Elastic SIEM Admins
13 hours ago
Location: Los angeles, CA
Mode: Fulltime
Role Purpose: The Elastic SIEM Admins are responsible for the administration, configuration, and management of the Elastic SIEM platform to ensure the security, performance, and integrity of the organization's security monitoring and incident response capabilities.
Role Responsibilities:
System Configuration: Configure and maintain the Elastic SIEM platform, including settings related to data collection, retention, indexing, and storage.
Data Source Management: Manage the configuration of data sources, such as logs, network traffic, and security appliances, ensuring accurate and efficient data collection.
User and Role Management: Create, manage, and modify user accounts and roles within the SIEM platform, adhering to the principle of least privilege.
Access Control: Define and enforce role-based access control (RBAC) policies to ensure that users have appropriate access levels based on their job functions.
Security Rules: Create and manage security detection rules, anomaly detection settings, and threat intelligence integrations to enhance threat detection capabilities.
Alerting and Incident Response: Configure alerting rules and notifications to promptly inform security teams about potential threats or security incidents.
Data Visualization: Design and manage custom dashboards and visualizations to provide meaningful insights into security data and incidents.
Integration and Automation: Integrate the SIEM platform with other security tools, systems, and workflows to streamline incident response processes.
Platform Upgrades and Maintenance: Plan and execute upgrades, patches, and maintenance tasks to keep the SIEM environment up to date and secure.
Performance Optimization: Monitor the performance and health of the SIEM platform, addressing any performance issues and optimizing resource utilization.
Documentation: Maintain documentation related to the SIEM environment, including configurations, procedures, and best practices.
Access Level: Elastic SIEM Admins have full administrative access to the Elastic SIEM platform, allowing them to configure, manage, and maintain all aspects of the system.
-
Security Architect
9 hours ago
Los Angeles, United States Bio-Rad Laboratories Full timeWe are currently seeking a SOC and Incident response consultant to join our Global information Security Team! We are looking for a candidate who is passionate about security, a self-starter and thrives in a collaborative environment. The ideal candidate will have a bachelor's degree in Computer Science or closely related subject; an advanced degree is...
-
Security Architect
2 months ago
Los Angeles, United States Bio-Rad Laboratories Full timeWe are currently seeking a SOC and Incident response consultant to join our Global information Security Team! We are looking for a candidate who is passionate about security, a self-starter and thrives in a collaborative environment. The ideal candidate will have a bachelor‘s degree in Computer Science or closely related subject; an advanced degree is...
-
Senior Security Operations Center
1 week ago
Los Angeles, CA, United States Deloitte Full timePosition Summary The Senior SOC Analyst team member is responsible for the analysis of all technology devices which may include Operational Technology (OT) and Industrial Control Systems (ICS) within enterprise. This includes analytical analysis of device communication, forensic analysis of Windows or Linux systems and servers, timeline analysis of...