Senior SIEM Engineer

Malomatia — Qatar · Posted ~1 week ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

Job Description We are seeking a Senior SIEM Engineer responsible for designing, implementing, and managing SIEM solutions to enhance security monitoring, threat detection, and incident response capabilities. The ideal candidate will have strong expertise in SIEM platforms such as Splunk, Microsoft Sentinel, or similar technologies, with experience in security integrations, log management, detection engineering, and SOC operations. The role will focus on optimizing SIEM capabilities, supporting security improvements, and collaborating with stakeholders to strengthen overall security posture. Responsibilities Designing, reviewing, implementing, testing, maintaining, and troubleshooting SIEM deployments and infrastructures.Responsible for managing arrangements of dependencies and pre-requisites for SIEM projects e.g., connectivity, storage, licenses, and other equipment).Responsible for implementing changes to the SIEM infrastructure (including patches, updates, and upgrades) and performing SIEM Health Checks; and for creating technically relevant detailed reports to track solution effectiveness and performance.Manage SIEM Appliance or Virtual Appliance (including OS and SIEM software).Configure backups, verify custom reports, manage log source groups, and validate log sources.Manage SIEM user accounts (create, delete, modify, etc.).Add /Remove log sources. Troubleshoot issues with log sources or systems with system owners and vendors, and report system defects and product enhancement / feature requests with vendors as needed.Be responsible for development of integrations, connectors, and parsers for new event sourcesImplementing security monitoring rules in a SIEM tooling, according to the business needsAssist with fully optimizing the SIEM system capabilities and identifying opportunities for automation to improve SIEM effectiveness and efficiency.Create rules and reports for compliance and audit requirements and create and manage Watch Lists for current threats.Create engineering and security documentation for internal and external needs including high level and low-level design of SIEM infrastructure, as-built documentation and documentation for custom connectors/parsers and integrations.Assist with designing and documenting work processes within the SOC.Responsible for mentoring and training of Junior SIEM Engineers.Perform other duties as assigned. Qualifications Total Experience: A minimum of 5-years in Security Engineering with at least 3-year experience managing SIEM solutions Required Skills Proven experience of designing and implementing SIEM solutionsProven experience in integrating security tools such as AV, AAA, Firewall, DLP, IDS/IPS into SIEM solutionProven experience of applying SIEM monitoring with cloud systems (e.g., AWS CloudTrail, AWS GuardDuty, AWS VPC Flow Logs, Azure Activity Log, Azure AD/Entra ID Sign-in Logs, Microsoft Defender for Cloud, GCP Cloud Audit Logs, GCP VPC Flow Logs, OCI Audit Logs, OCI Cloud Guard)Proven experience of SIEM technologies (e.g., Splunk, Microsoft Sentinel, Google SecOps, etc.)Demonstrated understanding of Information Security regulations, frameworks, requirements and how to map a client’s security needs to a SIEM solution required.Solid understanding of Information Security and Networking required.Proven experience of scripting/query languages relevant to SIEM data onboarding (e.g., Python, Regex, SPL, KQL)Outstanding time management and organizational skills required.Ability to work On-Call (nights or weekends) as required.Proven capability to learn and deliver to a high standard within deadlines.Strong organizational skills and an ability prioritize tasks from multiple stakeholders.Excellent written and verbal communication skills required.Ability to relay complex technical subject matters to non-technical stakeholders.Demonstrable analytical and technical aptitude with focus on identifying and alleviating the root cause of a problem.Proven ability to thrive and respond to frequent demands of multiple constituents, both internal and external, in a high demand, customer-centric environment. Educational Qualifications: Relevant Bachelor’s Degree Desirable: Familiarity and experience working within the regionExperience working as part of a MSSP or MDR providerExperience with deploying and administering multiple SIEM technologiesCertification for Managing and Administration Splunk, Microsoft Sentinel, Google Sec Ops or any other SIEM relevant