We are seeking a Cyber Security Analyst with a solid understanding of SIEM systems, preferably Trellix, and experience in maintaining and optimizing logging infrastructure for security monitoring purposes. The candidate will be responsible for ensuring that logs are collected, processed, and stored correctly, ensuring compliance with regulatory requirements and internal security protocols. This role requires collaboration with IT and security teams to manage log data and improve SIEM functionality.
Principal Accountabilities:
Serve as the technical expert for an on-premise Security Information and Event Management (SIEM) system.
Update SIEM software to current versions, monitor log data, ensure data integrity, and collaborate with cross-functional teams to improve log quality.
Execute response activities, including incident response, incident management, remediation/mitigation, and forensic analysis.
Identify and address security weaknesses, such as vulnerabilities and insecure configurations.
Facilitate internal skills development for information security personnel on security monitoring and incident response.
Update SIEM software to the latest versions for optimal performance and security.
Monitor SIEM data to identify, troubleshoot, and resolve issues related to log ingestion, parsing, and storage.
Work closely with IT, security, and other operational teams to ensure proper log ingestion and processing within the SIEM.
Identify areas for log data cleanup and optimization to improve system efficiency.
Maintain security monitoring configurations and ensure logs comply with regulatory standards for nuclear power facilities.
Follow proper documentation and change management procedures for SIEM updates or modifications.
Continuously evaluate the SIEM setup for enhancements to meet evolving security requirements.
Required Education and Experience:
Bachelor's degree in Computer Science, Information Security, or a related field.
Minimum of 7 years of experience in cybersecurity or IT, with at least 3 years focused on SIEM administration and management.
Preferred Education and Experience:
Proven experience with Trellix SIEM software (or similar SIEM platforms).
Required Abilities and Skills:
Strong knowledge of security event logging standards, data parsing, and event correlation.
7 years of relevant experience.
Desired Abilities and Skills:
Familiarity with compliance requirements and regulations in critical infrastructure environments, preferably in the nuclear or energy sector.
Contact: kgregor@judge.com
This job and many more are available through The Judge Group. Find us on the web at www.judge.com