Primary Responsibility
- Planning, creating, establishing, managing, monitoring and serving as a subject matter expert in Security Operation Center/Cyber Defense Center (SOC/CDC)
- Stabilize and optimize ArcSight SIEM system Performance, MDR (Managed Detection & Response) Platform including infra, content & reports.
- Plan all SOC change activities, attend Change Management Meetings and ensure all SOC change request is addressed.
- Assess requirement, Plan and drive device On-boarding devices to SIEM platform in collaboration of MSSP
- Drive Threat Hunting/User behavior analytics (UEBA) with MSSP and review outcome
- Compile and Validate statistical data to be used to determine the viability of SIEM/SOC/CDC across the organization.
- Plan and implementation Security automation/ Orchestration
Performance Parameters :
- Complete visibility of Cyber Intrusion and system activities in the environment through Logging & Monitoring solution
- SOC/CDC KPIs are maintained and False Positives for Alerts/Incidents are minimal
- NIL observations in Audits (Internal, client, Third Party) due to an unknown issue
Qualification :
- Strong knowledge of Arcsight SIEM Platform including Content Management(Use Case, TI etc) & Administration
- Good working exposure with Security Operations center/Cyber Defense Center for Alert, Triage, and Incident
- Knowledge of Industrywide Cyber Attacks & Threat Intelligence
- Understanding of Information Security frameworks like NIST and Attack framework such as TTPs and the ATT&CK
- At least one industry accepted Security Certification
- Bachelor's degree in information technology or computer science related field.
Experience :
- 5-7 years of Information Technology/Information Security experience
- Must have managed ArcSight SIEM Platform for a medium or large organization including content and infrastructure
- Ability to understand requirements and business drivers and priorities, and integrate these requirements into overall DLP controls and policies
Didn’t find the job appropriate? Report this Job