SIEM Onboarding Engineer

Avensys Consulting European Union
Remote
Apply
AI Summary

Enhance security posture by integrating devices and data sources into SIEM environment. Collaborate with business units to onboard devices, manage data pipeline, and automate configuration. Leverage automation scripts and tools to streamline deployment and configuration.

Key Highlights
Device Integration
Data Pipeline Management
Automation
Collaboration
Monitoring and Troubleshooting
Key Responsibilities
Work with various business units to identify devices and data sources that need to be onboarded to our SIEM (OpenSearch with Security Analytics).
Configure and manage data collection agents to ensure data is reliably ingested into the SIEM.
Leverage automation scripts and tools to streamline the deployment and configuration of data collection agents across multiple devices.
Collaborate with security engineers and other stakeholders to ensure seamless integration and optimal performance of the SIEM.
Monitor the data pipeline for issues, troubleshoot problems, and implement fixes to maintain data integrity and system reliability.
Maintain comprehensive documentation on the onboarding processes, configurations, and troubleshooting procedures.
Technical Skills Required
Infra Knowledge Networking SIEM tools AWS Elasticsearch Wazuh OpenSearch
Benefits & Perks
Euro 280/day
Remote work
Nice to Have
Experience creating and managing automation scripts for deploying and configuring security agents across large environments.
Experience in tuning and optimizing OpenSearch or Elasticsearch indexers.
Experience with incident response processes and forensic analysis to support investigations and improve threat detection.
Experience with cloud-native security tools and services.

Job Description


Role: SIEM Onboarding Engineer

Location: Europe(100% Remote)

Rate: Euro 280/Day(It’s Max rate)

Must have skills: Infra Knowledge, networking Basic understanding, SIEM tools understanding, AWS, Information Security understanding, Elastic Search-Knowledge, Wazuh

Working Hour: UK working hour


Job Description:

The SIEM Onboarding Engineer plays a critical role in enhancing our organization’s security posture by integrating various devices and data sources into our SIEM environment, utilizing OpenSearch. The SIEM Onboarding Engineer will work closely with business units to identify devices for onboarding, manage the data pipeline, and assist other engineers in configuring their data sources to provide a resilient pipeline. The SIEM Onboarding Engineer will approach each system to be onboarded methodically while using our automation tool whenever possible.


Responsibilities:

  • Device Integration: Work with various business units to identify devices and data sources that need to be onboarded to our SIEM (OpenSearch with Security Analytics).
  • Data Pipeline Management: Configure and manage data collection agents to ensure data is reliably ingested into the SIEM.
  • Automation: Leverage automation scripts and tools to streamline the deployment and configuration of data collection agents across multiple devices.
  • Collaboration: Collaborate with security engineers and other stakeholders to ensure seamless integration and optimal performance of the SIEM.
  • Monitoring and Troubleshooting: Monitor the data pipeline for issues, troubleshoot problems, and implement fixes to maintain data integrity and system reliability.
  • Documentation: Maintain comprehensive documentation on the onboarding processes, configurations, and troubleshooting procedures.
  • Compliance and Security: Ensure all data collection and onboarding processes comply with organizational security policies and industry best practices.


Required Experience:

  • Hands-on experience with onboarding new devices into a SIEM.
  • Hands-on experience with data pipeline management with fluentd nodes and Beats.
  • Experience with sending data to Elasticsearch or OpenSearch clusters.
  • Proven experience in onboarding data from common security data sources to include:
  • Application logs
  • Linux and Windows Servers
  • Firewalls
  • Load balancers and Proxies
  • AWS services
  • Familiarity with cloud infrastructure and services including IAM, VPCs, and container orchestrations.


Desired Experience:

  • Experience creating and managing automation scripts for deploying and configuring security agents across large environments.
  • Experience in tuning and optimizing OpenSearch or Elasticsearch indexers.
  • Experience with incident response processes and forensic analysis to support investigations and improve threat detection.
  • Experience with cloud-native security tools and services


Desired Qualifications:

  • Advanced coursework in Computer Science or Information Technology, or equivalent experience.
  • Bachelor’s Degree in a related field, or equivalent industry experience.
  • Relevant industry certifications such as CISSP, CISM, SANS GIAC, CEH, LPT, etc.


Similar Jobs

Explore other opportunities that match your interests

Associate Account Manager - B2B Sales (Remote)

Cyber Security
37m ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Keeper Security, Inc.

United State

Product Security Architect

Cyber Security
39m ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

The College Board

United State

Cyber Security Risk Consultant

Cyber Security
3h ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Not Applicable

hire feed

Emea

Subscribe our newsletter

New Things Will Always Update Regularly