SIEM Admin
الوصف الوظيفي
About Accenture
Accenture stands at the forefront of global professional services, empowering the world’s most influential businesses, governments, and organizations to construct robust digital foundations, refine operational efficiency, enhance revenue growth, and elevate citizen services. With a workforce of approximately 784,000 professionals spanning over 120 countries, Accenture combines unparalleled expertise in technology, cloud computing, data analytics, and artificial intelligence with deep industry knowledge to drive transformative change. Our comprehensive suite of services—encompassing Strategy & Consulting, Technology, Operations, Industry X, and Song—alongside our commitment to shared success and 360° value creation, enables us to foster enduring client relationships built on trust and innovation. Discover more at www.accenture.com.
Accenture Security: Defending the Digital Frontier
Join Accenture Security to spearhead cutting-edge security solutions that integrate risk strategy, digital identity, cyber defense, application security, and managed services. By leveraging next-generation technologies, you will play a pivotal role in staying ahead of cyber threats, outmaneuvering adversaries, and safeguarding critical assets. Accenture Security delivers end-to-end security services—from strategic risk assessments to business transformation and managed security solutions—on a global scale. Our team of seasoned security professionals empowers organizations to identify risks, build resilience, and focus on innovation and growth with confidence.
Role Overview: Senior SIEM Consultant
We are seeking a highly skilled Senior SIEM Consultant with specialized expertise in Microsoft Sentinel and Azure Security to lead the design, implementation, and optimization of large-scale SIEM solutions for enterprise clients across the Middle East. The ideal candidate will possess 6–8 years of comprehensive cybersecurity experience, a proven track record in client-facing engagements, and hands-on leadership in managing complex, hybrid Sentinel environments within large organizations or Managed Security Service Providers (MSSPs). This role demands a unique blend of technical proficiency and exceptional stakeholder engagement, enabling you to translate intricate security concepts into actionable strategies that drive tangible outcomes.
Key Responsibilities
SIEM & Security Operations Leadership
- Strategic Design & Deployment: Lead the architectural design and deployment of large-scale Microsoft Sentinel implementations tailored to enterprise clients, ensuring alignment with business objectives and security requirements.
- Hybrid Environment Management: Oversee and support complex hybrid Sentinel environments, including multi-cloud, on-premises, multi-tenant, and multi-subscription architectures, to ensure seamless integration and operational efficiency.
- Platform Optimization: Ensure maximum uptime and operational health of SIEM platforms by managing log ingestion, data connectors, and log collectors, while addressing performance bottlenecks and scalability challenges.
- SOC Enhancement: Drive continuous improvement of Security Operations Center (SOC) operations through the development of optimized detection logic, customized dashboards, and automation workflows to enhance threat detection and response capabilities.
Microsoft Azure & Security Engineering
- Azure Security Expertise: Provide deep technical guidance across Microsoft Azure, supporting security architecture, integrations, and troubleshooting to ensure robust protection of cloud environments.
- Log Source Onboarding: Lead the onboarding of large-scale log sources, including Windows and Linux endpoints, network and security devices, and third-party or SaaS applications, ensuring comprehensive visibility and data integrity.
- Troubleshooting & Integration: Address cloud and network-related challenges in log source integration and data flow, resolving issues to maintain seamless security monitoring and incident response.
Detection Engineering & Threat Use Cases
- Advanced Detection Design: Develop and manage sophisticated detection use cases grounded in the MITRE ATT&CK framework, tailored to both standard and client-specific threat scenarios to proactively identify and mitigate risks.
- Defender XDR Integration: Optimize detection rules by leveraging comprehensive knowledge of the Microsoft Defender XDR suite, including Defender for Endpoint, Identity, Office, Cloud Apps, and Servers, to enhance threat detection accuracy and reduce false positives.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.