SIEM Administrator – Global Brand – Enterprise & Fast pace – Leeds REF 884

·
Full time
Location: Wakefield
·
Job offered by: Interface Recruitment UK
·
Category: IT & Technology
Salary:

£NEG

Education Requirements:

None, but degree preferred or commercial exposure

Experience Requirements:

Expert

Industry:

Technology

Location:

Leeds

Qualifications:

Any MS or Security Relevant Quals

Work Hours:

The role will initially require 3 days in the office per week but normal working practices will apply post Covid.

Principal Duties, Responsibilities & Accountabilities: The role of the SIEM Administrator will be to work closely with our security team to develop and deliver solutions to gain visibility of security events within our environment. Build new or develop existing event correlation, reporting and remediation capabilities based on advanced monitoring use cases, external threat intelligence, and known traffic patterns. Regularly review Audit Logs to recognize both normal and abnormal activity.

Responsibilities:

Develop and enhance security policies, processes, procedures and technical controls to strengthen security capabilities and resilience to cyber threats.

Take a proactive role in identifying security risks, mitigations and opportunities to strengthen resilience to cyber-attacks and security incidents.

Participate in the design and implementation of systems and applications to ensure that proposed solutions comply with the company’s IT Security policies.

Assist with security incident management and response activities.

Interact with the IT team to provide and share technical issue resolution knowledge and deployment/adoption processes best practices.

Provide analysis of information security risk and issues of non-compliance.

Manage, maintain, optimize and tune the Microsoft Sentinel SIEM solution, ensuring all key systems send activity information to the SIEM solution and that the solution recognizes and differentiates between both normal and abnormal system activities.

Investigate unusual behavior highlighted by SIEM, reporting potential threats or malicious activity and support security incident response efforts as required.

Develop dashboards and reports for monitoring of real-time log data, that clearly report on and highlight critical events.

Provide internal training, support and knowledge transfer to other Information Security team members, to enable efficient management of SIEM related processes.

Skills:

Experience and good understanding of Microsoft technologies including: Azure Active Directory, Windows Server, and M365.

An in-depth knowledge of the Microsoft Sentinel SIEM solution and configuration best practice and use.

Use of advanced security assessment tools.

Basic understanding of firewall and intrusion detection system administration.

Basic understanding of TCP/IP.

Ability to tune and harden various operating systems.

Ability to use security systems to correlate and respond to security alerts and events.

Detailed Knowledge of:

SIEM administration, log investigation, analysis and reporting.

Common exploitation tools, tactics and procedures.

Persistent attacks, detection methods and how malicious software persists on compromised systems. Security incident response procedures and best practices.

We believe this is an excellent opportunity for candidates who have a strong understanding of IT security with experience of working in a fast-paced environment.

#J-18808-Ljbffr

Recent Jobs

London (On site) · Full time

Are you a smart, driven professional who takes pride in making a difference in local communities? Turner & Townsend’s Real Estate division is experiencing significant growth and we’re looking for an experienced industry professional with health project experience to join our high-performing and collaborative Project Management team. Why Join Us? Impactful Work: Contribute to social [...]Read More... from Assistant Project Manager – Healthcare See details

Chasetown (On site) · Full time

My client, Autosmart International are a manufacturing success story! Site Operations Manager – leading fast-paced manufacturing and warehousing About Our Client Autosmart International is a manufacturing success story, leading the field in vehicle cleaning products. We are the No.1 choice of automotive trade customers across the UK. We have doubled in size in the last [...]Read More... from Site Operations Manager See details

London (On site) · Full time

CSS are looking for an experienced duty officer to join our client’s team who are a local council responsible for all areas within the Tendering district. Working hours: All shifts are 8 hours long with various start times available: Monday to Friday – start times between 6AM – 3PM Saturday & Sunday – 6AM – [...]Read More... from Duty Officer See details