SIEM Admin
الوصف الوظيفي
About Innovative Solutions (IS)
Innovative Solutions (IS) is a premier cybersecurity firm established in 2003, headquartered in Riyadh, with strategic offices in Al Khobar, Jeddah, Dubai, and Abu Dhabi. We are committed to delivering cutting-edge cybersecurity solutions and services, including Advisory Services, Technical Assurance, Solution Deployment, Professional Services, and Managed Security Services. Our mission is to empower organizations by providing secure and intelligent digital services that drive operational excellence and resilience.
Role Overview
We are seeking a highly skilled and proactive SIEM Administrator to join our dynamic team. In this pivotal role, you will be responsible for designing, deploying, and maintaining our Security Information and Event Management (SIEM) platform. As the technical backbone of our log management and threat detection infrastructure, you will collaborate closely with cross-functional teams to ensure seamless integration of log sources, develop custom detection rules, and maintain the operational integrity of our security operations tools. Your expertise will be instrumental in safeguarding enterprise assets against evolving cyber threats.
Key Responsibilities
- Platform Architecture & Maintenance: Design, deploy, patch, and upgrade the SIEM platform and associated agents to ensure optimal performance and security. Stay abreast of industry advancements to implement best practices in system administration.
- Log Onboarding & Integration: Partner with business units to map network hierarchies, establish foundational building blocks, and classify log sources for comprehensive visibility. Ensure seamless integration of diverse log sources into the SIEM environment.
- Custom Development & Integration: Develop and deploy custom API connectors and parsers to support non-standard log sources that lack native vendor support. Enhance the SIEM’s capabilities to process and analyze unique data formats effectively.
- Threat Detection & Modeling: Design and implement robust use cases, custom SIEM detection rules, and MITRE ATT&CK-based threat models. Proactively identify and mitigate potential security risks to strengthen our defensive posture.
- Operations & Troubleshooting: Diagnose and resolve day-to-day operational issues across log sources, collectors, agents, and other SOC tools. Maintain high system availability and performance to support continuous security monitoring.
- Data Governance & Compliance: Manage data archiving, backups, retention, and purging configurations in alignment with regulatory and compliance standards. Ensure data integrity and availability for forensic investigations and audits.
- Change & Audit Management: Initiate, track, and manage change tickets for administrative tasks such as patch upgrades and log onboarding. Prepare detailed assessment reports for existing platforms to ensure transparency and accountability.
- System Administration: Apply foundational Windows and Unix administration skills to support the health and stability of the SIEM infrastructure. Implement hardening techniques to enhance system security and resilience.
Requirements & Qualifications
- Education & Experience: Bachelor’s degree in a related field (e.g., Cybersecurity, Computer Science, or Information Technology) or equivalent professional experience in a relevant domain.
- Core Technical Knowledge: Demonstrated expertise in cybersecurity and IT disciplines, including networking, operating systems, authentication protocols, enterprise architecture, and incident response methodologies.
- Enterprise Technology Proficiency: Familiarity with common enterprise tools and logging capabilities, such as firewalls, Active Directory, EDR/antivirus solutions, IDS/IPS systems, proxies, and cloud platforms. Knowledge of SOAR (Security Orchestration, Automation, and Response) is highly desirable.
- SIEM Expertise: Hands-on experience with log aggregation or correlation technologies, including Splunk, QRadar, LogRhythm, Microsoft Sentinel, or Palo Alto XSIAM.
- Security Principles: Deep understanding of risk management processes, the CIA triad (Confidentiality, Integrity, Availability), cryptography, Identity and Access Management (IAM), access controls, and network security methodologies.
- System Hardening: Proven experience in system administration, network, and operating system hardening techniques to mitigate vulnerabilities and enhance security postures.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.