SIEM Engineer Trantor
Trantor
Office Location
Full Time
Experience: 6 - 6 years required
Pay:
Salary Information not included
Type: Full Time
Location: Noida
Skills: SIEM, Security Incident Response, NIST, soar, correlation rules, log ingestion strategy, Threat Hunting, Regular expression, Security Analysis Response, CIS, CSA
About Trantor
Trantor is a pioneer in the development of enterprise technology solutions and state-of-the-art CaptiveCoE™, assisting global enterprises with their digital transformations and business requirements. Our dedication to excellence and sincerity has resulted in enduring partnerships with our clients and solution partners. Since 2012, Trantor has assisted businesses all over the world in expanding their engineering capabilities and developing successful technology products. With extensive knowledge of cloud strategy, cloud-native development, containers, application modernization, AI/ML, and Security/Compliance, we help our customers accelerate innovation by leveraging the full capabilities of the AWS cloud. Trantor's knowledge of AWS cloud services enables clients to achieve operational excellence, security, and compliance on AWS Cloud. Trantor assists clients in optimising their use of AWS through Managed DevOps services and commits to accurately estimating migration costs and developing a comprehensive AWS migration plan. Trantor assists clients in gaining cost control and continuously optimising spending while developing modern, scalable cloud applications to meet their needs. Trantor delivers intelligent automation solutions by combining Analytics, Automation, and AI. We enable clients to scale their strategic marketing and technology initiatives. Our in-depth knowledge of Fintech, Martech, E-commerce, and Captive Centers is reflected in our extensive portfolio and globally dispersed clientele. We also cultivate strong partnerships with leading technology providers, such as Amazon Web Services (AWS), Microsoft, Oracle, Adobe, Cloud Lending, and Genpact, among others.
Job Description
As a SIEM Engineer, you will be responsible for assisting with the log migration and detection strategy of our customers. You will ensure that all of the relevant log sources are onboarded and ingested into SOAR in accordance with industry best practices and customer requirements. You will then work to determine a suitable detection strategy, helping to protect customers from threats, by designing and implementing correlation rules. Responsibilities: Devise a comprehensive log ingestion strategy Create meticulous and effective correlation rules Fine-tune log sources and correlation rules to enhance system efficiency Contribute to the development of detection strategies based on industry best practices Articulate a step-by-step process to ensure the ingestion of high-quality log sources Monitor and optimize log sources for optimal performance Serve as the subject matter expert (SME) in SIEM and SOAR, correlation, and log source ingestion Leverage your in-depth knowledge of SIEM and SOAR and SOC practices to assess customer needs, provide tailored recommendations, and assist in the formulation of effective security strategies Produce technical documentation detailing SIEM and SOAR aspects of the engagement. Qualifications: 6+ years of experience in deploying and integrating (SIEM) to enterprise to large enterprise-level Deep expertise with load, transformation and correlation of sources such as Cloud, Endpoint, Firewall Coordinating and conducting event collection, log management, event management, compliance automation, and identity monitoring activities using (SIEM) platforms Architect-level individual with experience in SIEM (Splunk, Netwitness, Qradar, Arcsight etc.).Candidates with Qradar experience will be preferred. Ability to perform Threat Hunting exercises from telemetry. Extensive experience in creating and developing correlation and detection rules, within a SIEM to support alerting capabilities. Strong Regular Expression skills. A proven ability to offer suggestions on detection strategy based on customer requirements. Knowledge of Security Analysis & Response a plus, including both endpoint, network & cloud-based environments. Strong technical skills in SIEM/SOAR tools and technologies Experience in developing and implementing security strategies Experience in conducting security incident response Ability to define and design security controls based on NIST, CIS, CSA and other standards Certifications such as CISSP, CISM, GIAC, SIEM Vendor Qualification would be a plus. Excellent communication and interpersonal skills Immediate and early joiners will be preferred. Kindly share your resume on abhishek.kumar@trantorinc.com,