SIEM Engineer

Ensign InfoSecurity

Jakarta Pusat

On-site

IDR 180,000,000 - 360,000,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ensign InfoSecurity seeks an experienced SIEM Engineer to architect, implement, and maintain SIEM solutions for our clients. You will configure parsers, maintain health and uptime, and develop detections for emerging threats across on-premises and cloud environments.

You will automate processes using PowerShell, Python, or Bash, and work closely with SOC analysts to investigate incidents and improve security postures.

Qualifications

  • Proven experience as a SIEM Engineer or in a similar security operations role.
  • Knowledge of designing and operating SIEM use cases and operational models.
  • Hands-on in multiple security domains such as SIEM, EDR, vulnerability management or cloud security.

Responsibilities

  • Architect, implement, and maintain SIEM solutions for customers.
  • Ensure SIEM health and uptime; patching and upgrades as needed.
  • Integrate data feeds from on-premises and cloud devices; configure parsers and forwarders.
  • Develop detections for latest threats and automate responses using scripting.
  • Support SOC analysts and provide security consultancy to internal teams.

Skills

Cyber security
SIEM engineering
Security monitoring
Scripting: PowerShell/Python
Cloud security

Tools

Splunk
PAM/EDR/IDS-IPS/WAF

Job description

The SIEM engineer will architect, implement, and maintain various SIEM solutions for our customers to support our security analysts. This role will primarily setup, maintain, and enhance various SIEMs.

  • Configure and administer the SIEM to support the needs of SOC.
  • Responsible for maintaining the health of the SIEM tool and ensuring agreed uptime of the respective platform.
  • Perform regular patching and version upgrades on the SIEM platform.
  • Configure respective parsers, forwarders (engage principal vendors if needed) to integrate various log sources with SIEM platform for log monitoring.
  • Research, build, and maintain detection capabilities for the latest threats across SIEM, log analytic, and security tool platforms.
  • Ensure real time data and Configuration replication between Primary and DR sites.
  • Integrate data feeds (logs) into SIEM/Splunk from on-premises and cloud deployed devices and applications.
  • Explore leading cybersecurity products. Work with 3rd party security consultants and service providers to ensure all security aspects are covered. Operate security solutions such as SIEM, PAM, EDR, IDS/IPS and Web Application Firewall while ensuring compliance to regulatory standards and procedures.
  • Security Automation: Automating processes using well-known frameworks such as PowerShell, Python, Bash, etc. As well as SOAR build out. (look like using AWS lambda to integration (CloudFront/WAF/ALB) and automating your work.)
  • Continuous Monitoring: Management AWS Guard duty and intrusion detection, User Behavior, and other security monitoring.
  • Support the SOC Analysts in the use of the toolset and with investigations to establish the facts surrounding potential suspicious activities and to understand the impact and possible risks associated.
  • Creation, amendment, tuning and supporting the engineering of advanced or complex protective monitoring use cases.
  • Provide security consultancy to other internal teams for matters relating to the SIEM.
  • Troubleshooting complex issues that may occur within the SIEM and resolving them with the help of vendor support
  • Advise clients of security standards, best practice and solutions relating to SIEM and SOC solutions.
Requirements
  • Advanced knowledge and experience of Cyber Security and evidence of working as a SIEM Engineer with previous experience of the software, including architectural design, configuring, operating and problem-solving activities.
  • A good understanding of implementing use cases and operational models or specific security solutions to meet the customer's requirement and understand how SIEM solution
  • Hands-on experience in a two or more of the key security domains such as: security operations (SIEM, EDR, vulnerability management), Cloud security, Data security, Identity and access management, and secure software development lifecycle
  • Knowledge of networking and AWS/Azure Cloud Security practices and tools.
  • SIEM related certifications for Administration, implementation, deployment, architecture.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM & Elastic Security Engineer
SIEM & Elastic Security Engineer

Telkom Indonesia • Jakarta Pusat

On-site
IDR 279,000,000 - 502,200,000
Security Platform Engineer
Security Platform Engineer

Ajaib Group • Jakarta Pusat

On-site
Senior SIEM Engineer - Cloud Security & SOC Automation
Senior SIEM Engineer - Cloud Security & SOC Automation

Ensign InfoSecurity • Jakarta Pusat

On-site
IDR 180,000,000 - 360,000,000
TC - SOC Cybersecurity Consultant Manager
TC - SOC Cybersecurity Consultant Manager

EY • Daerah Khusus Ibukota Jakarta

On-site
IT CYBERSECURITY
IT CYBERSECURITY

Confidential • Jakarta Timur

On-site
IDR 200,880,000 - 357,120,000
Information Technology Security Engineer
Information Technology Security Engineer

SECURXCESS • Jakarta Pusat

On-site
IDR 167,400,000 - 390,600,000
Security Operations Center Analyst
Security Operations Center Analyst

Privy • Jakarta Pusat

On-site
IDR 133,920,000 - 200,880,000
SIEM (Security Information and Event Management) Administrator
SIEM (Security Information and Event Management) Administrator

Techconnect • Daerah Khusus Ibukota Jakarta

On-site
IT Security Operation Center (SOC) - L2 (IT Consulting)
IT Security Operation Center (SOC) - L2 (IT Consulting)

Luminare Consulting • Daerah Khusus Ibukota Jakarta

On-site
IDR 671,704,000 - 1,007,557,000
Cyber Security Specialist
Cyber Security Specialist

Indivara Group • Indonesia

On-site
IDR 180,000,000 - 280,000,000