Logo
Entelligence

SIEM/SOAR Engineer

Entelligence, Charlotte, North Carolina, United States, 28245

Save Job

Entelligence is seeking an engineer to support our clients. The successful candidate must be able to work in a cross‑functional environment and interact with representatives from Entelligence, the client, and the end‑user.

As an Engineer for Cortex XSIAM, you will assist with log migration and detection strategy for our customers. You will work closely with the technical lead to ensure all relevant log sources are onboarded and ingested into XSIAM in accordance with industry best practices and customer requirements. You will then determine a suitable detection strategy, helping to protect customers from threats by designing and implementing correlation rules.

Responsibilities

Work with technical lead to develop log ingestion strategy

Contribute to detection strategy based on industry best practices

Detail step‑by‑step process to ingest high‑quality log sources

Perform log source monitoring and optimization

Create high‑quality correlation rules

Tune log sources and correlation rules

Be an SME for SIEM, Correlation and Log Source Ingestion

Recognize opportunities where automation can improve analyst alert handling

Collaborate with internal and external teams to ensure product adoption

Create technical documentation detailing SIEM aspects of the engagement

Travel to customer meetings and workshops as needed (10%)

Job Requirements

Strong communication (written and verbal) and presentation skills, both internally and externally

Fluent English is a requirement – any other language is a plus

3+ years of deploying and integrating SIEM at enterprise or large enterprise‑level

Coordinating and conducting event collection, log management, event management, compliance automation, and identity monitoring activities using SIEM platforms

Ability to create and develop correlation and detection rules within a SIEM to support alerting capabilities

Experience working with and deploying a variety of SIEM technologies (i.e., Splunk, IBM QRadar)

Proven ability to offer suggestions on detection strategy based on customer requirements

Ability to understand logs, locate and understand third‑party documentation where needed

Familiarity with reports on the status of the SIEM to include metrics such as number of logging sources, log collection rate, and other performance metrics

Knowledge of Security Analysis & Response a plus, including both endpoint, network & cloud‑based environments

3 years of experience with Security Operations Center tooling and processes

Relevant bachelor’s degree or industry‑recognized qualifications (CISSP, GIAC, SIEM Vendor Qualification, etc.)

Ability to read and understand technical design documentation

Ability to create technical design documentation

Benefits

Competitive base salary

Medical, dental, vision, and life insurance

Vacation, sick time, and paid holidays

Matching 401(k) program

Since 1997, Entelligence has provided mission‑critical project delivery capacity for uninterrupted growth and long‑term market leadership to the industry’s biggest enterprise IT brands. Our commitment to close working partnerships and a proven approach for sustainable success is why Entelligence is always ready to help the world’s technology leaders quickly deliver their most advanced IT solutions to their most important customers.

#J-18808-Ljbffr