drjobs
Threat Content Lead
drjobs
Threat Content Lead
Help AG
drjobs Threat Content Lead العربية

Threat Content Lead

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs

Jobs by Experience

drjobs

0 - 3 years

Job Location

drjobs

Dubai - UAE

Monthly Salary

drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Nationality

Any Nationality

Gender

N/A

Vacancy

1 Vacancy

Job Description

Req ID : 2366949

Responsibilities:
• Implement and maintain detection capabilities across SIEM and EDR/XDR platforms.
• Evaluate existing EDR/SIEM content to determine which content should be removed or updated to improve fidelity.
• Leverage the MITRE ATT&CK framework, monitor the threat landscape and evaluate existing data sources to identify opportunities for new content development for detection and response.
• Research and innovate new mitigation, detection, and response capabilities given input from industry trends, customer feedback, and personal research.
• Support the onboarding of new data sources by developing relevant EDR/SIEM content.
• Develop EDR/SIEM detection uses cases and review with relevant stakeholders, such as engineers, and others.
• Develop and maintain content catalog, including mapping to the MITRE ATT&CK framework, to improve the efficiency of deploying the security stack to new environments.
• Document and communicate detection capabilities and gaps clearly and effectively leveraging multiple industry frameworks including MITRE ATT&CK, the Cyber Kill Chain, and NIST.
• Design, develop, and monitor various dashboards and reports that provide information on content coverage, alerting, and fidelity.
• Collaborate with technology staff at varying levels of expertise to improve logging from various appliances and correct misconfigurations.
• Assess customer needs and expectations, design solutions to meet those needs, and then implement the design.
• Quickly build and solve a problem using a new technology to determine viability.
• Serve as a primary responder for Managed Security customer systems, taking ownership of issues and tracking through resolution.
• Competent Splunk administration experience, expertise.
• Developing new or extending existing apps to perform specialized functionality.
• Maintain & supporting CIM compliance standardization across Splunk SIEM data sources.
• Integrating Splunk with a wide variety of legacy data sources.
• Engaging application and infrastructure teams to establish best practices for utilizing Splunk data and visualizations.

Employment Type

Full Time

Company Industry

IT - Software Services

Department / Functional Area

Journalism / Content Writing / Editing / Correspondent

About Company

Report This Job
Disclaimer: Drjobs.ae is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.