SIEM Security Engineer
- SIEM
- Incident Response
- Microsoft Sentinel
- LogRhythm
- triage
- Active Directory
- EDR
- Threat Intelligence
- ServiceNow
- Windows
- Linux
- DNS
- DHCP
Job Title: SIEM Security Engineer
Experience: 6-12 Years
Location PAN INDIA
Job Summary:
We are seeking an experienced SIEM Security Engineer with strong expertise in Security Operations, Threat Monitoring, Incident Response, and SIEM technologies. The ideal candidate should have hands-on experience with Microsoft Sentinel, IBM QRadar, ArcSight, LogRhythm, or similar SIEM platforms and possess strong analytical skills for identifying, investigating, and responding to security incidents.
Key Responsibilities:
• Monitor, analyze, and investigate security alerts generated from SIEM platforms.
• Perform incident triage, threat analysis, root cause investigation, and remediation activities.
• Correlate logs from various security devices including Firewalls, IDS/IPS, Proxy, Active Directory, EDR, and Email Security solutions.
• Support 24x7 Security Operations Center (SOC) activities and ensure timely response to security incidents.
• Conduct phishing investigations, malware analysis, IOC validation, and threat intelligence research.
• Develop and maintain incident response procedures, playbooks, and operational documentation.
• Generate daily, weekly, and monthly security monitoring reports and dashboards.
• Collaborate with Threat Intelligence, Incident Response, Compliance, and Infrastructure teams.
• Perform threat hunting activities using MITRE Telecommunication&CK and Cyber Kill Chain methodologies.
• Escalate critical incidents and coordinate containment, remediation, and recovery activities.
Required Skills:
• Strong experience with Microsoft Sentinel, IBM QRadar, ArcSight, AlienVault, or LogRhythm.
• Hands-on experience in Security Monitoring and Incident Response.
• Knowledge of IDS/IPS, Firewalls, Proxy, Active Directory, EDR, Email Security, and Endpoint Security.
• Experience in IOC analysis, Threat Intelligence, Malware Analysis, and Phishing Investigations.
• Familiarity with MITRE Telecommunication&CK Framework and Cyber Kill Chain.
• Experience with ServiceNow or similar ticketing platforms.
• Good understanding of Windows, Linux, Networking, DNS, DHCP, and Security Concepts.
• Strong communication, documentation, and analytical skills.
SIEM Security Engineer · Diverse Lynx India