Security Content Engineer at Securonix building analytics content and threat detection models for their SIEM platform. Collaborating with the Detection Engineering team to combat advanced cyber threats.
Responsibilities
Learn the platform capabilities and internals to be able to support troubleshoot issues with detection content
Triage customer tickets and provide technical support for issues in customer environment associated to detection content
Provide on-call support during weekdays and weekends
Proactively monitor reports and dashboards tracking content metrics from the field and flag issues
Help generate or collect sample logs relevant for resolution of detection tickets
Document RCAs for issues resolved
Ensure detection content is sufficiently tested and validated before pushing to production
Submit clear documentation around the detection content developed
Responsible for maintaining policies and threat-models in the Securonix platform
Requirements
At-least 1 year of prior experience in building threat detection content for SIEM platforms like ArcSight, QRadar, Splunk, LogRhythm, etc.
Understanding of the different MITRE ATT&CK Matrices
Strong fundamentals in network and operating systems concepts
Experience working with offensive security testing tools
Ability to automate basic tasks using scripting languages like Python
Experience in GIT and SVN based code management
Benefits
Health Insurance with a total sum insured is INR 5,00,000 Coverage: Self, Spouse, 2 kids, Dependent parents, or parents-in-law
Personal Accident with total sum insured is INR 10,00,000
Term Life Insurance with a sum assured for employees is 5 times fixed base pay is covered.
Director managing strategic stakeholder engagement for cyber security initiatives in Australia. Collaborating across governments and industry to drive national cyber preparedness and awareness.
Information Systems Security Officer ensuring operational security for information systems. Collaborating with ISSM and ISO while managing security operations and compliance.
Cybersecurity Engineer Principal at GDIT leads enterprise initiatives for improving identity and access security. Collaborates with leadership to architect modern IAM solutions per Zero Trust Principles.
Manager role supporting Cybersecurity and Technology Risk Oversight Center of Excellence. Leading regulatory exams and audits while collaborating with cross - functional risk management teams.
Cybersecurity Specialist protecting DSV Contract Logistics IT platforms. Manage cybersecurity risks and embed security into IT solutions while ensuring operational continuity.
Regional Security Manager responsible for security operations at EMEA Data Centers. Collaborating with cross - functional teams for compliance and incident management.
Chargé.e d’Etudes et Travaux en systèmes électromécaniques de sécurité at RATP Infrastructures. Responsible for ensuring technical compliance and supervising project activities on - site.
Senior Infrastructure Security Engineer handling cloud security and infrastructure lifecycle for Zocks, a fintech startup. Responsible for security initiatives and compliance readiness in a rapidly growing team.
Data Center Security Officer ensuring safety and security for data center clients through patrols and monitoring. Conducting reports and maintaining client security requirements.