21 Aug
|
Ibm
|
New South Wales
21 Aug
Ibm
New South Wales
Job Description
Introduction
n
Stay up to date with the latest SIEM/SOAR technologies, industry trends, and best practices.
n
Your Role And Responsibilities
n
We are seeking a skilled and experienced Security Consultant focused on SIEM, Security Automation and Response (SOAR), and overall SOC technology capabilities to join our team. The ideal candidate will possess a deep understanding of SIEM/SOAR technologies and related solutions, with expertise in designing, implementing, and optimising security automation and orchestration strategies for our clients.
n
The SIEM/SOAR Consultant will work closely with clients to understand their security needs, architect tailored security tool plans and deployments, and ensure successful project delivery.
n
Responsibilities
n
Client Engagement and Relationship Management:
n
Engage with clients to understand their security requirements, pain points, and business objectives.
n
Develop and maintain strong client relationships, ensuring customer satisfaction and driving repeat business.
n
SIEM/SOAR Architecture and Design:
n
Design and architect SOAR solutions based on clients' unique security needs and infrastructure.
n
Suggest and evaluate different SIEM/SOAR technologies, comparing and contrasting solutions for clients.
n
Create detailed technical documentation, including architecture diagrams, implementation plans, and configuration guides.
n
Deployment and Configuration:
n
Lead the deployment of SOC platforms, ensuring adherence to best practices and security standards.
n
Correctly size tools to vendor specifications to meet clients' needs, including specific vendor add-ons and their optimisation to meet customer demands.
n
Design the integration of SIEM/SOAR platforms with other security tools, such as firewalls,
intrusion detection systems, and endpoint protection platforms.
n
Assist with hands-on coding of these tools when required.
n
Playbook and Workflow Development:
n
Develop and maintain playbooks, workflows, and automation scripts using SIEM/SOAR tools.
n
Collaborate with clients to refine and enhance playbooks based on their specific use cases and requirements.
n
Incident Response and Orchestration:
n
Assist clients in developing and refining incident response strategies using SIEM/SOAR automation and orchestration capabilities.
n
Support clients in managing and coordinating security incidents, leveraging SIEM/SOAR investigation and orchestration features.
n
Training and Knowledge Transfer:
n
Deliver training sessions and workshops to clients' security teams, covering tool features, best practices, and customization.
n
Facilitate knowledge transfer and capacity building within client organisations.
n
Project Management:
n
Manage multiple concurrent projects, ensuring timely delivery within budget and scope.
n
Collaborate with internal teams, including pre-sales, professional services, and support, to ensure seamless project execution.
n
Identify project gaps and address them as required for successful completion
n
Continuous Improvement and Innovation:
n
Stay up to date with the latest SIEM/SOAR technologies, industry trends, and best practices.
n
Contribute to the continuous improvement of our SOAR consulting services and methodologies.
n
Required Technical And Professional Expertise
n
Education and Certifications:
n
Bachelor's degree in Computer Science, Information Technology, or a related field.
n
Relevant SOAR certifications (e.g., IBM Resilient, Demisto(XSOAR), XSIAM or vendor-specific certifications) highly desirable.
n
Relevant SIEM certifications (e.g., administrator or architect level) in SIEM vendor technologies.
n
Relevant Security Certification (e.g., GIAC, CISSP) highly desirable.
n
Experience:
n
Minimum of 3 years' experience in SOC tools consulting, with additional experience as a user, administrator, or operator.
n
Proven track record of designing, implementing, and optimising SOAR solutions.
n
Technical Skills:
n
Extensive knowledge of SIEM/SOAR technologies and platforms, such as IBM Qradar, IBM Resilient, Splunk/Phantom or Demisto (Palo Alto Cortex XSOAR).
n
Proficiency in automation tools and scripting languages (e.g. Python, PowerShell, Bash).
n
Strong understanding of security orchestration, automation, and response (SOAR) concepts and best practices.
n
Familiarity with other security solutions, such as incident response platforms, threat intelligence platforms, and Security Information and Event Management (SIEM) systems.
n
Preferred Technical And Professional Experience
n
Soft Skills:
n
Excellent communication and presentation skills.
n
Strong problem-solving and analytical abilities.
n
Effective time management and project management skills.
n
Ability to work independently and collaboratively in a fast-paced workplace.
#J-*****-Ljbffr
📌 Siem/Soar Consultant - Architect (New South Wales)
🏢 Ibm
📍 New South Wales