Search by job, company or skills

Team Lead / Service Manager SIEM

Early Applicant
  • Posted 5 days ago
  • Be among the first 10 applicants

Job Description

Responsibilities

  • Perform analysis and corrective action for alerts that have not been reported by SOC within agreed SLA
  • Review and submit the Daily Operations Status report to SOC Delivery Manager
  • Review the SOC Knowledge base and enhance as required
  • Review the Monthly MIS report and Alert report prepared by Threat Analyst
  • Review of new reports/alerts added
  • Level 2 escalation point for all alerts detection and reporting
  • Level 1 Escalation regarding misses in analysis or threat anomalies not informed to the customer by TA team
  • Review analysis or reports done by TA team before sending it to the client
  • Review and upload the SOC shift handover report sheet
  • Support Threat Analyst in retrieving data from archive for alert analysis and support Threat Hunters in investigations and analysis
  • Provide approval for addition/modification/deletion of scheduled report, threat cases
  • Add/Modify rules in SIEM console based on approved change requests
  • Provide support in preparing SOC Internal audit reports and ensure that SOC takes action on findings
  • Identify, document and share the alert scenario
  • Participate in the alert drill and document the learning
  • Collect KPI data for defined parameters and submit to Delivery and Quality Team
  • Track new log source addition, check for SIEM console support and License verification
  • Troubleshooting log source & track log stoppage
  • Analyze daily backup failure and implement corrections
  • Perform recovery of data or configuration as needed
  • Define and configure health monitoring parameters and their thresholds
  • Review the model output, making sure required logs are available for TH team
  • Review Active Discovery models, suggestion for new models
  • Work Data Scientists and Development team for the development new models and fine tuning of existing ones
  • Connect with customer in providing updates on Threat Hunting and Threat Analysis activity, collect customer feedback.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 151415277

Similar Jobs

Malaysia, Cyberjaya, Selangor

Skills:

SiemThreat Analysis