Role Proficiency:
Provide support across SIEM or EDR technologies for global customers; ensuring the platforms are functioning as expected. Independently conduct checks and basic triage for global customers under minimal guidance of senior members of the team.
Outcomes:
Conduct Health checks for a single or multiple platform types following guidance and escalating issues observed escalating to a senior team member for review to ensure proper visibility of issues before they become incidents. Assist with service requests for platform types such as access requests as well as more targeted requests for specific modules on platform such as dashboard creation and query support. Investigation of larger issues supporting internal and external stakeholders. Provide assistance with maintenance activities to help with improving the understanding of architecture of supported platforms. Build a self awareness proficiency for supported toolsets. Generate relevant reporting as required for platforms being supported on a regular basis to help meet internal and external reporting requirements. Follow relevant in-life processes tracking any escalation pipelines and pathways required to ensure consistency of applications provided to the customer. Provide support and guidance to more junior members of the team assisting with their development.Measures of Outcomes:
Percent of adherence to processes and methodologiesa.Percent of adherence to SLAs for in life ticketing processesb.Percent of adherence to workflows and the completeness of audit trails for any activities Productivity score maintaineda.Number of issues identified early in pinpoint problems with delivering tasks or workload.b.Number of issues with effective evidence provided for escalations during triage. Number of relevant change documentation reviewed on a regular basis; ensuring processes remain relevant for the broader team. Number of relevant skill related training and development activities undertaken; evidenced by certification.Outputs Expected:
Platform Health Monitoring:
Support Service Requests and first level Incident support as well as assisting Junior Members. Proactive identification of issueswith behavioural analysis/patterns identified
with suggestions for resolutions. Conduct daily and regular occurring service tasks with minimal supervision to ensure daily operation of the platform supported.
Technical Expertise:
identify and be able to implement technical solutions to issues with queries/rules/dashboards/data feeds
Customer Focus:
Skill Examples:
Good communication skills Ability to be prepared to undertake background check/validation to ensure integrity. Aptitude in working with a/multiple SIEM or EDR technologies unsupervised. Capable in working as part of a shift Ability to share knowledge with peers and juniors Ability to work with querying data and the role of a SIEM/EDR Ability to demonstrate analytical skills working across multiple technologies and customers.Knowledge Examples:
Knowledge Examples
Good communication skills Ability to be prepared to undertake background check/validation to ensure integrity. Aptitude in working with a/multiple SIEM or EDR technologies unsupervised. Capable in working as part of a shift Ability to share knowledge with peers and juniors Ability to work with querying data and the role of a SIEM/EDR Ability to demonstrate analytical skills working across multiple technologies and customers.Additional Comments:
QRadar SIEM Engineer / Cybersecurity Expert CyberProof is a cyber security services and platform company whose mission is to help our customers react faster and smarter – and stay ahead of security threats, by creating secure digital ecosystems. CyberProof automates processes to detect and prioritize threats early and respond rapidly and decisively. CyberProof is part of the UST Global family. Some of the world’s largest enterprises trust us to create and maintain secure digital ecosystems using our comprehensive cyber security platform and mitigation services. We are looking for a QRadar SIEM Engineer in the Use Case Management team to join us and become a member of our global Security Operations Team. Main Tasks and Accountabilities: • Understand customer requirements and recommend best practices related to QRadar solution. • Offer consultative advice on security principles and best practices related to QRadar operations. • Identify, develop, and document QRadar use cases, rules, correlations, dashboards, addressing emerging threats and customer needs. • Deploy and configure QRadar platforms as per Vendor guidelines and industry Best Practices. • Assist client with technical guidance to configure end log sources in-scope to be logged to the QRadar. • Verification of data of log sources in the QRadar. • Maintain and create DSMs/parsers for required log sources. • Serve as a subject matter expert in SIEM technologies and content development. Mandatory Requirements: • Experience with QRadar SIEM platform. The person can have prior experience in other common SIEM platforms as well, but recent role needs to be with QRadar as the role is expected to work primarily in this platform. Minimum of 2 years of experience in a similar role. • Preferred SIEM vendor certification of administrator. • Hands-on Experience in AQL with writing Use Cases in QRadar. • Familiarity with different security attack vectors and means of protection. • University degree in information security or equivalent work experience. • Strong analytical and problem-solving skills. • Strong communication and collaboration skills, with the ability to work effectively in a team environment. • Ability to work independently; self-starter/self-motivated.