Manager, Security Data Analytics (SIEM)

Posted on Feb 23, 2021 by Tri-S Recruiters, Inc.
Deerfield, IL 60015
IT
Immediate Start
$120k - $140k Annual
Full-Time
Fortune 50 corporation is seeking a Manager, Security Data Analytics (SIEM) in Deerfield, IL
No current or future sponsorship of any kind is available...
- Responsible for overall security data analytics strategy within the Global Security Fusion Center
- Provide day-to-day oversight of SIEM and data analytics teams
- Coordinates with Incident Handling, Threat Hunt, Data Protection, Threat Intelligence, Vulnerability Management, and Intelligence Information & Reporting teams as well as other teams to provide consistent quality of data analysis across the GSFC portfolio
- Partners with technology teams, including Data Discovery & Decision Science, Monitoring & Analytics Engineering, and Systems Engineering teams to implement and delivery best-of-breed data analytics solutions
- Serves as subject matter expert related to Splunk and content development
- Champions the implementation of enterprise-wide logging and monitoring initiatives
- Periodically reviews saved searches and notable content to ensure ongoing quality
- Leads weekly SIEM stakeholder meetings to understand and prioritize ongoing quality and continuous improvement activities
- Supervises the creation and management of dashboards showing overall status of GSFC data inputs and outputs/products
Job Requirements
- Bachelor's Degree in business, engineering, or technology, or equivalent experience
- 7 or more years of related experience
- Advanced understanding of security operations and security incident & event management
- Basic understanding of vulnerability management, threat intelligence, penetration testing, data protection, and threat hunting functions
- Advanced knowledge of Splunk, including forwarding architecture, indexing architecture, and search architecture, information models, as well as query preparation, query analysis, and query performance
- Understanding of contemporary data analytics approaches, including expert systems and machine learning
- Professional certification or commensurate experience
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Experience working with large, decentralized software development organizations
Reference: 1105873132