Job Description
Ø Develop and implement content for any SIEM platforms, including Google Chronicle, Sumologic, and Splunk.
Ø Configure and fine-tune use cases, correlation, grouping, and logical rules in SIEM tools.
Ø Integrate new log sources, assets with SIEM, and incremental threat intelligence feeds.
Ø Draft, test, and deploy YARA and Chronicle Backstory rules.
Ø Curate and update Incident Response Guides.
Ø Customize SIGMA rules and maintain familiarity with the MITRE ATT&CK Framework.
Ø Develop threat detection content for various datasets such as Proxy, VPN, Firewall, and DLP.
Ø Aid in process development/improvement for Security Operations.
Ø Recognize and propose new security controls to bridge existing gaps.
Ø Chronicle Backstory/ ELK Stack/ YARA / CrowdStrike rules experience is a plus.
Skills:- Security Information and Event Management (SIEM), Google Chronicle, Sumologic, Splunk and Crowdstrike