SIEM Engineer
# SIEM Engineer **Ebizolution** · Makati · `On-site` 🕒 **Статус:** *Опубликовано: 4 дня назад* · *Источник: Indeed* --- ### About the Role Job Summary The SIEM Engineer is responsible for deploying, integrating, configuring, tuning, and maintaining Security Information and Event Management (SIEM) platforms to support effective security monitoring, threat detection, and incident response. The role focuses on maintaining SIEM integrations, log sources, dashboards, detection use cases, correlation rules, and security reports. The SIEM Engineer works closely with SOC, IT Infrastructure, Network, Endpoint, and other technical teams to ensure reliable log collection, accurate security event detection, and continuous improvement of SIEM capabilities. Key Responsibilities Maintain and manage SIEM platform integrations , ensuring reliable connectivity and data flow from security and IT systems. Configure, monitor, and maintain log sources , including servers, network devices, firewalls, endpoints, applications, databases, and cloud environments. Ensure proper log collection, parsing, normalization, and data quality within the SIEM platform. Develop, maintain, and tune SIEM use cases and correlation rules to improve threat detection and reduce false positives. Configure and maintain SIEM dashboards for security monitoring, operational visibility, and management reporting. Develop and maintain security reports covering security events, incidents, alerts, log source health, and SIEM performance. Troubleshoot SIEM integration issues, missing logs, ingestion failures, parsing errors, and other platform-related problems. Monitor SIEM performance, log ingestion, storage, and system health to ensure platform availability and reliability. Collaborate with SOC analysts to review detection requirements, improve alert quality, and enhance security monitoring capabilities. Support the onboarding of new log sources and security technologies into the SIEM environment. Review and optimize correlation rules, detection logic, and alert thresholds based on emerging threats and operational requirements. Assist in investigating security events and provide relevant log data and technical analysis to support incident response. Maintain SIEM documentation, including integration configurations, log source inventories, use cases, correlation rules, and operating procedures. Support SIEM upgrades, configuration changes, maintenance activities, and security tool integrations. Ensure SIEM operations align with organizational security policies, monitoring requirements, and compliance standards. Perform other SIEM engineering and security monitoring activities as assigned. Minimum Qualifications Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or a related field . Experience deploying, integrating, tuning, and maintaining SIEM platforms, log sources, correlation rules, dashboards, and reports . Hands-on experience with SIEM configuration, log collection, and security event monitoring. Working knowledge of log management, event correlation, and security detection concepts. Experience troubleshooting SIEM integrations, log ingestion, and data parsing issues. Understanding of network security, operating systems, applications, and security technologies. Strong analytical, problem-solving, documentation, and communication skills. Ability to work effectively with SOC, IT Infrastructure, Network, Endpoint, and other technical teams. Preferred Qualifications Experience with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, Wazuh, Securonix, LogRhythm , or similar technologies. Experience developing SIEM use cases, correlation rules, and detection logic. Knowledge of log formats and data collection protocols such as Syslog, Windows Event Logs, JSON, CEF, and LEEF . Familiarity with query and scripting languages such as KQL, SPL, SQL, Python, or PowerShell . Experience integrating firewalls, EDR/XDR, IDS/IPS, cloud platforms, identity systems, and other security tools with SIEM. Knowledge of threat detection frameworks such as MITRE ATT&CK . Familiarity with security monitoring, incident response, and SOC operations. Relevant certifications such as Microsoft Certified: Security Operations Analyst Associate (SC-200), Splunk certifications, CompTIA CySA+, Security+, or equivalent certifications are an advantage. Core Competencies SIEM Deployment & Administration SIEM Integration & Log Management Log Source Configuration Correlation Rules & Detection Engineering SIEM Use Case Development Dashboard & Security Report Management SIEM Tuning & Optimization Log Ingestion Troubleshooting Security Monitoring Incident Response Support Technical Documentation Analytical & Problem-Solving Skills Stakeholder Coordination Work Location: In person
Наблюдалась 2026-09-21, впервые 2026-09-18, источник — Indeed.