Tech Mahindra Ltd logo
LogRhythm Platform Administrator

Tech Mahindra Ltd

Job Type

Full-time

Work Type

On-Site

Location

Doha, Qatar

Experience

5 - 10 years

Platform Administration:

  • Install, configure, and maintain LogRhythm SIEM platform components (collectors, processors, and storage).
  • Manage system updates, patches, and upgrades to ensure platform security and functionality.
  • Monitor the health and performance of the platform, ensuring high availability and reliability.
  • Troubleshoot and resolve issues related to the LogRhythm platform, including data ingestion, alerts, and reporting.
  • Perform periodic backups of configurations and ensure recovery processes are tested.

Security Monitoring & Event Management:

  • Work with the security operations team to tune and optimize event correlation rules, policies, and alerts.
  • Analyze and review LogRhythm logs and events to identify potential security incidents or vulnerabilities.
  • Configure and maintain custom log sources and integrations, ensuring all necessary data is ingested into the platform.
  • Collaborate with other IT teams to integrate additional security tools into LogRhythm (e.g., firewalls, IDS/IPS, endpoint protection systems).

Incident Response Support:

  • Assist with investigating security incidents by providing insights from LogRhythm dashboards, reports, and logs.
  • Create custom reports and alerts to aid in incident detection and response.
  • Provide technical support to security analysts during incident investigations.

Reporting & Dashboards:

  • Develop and maintain customized dashboards and reports tailored to the organization's security requirements.
  • Create automated reports for compliance and audit purposes.
  • Provide visibility into security metrics and key performance indicators (KPIs) to stakeholders.

Performance Optimization:

  • Continuously assess and improve the performance of the LogRhythm platform, ensuring efficient data processing and storage.
  • Identify and address any performance bottlenecks related to data ingestion, correlation, and reporting.

Collaboration & Documentation:

  • Collaborate with internal teams to identify and address emerging security threats.
  • Maintain clear and comprehensive documentation for platform configuration, processes, and incident resolution.
  • Train and support team members on LogRhythm best practices and usage.

Compliance & Security Standards:

  • Ensure the platform is configured to comply with industry regulations (e.g., GDPR, HIPAA, PCI-DSS).
  • Conduct periodic reviews of platform configurations to ensure alignment with internal security policies.