Entelligence · 18 hours ago
XSIAM Engineer
Entelligence is seeking an Engineer to support our clients. As an Engineer for Cortex XSIAM, you will assist with log migration and detection strategies, ensuring log sources are onboarded and helping to protect customers from threats by designing and implementing correlation rules.
Information ServicesInformation Technology
Responsibilities
Work with technical lead to develop log ingestion strategy
Contribute to detection strategy based on industry best practices
Detail step by step process to ingest high quality log sources
Perform log source monitoring and optimization
Create high quality correlation rules
Tune log sources and correlation rules
Be an SME for SIEM, Correlation and Log Source Ingestion
Recognize opportunities where automation can improve analyst alert handling
Collaborate with internal and external teams to ensure product adoption
Create technical documentation detailing SIEM aspects of the engagement
Travel to customer meetings and workshops as needed (10%)
Qualification
Required
Strong communication (written and verbal) and presentation skills, both internally and externally
Fluent English is a requirement - Any other language is a plus
3+ years of deploying and integrating (SIEM) to enterprise to large enterprise-level
Coordinating and conducting event collection, log management, event management, compliance automation, and identity monitoring activities using (SIEM) platforms
The ability to create and develop correlation and detection rules, within a (SIEM) to support alerting capabilities
Experience working with and deploying a variety of SIEM technologies (i.e Splunk, IBM QRadar)
A proven ability to offer suggestions on detection strategy based on customer requirements
Ability to understand logs, locating and understanding 3rd party documentation where needed
Familiarity with reports on the status of the SIEM to include metrics on items such as number of logging sources - log collection rate, and other performance metrics
Knowledge of Security Analysis & Response a plus, including both endpoint, network & cloud based environments
3 years experience with Security Operation Centers tooling and processes
Relevant bachelor's degree or industry recognized qualifications (CISSP, GIAC, SIEM Vendor Qualification etc)
Ability to read and understand technical design documentation
Ability to create technical design documentation
Benefits
Competitive base salary
Medical, dental, vision and life insurance
Vacation, sick time and paid holidays
Matching 401(k) program
Company
Entelligence
Entelligence helps the world’s technology leaders quickly deliver their most advanced cloud solutions to their most important customers.
H1B Sponsorship
Entelligence has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2021 (2)
Funding
Current Stage
Growth StageLeadership Team
Company data provided by crunchbase