-to-date on the latest cyber threats, SIEM best practices, and emerging technologies.

Provide ongoing training and support to internal stakeholders on SIEM capabilities and incident response procedures.


Qualifications


4-5 years of experience in implementing and managing SIEM solutions.

Proven experience with renowned SIEM tools and solutions (e.g., Splunk, Microsoft Sentinel, ArcSight, LogRhythm, IBM QRadar, etc.).

Strong understanding of SOAR principles and experience with SOAR platforms.

Expertise in log management, security event correlation, and threat detection techniques.

Experience in designing and implementing security dashboards and reports.

Excellent analytical and problem-solving skills.

Strong communication and collaboration skills.

Ability to work independently and as part of a team.

A passion for cybersecurity and a desire to stay current on industry trends.


Preferred Qualifications


Certifications in SIEM technologies (e.g., Splunk Certified User, SC-200, MCSA: Security Operations)

Experience with security automation scripting languages (e.g., Python, PowerShell)

Experience with security information and event management (SIEM) for cloud environments