تنفيذ وإدارة SIEM: نشر وإعداد وصيانة منصات SIEM (مثل Splunk وQRadar وArcSight وLogRhythm).
دمج مصادر السجلات: دمج مصادر السجلات المتنوعة، وتطوير أدوات تحليل مخصصة، وضبط القواعد للكشف الدقيق.
قواعد الكشف: إنشاء وتجربة وتحسين قواعد الكشف، ومنطق الربط، والتنبيهات بناءً على نماذج التهديدات ومخاطر الأعمال.
التعاون: العمل عن كثب مع فرق مركز عمليات الأمن (SOC) والاستجابة للحوادث لتعزيز سير عمل التحقيقات.
الأتمتة والبرمجة النصية: استخدام Python أو PowerShell أو لغات البرمجة النصية المشابهة للأتمتة، وإنشاء لوحات التحكم، والتقارير المخصصة.
رؤية التهديدات: تحسين تغطية المراقبة وضمان الكشف الاستباقي للتهديدات المتقدمة.
التوثيق: الحفاظ على التوثيق الفني، وأدلة إجراءات الكشف، وتقارير الامتثال.
درجة البكالوريوس في علوم الحاسوب، أو تكنولوجيا المعلومات، أو تخصص ذات صلة.
خبرة لا تقل عن 8+ سنوات في هندسة SIEM، أو المراقبة الأمنية، أو بيئات SOC.
معرفة قوية بمنصات SIEM وإدارة السجلات.
شهادة Splunk Certified Architect.
شهادة GCIA (محلل التسلل المعتمد من GIAC).
شهادات SIEM/أمنية مكافئة.
SIEM Implementation & Management: Deploy, configure, and maintain SIEM platforms (Splunk, QRadar, ArcSight, LogRhythm).
Log Source Integration: Integrate diverse log sources, develop custom parsers, and tune rules for accurate detection.
Detection Rules: Create, test, and optimize detection rules, correlation logic, and alerts based on threat models and business risks.
Collaboration: Work closely with SOC and Incident Response teams to enhance investigative workflows.
Automation & Scripting: Use Python, PowerShell, or similar scripting languages for automation, dashboard creation, and custom reporting.
Threat Visibility: Improve monitoring coverage and ensure proactive detection of advanced threats.
Documentation: Maintain technical documentation, detection playbooks, and compliance reports.
Bachelor’s degree in Computer Science, Information Technology, or related discipline.
Minimum 8+ years of experience in SIEM engineering, security monitoring, or SOC environments.
Strong knowledge of SIEM platforms and log management.
Splunk Certified Architect.
GCIA (GIAC Certified Intrusion Analyst).
Equivalent SIEM/security certifications.
Tanqeeb.com هو محرك البحث عن الوظائف الأول فى الوطن العربى الذى يجمع لك الوظائف المناسبة من مختلف مواقع التوظيف الآخرى فى مكان واحد !
Madre Integrated Engineering is privileged to partner Keppel Seghers, a leading provider of comprehensive environmental solutions in the development...