Chronicle Administrator (Consultant/Sr.Consultant)
HybridNoida, Uttar Pradesh, India
Noida, Uttar Pradesh, IndiaHybridFull TimeSenior LevelBachelors DegreeSmall
Full TimeSenior LevelBachelors DegreeSmall
Job Summary
Manage Chronicle implementation, log source integration, rule creation, and parser development within SIEM and EDR solutions. Design detection rules for attack activities including network probing, DDoS, malicious code, data exfiltration, and credential access using frameworks like MITRE ATT&CK. Configure detection mechanisms for cloud threats and network devices while maintaining proficiency with tools such as Splunk, QRadar, and LogRhythm. Requires 3 to 8 years of experience with a specific focus on Chronicle, CISSP or CEH certification, and strong analytical skills. Hybrid schedule.
Required Qualifications
- Bachelor's degree in engineering, computer science, information systems, information security, mathematics, decision sciences, risk management, or other business/technology fields, or equivalent professional experience
- Certifications such as CISSP, CEH, or similar
- 3 to 8 years of experience (Senior Level) with 8 months to 2 years specifically in Chronical implementation, including log source integration, rule creation, and parser development
- Proficiency with leading SIEM technologies (e.g., Splunk, QRadar, LogRhythm, Nitro, Chronicle), IDS/IPS, network and host-based firewalls, data leakage protection (DLP), and common EDR platforms
- Knowledge of potential attack activities such as network probing/scanning, DDoS, malicious code activity, data exfiltration, and credential access
- Familiarity with the Cyber Kill Chain, MITRE ATT&CK framework, and various TTPs used by attackers, along with the ability to create detection rules for these in SIEM and EDR solutions
- Understanding of tools, technologies, and logging mechanisms, including common network devices like routers, switches, and load balancers
- Awareness of typical cloud threats and how to detect and mitigate them, cloud logging and audit capabilities, and the ability to develop detection rules for these threats
- Basic understanding of networking protocols such as IP, DNS, HTTP, and the network stack
- Foundational knowledge in system security architecture and security solutions
Desired Qualifications
- Excellent interpersonal and organizational abilities
- Strong verbal and written communication skills
- Superior analytical and problem-solving capabilities
- Self-driven to enhance knowledge and skillsets
- A strong desire to comprehend not just the 'what,' but also the 'why' and 'how' of security incidents
- ability to create detection rules for these in SIEM and EDR solutions (added advantage)
- ability to develop detection rules for these threats
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.