Join to apply for the SIEM Engineer role at Opplæringskontoret for Offshore fag
3 weeks ago Be among the first 25 applicants
Key Accountabilities:
- Build and deploy innovative technical solutions to advance the security capability of the Cyber Security Operations function.
- Manage and oversee the configuration of various security tools to enable key stakeholders, such as CSOC and Threat Hunting and Detection Engineering (THaDE).
- Collaborate with application administrators across the business to onboard data sources into the SIEM data lake.
- Optimise forensic telemetry collection mechanisms to ensure accurate and efficient parsing and ingestion to the SIEM.
- Build resilient forensic telemetry collection technologies to support 24/7/365 monitoring of NESO and its control systems by CSO.
- Spearhead process improvement and curate, update and develop an internal cyber engineering knowledgebase – bonus if already skilled in Mermaid or Markdown.
About You:
We’re forging the path, and we know we can’t do it alone. That’s why we need visionary minds like yours to join us on this transformative journey. In this case, we’re looking for someone who:
- Is passionate about security and building secure infrastructure and secure foundations.
- Is curious. We often deal with bespoke or less common data sources at NESO, and a willingness and enthusiasm to take on the challenge of making sense of these data sources is a must.
- Has strong analytical and problem-solving skills and ability to handle complex and dynamic situations.
- Has a keen awareness of current and emerging cyber threats, trends, and best practices.
- Has proven experience working with SIEM platforms and related tooling.
- Has a strong understanding of SIEM concepts and best practices.
- Is familiar with SIEM telemetry onboarding processes and techniques.
- Is knowledgeable about various data source formats and protocols (e.g., syslog, JSON, REST API).
- Has experience in troubleshooting and resolving data quality or ingestion issues.
- Has previously worked closely with security tooling such as EDR, Deception Tech, Malware Sandboxes, Vulnerability Management Tooling, etc.
- Is familiar with security incident response and investigation processes.
- Has excellent problem-solving and analytical skills.
- Has strong communication and collaboration abilities.
- May have relevant certifications (e.g. GIAC), but this is not required.
Seniority Level: Entry level
Employment Type: Contract
Job Function: Information Technology
Industries: Computer and Network Security
#J-18808-Ljbffr
Contact Detail:
Oof Recruiting Team