Guadalajara, Jalisco
Job Summary
Responsible for the design & implementation of SIEM platform(s). • Responsible for upgrading/updating of SIEM components & applications within. • Responsible for the integration of various log sources with SIEM. • Responsible for custom log source integrations with SIEM. • Responsible for monitoring and maintaining the health of SIEM components & applications within. • Responsible for creation/modification of security use case (rule triggers) in SIEM by understanding the customer infra setup and customer needs. • Responsible for the creation/modification of reports (automated & custom). • Responsible for working with respective stakeholders to on-board or troubleshoot the broken log sources if any. • Responsible for Custom Property Creation. • Responsible for WinCollect Installation & Management. • Responsible for Apps Installation & Apphost Management. Technical Experience: • Custom Event Mapping for unknown events, miscategorized events, and custom log source extensions. • Work with the IRT team to remediate offenses, tune rules for false positives, and create new rules. • Creation and management of reference sets and outside threat intel sources. • Onboard new log sources and assign log sources to the correct group. • Dashboard creation for monitoring environment. • Report creation and maintenance. • Maintain all components of a distributed QRadar infrastructure and deployment servers. Provide overall management of the QRadar platform deployment, configuration, and maintenance across various UNIX and Windows platforms. Professional Attributes: • Previous QRadar administration or development (DSM/parser development) experience: At least 2 years of QRadar experience is required. • Create, modify, and tune the SIEM rules to adjust the specifications of alerts and incidents. • Work with customer-designated personnel to provide continual correlation rule tuning, incident classification, and prioritization recommendations. • Report query adjustments, dashboard creation, system maintenance, and other SIEM configuration activities. • Familiarity with working in the Red Hat Enterprise Linux operating system. • Custom Event Mapping for unknown events, miscategorized events, and custom log source extensions. • Work with the IRT team to remediate offenses, tune rules for false positives, and create new rules. • Creation and management of reference sets and outside threat intel sources. • Onboard new log sources and assign log sources to the correct group. • Dashboard creation for monitoring environment. • Report creation and maintenance. • Maintain all components of a distributed QRadar infrastructure and deployment servers. Provide overall management of the QRadar platform deployment, configuration, and maintenance across various UNIX and Windows platforms.
Key Responsibilities
Responsible for the design & implementation of SIEM platform(s). • Responsible for upgrading/updating of SIEM components & applications within. • Responsible for the integration of various log sources with SIEM. • Responsible for custom log source integrations with SIEM. • Responsible for monitoring and maintaining the health of SIEM components & applications within. • Responsible for creation/modification of security use case (rule triggers) in SIEM by understanding the customer infra setup and customer needs. • Responsible for the creation/modification of reports (automated & custom). • Responsible for working with respective stakeholders to on-board or troubleshoot the broken log sources if any. • Responsible for Custom Property Creation. • Responsible for WinCollect Installation & Management. • Responsible for Apps Installation & Apphost Management. Technical Experience: • Custom Event Mapping for unknown events, miscategorized events, and custom log source extensions. • Work with the IRT team to remediate offenses, tune rules for false positives, and create new rules. • Creation and management of reference sets and outside threat intel sources. • Onboard new log sources and assign log sources to the correct group. • Dashboard creation for monitoring environment. • Report creation and maintenance. • Maintain all components of a distributed QRadar infrastructure and deployment servers. Provide overall management of the QRadar platform deployment, configuration, and maintenance across various UNIX and Windows platforms. Professional Attributes: • Previous QRadar administration or development (DSM/parser development) experience: At least 2 years of QRadar experience is required. • Create, modify, and tune the SIEM rules to adjust the specifications of alerts and incidents. • Work with customer-designated personnel to provide continual correlation rule tuning, incident classification, and prioritization recommendations. • Report query adjustments, dashboard creation, system maintenance, and other SIEM configuration activities. • Familiarity with working in the Red Hat Enterprise Linux operating system. • Custom Event Mapping for unknown events, miscategorized events, and custom log source extensions. • Work with the IRT team to remediate offenses, tune rules for false positives, and create new rules. • Creation and management of reference sets and outside threat intel sources. • Onboard new log sources and assign log sources to the correct group. • Dashboard creation for monitoring environment. • Report creation and maintenance. • Maintain all components of a distributed QRadar infrastructure and deployment servers. Provide overall management of the QRadar platform deployment, configuration, and maintenance across various UNIX and Windows platforms.
Skill Requirements
Responsible for the design & implementation of SIEM platform(s). • Responsible for upgrading/updating of SIEM components & applications within. • Responsible for the integration of various log sources with SIEM. • Responsible for custom log source integrations with SIEM. • Responsible for monitoring and maintaining the health of SIEM components & applications within. • Responsible for creation/modification of security use case (rule triggers) in SIEM by understanding the customer infra setup and customer needs. • Responsible for the creation/modification of reports (automated & custom). • Responsible for working with respective stakeholders to on-board or troubleshoot the broken log sources if any. • Responsible for Custom Property Creation. • Responsible for WinCollect Installation & Management. • Responsible for Apps Installation & Apphost Management. Technical Experience: • Custom Event Mapping for unknown events, miscategorized events, and custom log source extensions. • Work with the IRT team to remediate offenses, tune rules for false positives, and create new rules. • Creation and management of reference sets and outside threat intel sources. • Onboard new log sources and assign log sources to the correct group. • Dashboard creation for monitoring environment. • Report creation and maintenance. • Maintain all components of a distributed QRadar infrastructure and deployment servers. Provide overall management of the QRadar platform deployment, configuration, and maintenance across various UNIX and Windows platforms. Professional Attributes: • Previous QRadar administration or development (DSM/parser development) experience: At least 2 years of QRadar experience is required. • Create, modify, and tune the SIEM rules to adjust the specifications of alerts and incidents. • Work with customer-designated personnel to provide continual correlation rule tuning, incident classification, and prioritization recommendations. • Report query adjustments, dashboard creation, system maintenance, and other SIEM configuration activities. • Familiarity with working in the Red Hat Enterprise Linux operating system. • Custom Event Mapping for unknown events, miscategorized events, and custom log source extensions. • Work with the IRT team to remediate offenses, tune rules for false positives, and create new rules. • Creation and management of reference sets and outside threat intel sources. • Onboard new log sources and assign log sources to the correct group. • Dashboard creation for monitoring environment. • Report creation and maintenance. • Maintain all components of a distributed QRadar infrastructure and deployment servers. Provide overall management of the QRadar platform deployment, configuration, and maintenance across various UNIX and Windows platforms.
Other Requirements
Responsible for the design & implementation of SIEM platform(s). • Responsible for upgrading/updating of SIEM components & applications within. • Responsible for the integration of various log sources with SIEM. • Responsible for custom log source integrations with SIEM. • Responsible for monitoring and maintaining the health of SIEM components & applications within. • Responsible for creation/modification of security use case (rule triggers) in SIEM by understanding the customer infra setup and customer needs. • Responsible for the creation/modification of reports (automated & custom). • Responsible for working with respective stakeholders to on-board or troubleshoot the broken log sources if any. • Responsible for Custom Property Creation. • Responsible for WinCollect Installation & Management. • Responsible for Apps Installation & Apphost Management. Technical Experience: • Custom Event Mapping for unknown events, miscategorized events, and custom log source extensions. • Work with the IRT team to remediate offenses, tune rules for false positives, and create new rules. • Creation and management of reference sets and outside threat intel sources. • Onboard new log sources and assign log sources to the correct group. • Dashboard creation for monitoring environment. • Report creation and maintenance. • Maintain all components of a distributed QRadar infrastructure and deployment servers. Provide overall management of the QRadar platform deployment, configuration, and maintenance across various UNIX and Windows platforms. Professional Attributes: • Previous QRadar administration or development (DSM/parser development) experience: At least 2 years of QRadar experience is required. • Create, modify, and tune the SIEM rules to adjust the specifications of alerts and incidents. • Work with customer-designated personnel to provide continual correlation rule tuning, incident classification, and prioritization recommendations. • Report query adjustments, dashboard creation, system maintenance, and other SIEM configuration activities. • Familiarity with working in the Red Hat Enterprise Linux operating system. • Custom Event Mapping for unknown events, miscategorized events, and custom log source extensions. • Work with the IRT team to remediate offenses, tune rules for false positives, and create new rules. • Creation and management of reference sets and outside threat intel sources. • Onboard new log sources and assign log sources to the correct group. • Dashboard creation for monitoring environment. • Report creation and maintenance. • Maintain all components of a distributed QRadar infrastructure and deployment servers. Provide overall management of the QRadar platform deployment, configuration, and maintenance across various UNIX and Windows platforms.
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-