Job Type
Full-time
Work Type
On-Site
Location
Doha, Qatar
Experience
5 - 10 years
Platform Administration:
- Install, configure, and maintain LogRhythm SIEM platform components (collectors, processors, and storage).
- Manage system updates, patches, and upgrades to ensure platform security and functionality.
- Monitor the health and performance of the platform, ensuring high availability and reliability.
- Troubleshoot and resolve issues related to the LogRhythm platform, including data ingestion, alerts, and reporting.
- Perform periodic backups of configurations and ensure recovery processes are tested.
Security Monitoring & Event Management:
- Work with the security operations team to tune and optimize event correlation rules, policies, and alerts.
- Analyze and review LogRhythm logs and events to identify potential security incidents or vulnerabilities.
- Configure and maintain custom log sources and integrations, ensuring all necessary data is ingested into the platform.
- Collaborate with other IT teams to integrate additional security tools into LogRhythm (e.g., firewalls, IDS/IPS, endpoint protection systems).
Incident Response Support:
- Assist with investigating security incidents by providing insights from LogRhythm dashboards, reports, and logs.
- Create custom reports and alerts to aid in incident detection and response.
- Provide technical support to security analysts during incident investigations.
Reporting & Dashboards:
- Develop and maintain customized dashboards and reports tailored to the organization's security requirements.
- Create automated reports for compliance and audit purposes.
- Provide visibility into security metrics and key performance indicators (KPIs) to stakeholders.
Performance Optimization:
- Continuously assess and improve the performance of the LogRhythm platform, ensuring efficient data processing and storage.
- Identify and address any performance bottlenecks related to data ingestion, correlation, and reporting.
Collaboration & Documentation:
- Collaborate with internal teams to identify and address emerging security threats.
- Maintain clear and comprehensive documentation for platform configuration, processes, and incident resolution.
- Train and support team members on LogRhythm best practices and usage.
Compliance & Security Standards:
- Ensure the platform is configured to comply with industry regulations (e.g., GDPR, HIPAA, PCI-DSS).
- Conduct periodic reviews of platform configurations to ensure alignment with internal security policies.