Jobs · Consulting

XSIAM Automation Consultant

Entelligence · United States · 3 wk ago
RemoteRemoteConsultingFull-time

Entelligence is seeking an Engineer to support our Professional Services clients. The successful candidate must be able to work in a cross-functional environment and interact with representatives from Entelligence and the end-user.

About the role

As an Engineer for Cortex XSIAM, you will be responsible for assisting with the log migration and detection strategy of our customers. You will work closely with the technical lead to ensure that all of the relevant log sources are onboarded and ingested into XSIAM in accordance with industry best practices and customer requirements. You will then work to determine a suitable detection strategy, helping to protect customers from threats by designing and implementing correlation rules.

Responsibilities

  • Work with technical lead to develop log ingestion strategy
  • Contribute to detection strategy based on industry best practices
  • Detail step-by-step process to ingest high-quality log sources
  • Perform log source monitoring and optimization
  • Create high-quality correlation rules
  • Tune log sources and correlation rules
  • Be an SME for SIEM, Correlation, and Log Source Ingestion
  • Recognize opportunities where automation can improve analyst alert handling
  • Collaborate with internal and external teams to ensure product adoption
  • Create technical documentation detailing SIEM aspects of the engagement
  • Travel to customer meetings and workshops as needed (10%)

Requirements

  • Strong communication (written and verbal) and presentation skills, both internally and externally
  • Fluent English is required; any other language is a plus
  • 3+ years of deploying and integrating SIEM in enterprise to large enterprise-level environments
  • Experience coordinating and conducting event collection, log management, event management, compliance automation, and identity monitoring activities using SIEM platforms
  • Ability to create and develop correlation and detection rules within a SIEM to support alerting capabilities
  • Experience working with and deploying a variety of SIEM technologies (e.g., Splunk, IBM QRadar)
  • Proven ability to offer suggestions on detection strategy based on customer requirements
  • Ability to understand logs and locate/understand third-party documentation where needed
  • Familiarity with reports on SIEM status, including metrics such as number of logging sources, log collection rate, and other performance metrics
  • Knowledge of Security Analysis & Response (a plus), including endpoint, network, and cloud-based environments
  • 3 years of experience with Security Operation Centers tooling and processes
  • Relevant bachelor’s degree or industry-recognized qualifications (e.g., CISSP, GIAC, SIEM Vendor Qualification)
  • Ability to read and understand technical design documentation
  • Ability to create technical design documentation

Benefits

  • Competitive base salary
  • Medical, dental, vision, and life insurance
  • Vacation, sick time, and paid holidays
  • Matching 401(k) program

Similar jobs

Automation Mechanic

Factory Automation JobsMaumelle, AR· 2 wk ago
Managementapply on jobs.factoryautomationjobs.com

Automation Mechanic

CVS HealthMount Prospect, IL· 3 mo ago
Managementapply on jobs.cvshealth.com

Automation Operator

Little Leaf FarmsManchester, TN· 3 wk ago
OTHR$20/hrapply on recruiting.paylocity.com