English Language Indonsian Language
Ensign InfoSecurity (Cyber Security) Pte Ltd
https://www.ensigninfosecurity.com/

SIEM Engineer

Looking for
S1

Ensign InfoSecurity is the largest pure-play end-to-end cybersecurity service provider in Asia. Headquartered in Singapore, Ensign offers bespoke solutions and services to address their clients’ cybersecurity needs. Their core competencies are in the provision of cybersecurity advisory and assurance services, architecture design and systems integration services, and managed security services for advanced threat detection, threat hunting, and incident response. Underpinning these competencies is in-house research and development in cybersecurity. Ensign has two decades of proven track record as a trusted and relevant service provider, serving clients from the public and private sectors in the Asia Pacific region.

  • Communicate effectively to both technical and non-technical audiences on log source onboarding and use case related topics.
  • Onboard log sources to SIEM as per the contracted service levels by coordinating with client and vendor contacts.
  • Parse the logs/events of onboarded log sources, verify the accuracy and the completeness of the field mapping.
  • Develop new collectors on SIEM to support log source onboarding activities
  • Integrate SIEM with other tools/applications/systems to enrich the alerts/events
  • Develop/tune SIEM rules and use-cases to ensure that threats to the environment are detected as per the client requirement and industry best practices.
  • develop custom threat detection rules based on use cases adhering to the set service level agreements
  • Actively participate in continuous improvement program to increase SOC detection capabilities and efficiency
  • Maintain the Use Case Library and responsible for lifecycle management activities of the Use Case Library
  • Troubleshoot and resolve SIEM related issues in collaboration with application owners and SIEM vendor
  • Monitor SIEM performance to proactively identify potential issues impacting the SOC services
  • Actively participate in SOC Threat Hunt program
  • Recommend security monitoring tools optimizations based on threat hunting discoveries
  • Assist in the SOC’s daily operations and provide support to incident response
  • Manage relationships with our customers’ in-house operations teams and frequently interact with client management
  • Work closely with the SOC Director to manage ongoing service delivery and onboarding of team members within the SOC

 

  • Bachelors or college degree of computer science, computer engineering or other relevant degrees
  • Hands-on experience and knowledge in any of the following SIEMs Splunk, QRadar, Devo
  • Knowledge and hands-on experience with SOAR is an advantage
  • Knowledge and hands on experience on cloud operations is an advantage
  • At least 4 years of SOC operations experience
  • At least 1 year experience in SOC service transition and SIEM Management
  • Relevant industry certifications or relevant technology vendor certifications
  • Ability to perform and grow in a continuous improvement focused environment
  • Strong knowledge of Cyber Security forensics, project management, change management, technology implementation and risk analysis strategy
  • Proficient at professional communication and documentation of processes and procedures

For interested applicants, please do send your resume in word.doc/PDF an email to Ms Magdalene Ho- magdalene_ho@ensigninfosecurity.com

Shortlisted applicants will be notified.

Thank you!

Only shortlisted candidates will be contacted.
Jakarta
31 December 2022
2
3
Logo ITB Logo ICC ITB

GKU Timur ITB Building

Jln. Ganesha 10, Bandung 40132 Indonesia

Customer Service

Phone & Fax: (+62-22) 2509177

career@itb.ac.id

Employer Service

Phone & Fax: (+62-22) 2509162

Email : employerservices@itb.ac.id

© Direktorat Kemahasiswaan Institut Teknologi Bandung