أبلاي إيدج ابدأ البحث عن عمل

SIEM Admin

Innovative Solutions SA · Riyadh, Riyadh, Saudi Arabia

قدّم وتابع مع أبلاي إيدج
Company OverviewInnovative Solutions (IS) is a leading Cybersecurity company established in 2003, with its headquarters in Riyadh and additional offices in Al Khobar, Jeddah, Dubai, and Abu Dhabi. We specialize in delivering Comprehensive Cybersecurity Solutions and Services encompassing Advisory Services, Technical Assurance, Solution Deployment, Professional Services, and Managed Security Services.Our mission is "Delivering secure and intelligent digital services that empower organizations"About The RoleA skilled SIEM Administrator to design, deploy, and maintain our (SIEM) platform. In this role, you will be the backbone of our log management and threat detection infrastructure. You will work closely with various business units to onboard log sources, build custom rules, and ensure our security operations tools run seamlessly to protect enterprise assets.Key ResponsibilitiesPlatform Architecture: Design, deploy, patch, and upgrade the SIEM platform and associated agentsLog Onboarding & Integration: Collaborate with business units to map network hierarchies, establish building blocks, and classify log sourcesCustom Development: Build custom API connectors and parsers for non-standard log sources lacking out-of-the-box vendor supportThreat Detection & Modeling: Develop robust use cases, create custom SIEM detection rules, and implement MITRE ATT&CK modelingOperations & Troubleshooting: Troubleshoot day-to-day issues across log sources, collectors, agents, and other SOC toolsData Governance: Manage data archiving, backups, retention, and purging configurations to align with compliance standards, restoring data as neededChange & Audit Management: Raise and manage change tickets for administrative tasks (e.g., patch upgrades, log onboarding) and prepare assessment reports for existing platformsSystem Administration: Leverage foundational Windows and Unix administration skills to support infrastructure healthRequirementsEducation: Bachelor's degree in a related field or equivalent demonstrated professional experienceCore Technical Knowledge: Strong understanding of cybersecurity and IT disciplines, including networking, operating systems, authentication protocols, enterprise architecture, and incident responseEnterprise Technology: Familiarity with common enterprise tools and logging capabilities (firewalls, Active Directory, EDR/antivirus, IDS/IPS, proxies, and cloud platforms). SOAR Knowledge ‘preferSIEM Expertise: Understanding of log aggregation or correlation technologies such as Splunk, QRadar, LogRhythm, Microsoft Sentinel, or Palo Alto XSIAMSecurity Principles: Deep knowledge of risk management processes, CIA triad principles, cryptography, IAM, access controls, and network security methodologiesHardening: Proven experience in system administration, network, and OS hardening techniques