Description
The role is responsible for collecting, normalizing, analyzing, and exploiting security logs from multiple sources, ingesting them into SIEM platforms, and using the data for threat detection, incident investigation, and forensic analysis. Responsibilities include building log pipelines, maintaining data quality, creating dashboards and alerts, hunting threats, supporting incident response, documenting findings, and producing reports. The position requires at least three years of experience in SIEM operations, log analysis, or security monitoring, along with hands-on experience with Splunk, CrowdStrike, and other log platforms, plus knowledge of scripting, YARA rules, regular expressions, and security tools.
