
Professional Services Consultant - XSIAM
- Singapore
- Permanent
- Full-time
- Collaborate with the technical lead to devise a comprehensive log ingestion strategy
- Contribute to the development of detection strategies based on industry best practices
- Articulate a step-by-step process to ensure the ingestion of high-quality log sources
- Monitor and optimize log sources for optimal performance
- Create meticulous and effective correlation rules
- Fine-tune log sources and correlation rules to enhance system efficiency
- Serve as the subject matter expert (SME) in SIEM, correlation, and log source ingestion
- Serve as a trusted advisor to end customers, offering consultative guidance and expertise in optimizing the utilization of Cortex XSIAM
- Leverage your in-depth knowledge of SIEM and SOC practices to assess customer needs, provide tailored recommendations, and assist in the formulation of effective security strategies
- Collaborate closely with customers to understand their unique challenges and objectives, translating them into actionable steps that enhance their security posture
- Identify opportunities to enhance analyst alert handling through automation
- Foster collaboration with internal and external teams to drive product adoption
- Produce technical documentation detailing SIEM aspects of the engagement
- Occasionally travel to customer meetings and workshops (up to 10% of the time)
- Exceptional written and verbal communication and presentation skills, for both internal and external interactions
- 6+ years of hands-on experience in deploying and integrating SIEM solutions within enterprise to large enterprise-level environments
- Proficiency in coordinating and conducting event collection, log management, event management, compliance automation, and identity monitoring using SIEM platforms
- Ability to conceive and develop detection use cases in SIEM systems to enable effective alerting
- Proficiency in implementing and integrating automation solutions to enhance SOC efficiency, thereby minimizing MTTR and optimizing operational effectiveness
- ​​Demonstrated expertise in threat intelligence management, including the ability to analyze and leverage threat intelligence feeds to proactively identify, assess, and mitigate potential security threats within the organization's environment
- Familiarity with a range of Endpoint security solutions such as anti malware, EDR, XDR
- Knowledge of generating reports on SIEM status, including metrics like logging source count, log collection rate, and other performance indicators
- Proven experience in providing consultative services to end customers within the realm of cybersecurity, particularly in SIEM and SOC domains
- Demonstrated ability to comprehend customer requirements, analyze complex security environments, and deliver strategic recommendations that align with their goals
- Proficient in comprehending and creating technical design documentation
- Proven track record in effectively leading technical teams, managing resources, and overseeing projects within a dynamic cybersecurity environment, ensuring alignment with strategic objectives, timely delivery of milestones, and efficient utilization of resources
- Skilled in facilitating collaboration among diverse stakeholders, including technical teams, management, and external partners, to drive informed decision-making processes that align with organizational objectives and foster innovation in cybersecurity strategies
- Relevant bachelor's degree or equivalent military experience or industry-recognized qualifications (CISSP, GIAC, SIEM Vendor Qualification, etc.), is a plus or equivalent military experience required