Roles and Responsibilities
- Manage day-to-day operations and administration of enterprise security platforms, including SIEM, SOAR, and Data Security platforms.
- Monitor platform health, service availability, performance, and capacity utilization.
- Perform proactive platform maintenance, system tuning, and health checks.
- Support platform deployment, upgrades, migrations, and patch management activities.
- Design, implement, and maintain integrations between security platforms and enterprise systems.
- Develop automation playbook to automate routine security tasks such as threat intelligence lookups, alert enrichment, incident response processes, and vulnerability scanning.
- Support onboarding of new data sources, use cases, and security technologies.
- Create and maintain technical documentation, operational manual, and standard operating procedure.
- Troubleshoot and resolve platform, infrastructure, integration, and data ingestion issues.
- Coordinate with internal teams, vendors, and external partners to resolve complex technical problems.
- Continuously track, monitor, and follow up on Incidents, Changes, and Problems throughout their lifecycle.
- Conduct root cause analysis (RCA) and implement corrective and preventive actions.
- Participate in major incident management activities and service restoration efforts.
- Partner with Internal Audit teams to support audit activities.
- Provide audit evidence, operational documentation, system records, and technical explanations when required.
- Support remediation activities arising from audit findings and compliance assessments.
- Ensure security platforms operate in accordance with organizational policies, standards, and regulatory requirements.
- Manage and fulfill user requests within agreed service levels.
- Provide technical support and consultation to BU security, infrastructure, and application teams.
- Collaborate with BU stakeholders on platform enhancements and operational improvements.
- Participate in project delivery and platform transformation initiatives.
Requirements
- At least 2-3 years of experience in Information Security, Security Engineering, Security Platform Operations, System Administration, or Infrastructure Operations.
- Experience supporting enterprise-scale security platforms in production environments.
- Experience working within Incident, Problem, and Change Management processes.
- Experience supporting audit, compliance, or regulatory requirements is preferred.
- Hands-on experience with SIEM technologies, in-depth knowledge of Google SecOps (Chronicle) is highly preferred.
- Experience with SOAR technologies and security automation workflows, e.g. Chronicle, Splunk SOAR.
- Understanding of security monitoring architecture and log management concepts.
- Strong knowledge of Linux and Windows administration.
- Experience with Microsoft Azure services and cloud operations.
- Hands-on Kubernetes (K8S) administration and troubleshooting experience.
- Understanding of networking fundamentals, including DNS, TCP/IP, HTTP/HTTPS, Syslog, and security-related protocols.
- Experience in Python and/or PowerShell scripting.
- Experience with REST APIs based system integrations.
- Experience automating operational tasks and platform management activities.
- Experience leveraging AI-powered tools (e.g., Microsoft Copilot) to improve operational efficiency, automate repetitive tasks, accelerate troubleshooting, enhance documentation quality, and support platform engineering activities.
- Azure Administrator Operation
- Kubernetes Platforms