Configure, deploy, and maintain the organization's SIEM platform to ensure optimal performance and functionality.
Develop and customize SIEM rules, filters, and alerts to meet specific security monitoring and compliance requirements.
Collaborate with IT teams to onboard new data sources and integrate logs into the SIEM platform for comprehensive threat detection.
Generate and present regular and ad-hoc reports on SIEM performance, security incidents, and compliance status to stakeholders and management.
Stay updated on emerging cybersecurity threats, vulnerabilities, and industry best practices to enhance SIEM capabilities and proactive defense strategies.
Participate in incident response activities, including incident simulations, tabletop exercises, and post-incident reviews.
Provide guidance and training to junior team members and stakeholders on SIEM platform usage, capabilities, and best practices.