TQUKI0404_4412 - SIEM Implementation

Job Title:

SOC (Security Operations Center) Lead


Required Expertise

  • Minimum 7–10 years of experience in Security Operations and Incident Response
  • Expertise in using SIEM tools (Sumo Logic), EDR, Email Security, and Incident Response
  • Responsible for providing advanced technical support and incident response


Key Responsibilities

  • Utilize SIEM tools such as Sumo Logic, QROC, and Azure Sentinel to monitor the security environment for potential threats and incidents
  • Analyze and triage security alerts generated by SIEM, EDR, and other security tools
  • Respond to security incidents: contain, mitigate, and remediate security threats
  • Analyze, review, and validate logs from various log sources
  • Suggest use case fine-tuning and create new use cases
  • Troubleshoot SIEM issues related to log sources
  • Collaborate with SOC team members and internal/external stakeholders to resolve complex incidents
  • Stay updated on latest cybersecurity threats, trends, and technologies to improve response effectiveness
  • Document security incidents and responses as per established procedures
  • Create SOPs and Playbooks for SOC incident triage
  • Establish KPIs, manage security logs, and provide reports based on metrics
  • Respond to client requests, concerns, and suggestions
  • Track SOC performance in terms of SLAs and incident quality
  • Prepare Daily, Weekly, and Monthly reports as required by clients
  • Develop and provide reporting metrics to demonstrate the SOC’s role and function
  • Lead governance calls with customers, presenting KPI and SLA reports



Requirements

  • Experience as a Senior Security Analyst leading a team
  • Hands-on experience in a Security Operations Center (SOC)
  • Experience in network event analysis and/or threat analysis
  • Proven Incident Responder experience
  • Strong knowledge of various security methodologies and technical security solutions
  • Ability to analyze data from cybersecurity monitoring tools
  • Skilled in analyzing endpoint, network, and application logs
  • Solid understanding of Internet protocols and common applications
  • Bachelor’s degree in Computer Science, Information Technology, or equivalent experience

Certifications (Preferred)

  • CEH, CISM, CompTIA Security+, Sumo Logic, QROC
  • Any of the above certifications are an added advantage


Want us
TO WORK FOR YOU?

GET THE QUOTE

Want to
WORK WITH US?

CAREER