Cyber Security Engineer (SIEM)
Xapiens Teknologi Indonesia
Tangerang Selatan
On-site
IDR 200.000.000 - 300.000.000
Full time
11 days ago
Job summary
A technology firm in Banten, Indonesia is seeking a Cybersecurity Engineer. You will manage and optimize SIEM solutions, analyze security events, and support incident response efforts. The ideal candidate will have a Bachelor's degree in a relevant field and 2–3 years of experience in SIEM management and cybersecurity operations.
Qualifications
- 2–3 years of hands-on experience in SIEM management, SOC operations, or cybersecurity engineering.
- Familiarity with working in SOC environments or security monitoring teams is a plus.
- Proficiency with scripting (Python, Bash, or PowerShell).
Responsibilities
- Deploy, configure, and maintain SIEM solutions.
- Develop, tune, and optimize correlation rules and alerts.
- Analyze and investigate security events.
Skills
SIEM deployment
Incident response
Correlation rules development
Security event analysis
Log management
Network protocols knowledge
Education
Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field
Tools
Splunk
IBM QRadar
ArcSight
ELK/Wazuh
Responsibilities
- Deploy, configure, and maintain SIEM solutions (e.g., Splunk, IBM QRadar, ArcSight, ELK/Wazuh).
- Develop, tune, and optimize correlation rules, alerts, dashboards, and use cases.
- Analyze and investigate security events, reducing false positives and ensuring actionable alerts.
- Collaborate with SOC analysts and IT operations to support incident response and forensic analysis.
- Integrate SIEM with security tools such as IDS/IPS, Firewalls, EDR, and Threat Intelligence feeds.
- Provide security reporting to support compliance and audit requirements.
- Continuously enhance SIEM performance and support security architecture improvements.
Requirements
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field.
- Professional certifications preferred: CEH, CompTIA Security+, Splunk Certified, QRadar Certified, or equivalent.
- 2–3 years of hands-on experience in SIEM management, SOC operations, or cybersecurity engineering.
- Direct experience in deploying and maintaining SIEM platforms.
- Familiarity with working in SOC environments or security monitoring teams is a plus.
- Strong knowledge of SIEM concepts, log management, event correlation, and incident detection.
- Proficiency with network protocols (TCP/IP, HTTP, DNS, SMTP) and both Windows and Linux environments.
- Ability to create and manage parsing rules, regular expressions, and scripting (Python, Bash, or PowerShell).
- Understanding of security frameworks (e.g., NIST, ISO 27001) and compliance requirements.