Senior Information Security Analyst – SIEM Engineer
McKesson View all jobs
- Cork
- €67,500-112,500 per year
- Permanent
- Full-time
- Design, implement, and support SIEM, SOAR solutions in a highly available, redundant, distributed computing environment for a global organization.
- Perform SIEM component configuration and troubleshooting across a variety of platforms both on-premises and in public clouds.
- Integrate data sources into SIEM from on-premises and cloud deployed devices and applications.
- Develop SIEM content and support other content developers using your expert knowledge.
- Monitor internal data sources to identify and resolve potential performance issues
- Automate frequently used process and workflows with SOAR related technologies.
- Maintain technical documentation and design documents related to system configurations, processes, and operational procedures.
- Requires 3-5 years of professional work experience
- BS/BA degree or equivalent experience.
- 1 - 3 years of IT experience in a technical position as an engineer, architect or system administrator within a large-scale mission critical enterprise environment.
- 2+ years of direct hands-on experience administration or support of SIEM solutions.
- Experience deploying, configuring and maintaining a SIEM at scale.
- Experience writing complex queries for dashboards, reports and apps.
- Experience automating repetitive and error prone operations with scripting languages.
- Working knowledge of enterprise architecture, infrastructure components and design
- Experience working in an Agile environment using Scrum or Kanban methods.
- Team oriented with great communication and interpersonal skills.
- Ability to work on all aspects of large-scale projects including planning, prioritizing, executing, delivering, and sustaining.
- Experience creating security detections for Palo Alto XSIAM or other SIEMs
- Proficiency with Linux platforms, including shell scripting. Red Hat preferred.
- Experience with cloud platforms such as Microsoft Azure and GCP
- Experience with additional logging/data broker ETL technologies such Kafka or Cribl
- Certified Splunk Power User or Administrator, CISSP certification preferred
- Working knowledge of machine learning and UEBA concepts