XSIAM Automation Consultant

Entelligence LLC
United States
20 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

ARM Architecture Cloud Computing Software Design Documents Security Information and Event Management Systems Integration Data Logging QRadar Splunk

Job description

Entelligence is seeking an Engineer to support our Professional Services clients. The successful candidate must be able to work in a cross-functional environment and interact with representatives from Entelligence and the end-user. As an Engineer for Cortex XSIAM, you will be responsible for assisting with the log migration and detection strategy of our customers. You will work closely with the technical lead to ensure that all of the relevant log sources are onboarded and ingested into XSIAM in accordance with industry best practices and customer requirements. You will then work to determine a suitable detection strategy, helping to protect customers from threats, by designing and implementing correlation rules., * Work with technical lead to develop log ingestion strategy

  • Contribute to detection strategy based on industry best practices
  • Detail step by step process to ingest high quality log sources
  • Perform log source monitoring and optimization
  • Create high quality correlation rules
  • Tune log sources and correlation rules
  • Be an SME for SIEM, Correlation and Log Source Ingestion
  • Recognize opportunities where automation can improve analyst alert handling
  • Collaborate with internal and external teams to ensure product adoption
  • Create technical documentation detailing SIEM aspects of the engagement
  • Travel to customer meetings and workshops as needed (10%)

Requirements

  • Strong communication (written and verbal) and presentation skills, both internally and externally
  • Fluent English is a requirement - Any other language is a plus
  • 3+ years of deploying and integrating (SIEM) to enterprise to large enterprise-level
  • Coordinating and conducting event collection, log management, event management, compliance automation, and identity monitoring activities using (SIEM) platforms
  • The ability to create and develop correlation and detection rules, within a (SIEM) to support alerting capabilities
  • Experience working with and deploying a variety of SIEM technologies (i.e Splunk, IBM QRadar)
  • A proven ability to offer suggestions on detection strategy based on customer requirements
  • Ability to understand logs, locating and understanding 3rd party documentation where needed
  • Familiarity with reports on the status of the SIEM to include metrics on items such as number of logging sources - log collection rate, and other performance metrics
  • Knowledge of Security Analysis & Response a plus, including both endpoint, network & cloud based environments
  • 3 years experience with Security Operation Centers tooling and processes
  • Relevant bachelor’s degree or industry recognized qualifications (CISSP, GIAC, SIEM Vendor Qualification etc)* Ability to read and understand technical design documentation
  • Ability to create technical design documentation

Benefits & conditions

  • Competitive base salary
  • Medical, dental, vision and life insurance
  • Vacation, sick time and paid holidays
  • Matching 401(k) program

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

1:34 min

Transitioning from traditional software development to artificial intelligence consulting

Patrick Schnell Patrick Schnell · Coffee With Developers

Videos

See all

Related articles

See all