ACG2366JOB
Our client is a leading information security technology company in Vietnam who is looking for a qualified candidate to join their firm:
- Build a monitoring use case set for new devices and platforms.
- Develop a monitoring use case set for new customers.
- The monitoring use case set must detect all risks and incidents.
- The false negative rate should be low.
- Collect data sources from SIEM and XDR systems.
- Write parsers.
- Create monitoring rules.
- Ensure the rules on SIEM and XDR systems correspond to the monitoring use case set.
- Maintain a low false negative rate: ensure that no attack behaviors intrusions or security incidents occur without alerts.
- Optimize the rule set on SIEM and XDR solutions.
- Keep the false positive alert rate below the target threshold.
- Support new employees in researching documents solutions and conducting tasks.
- Enable new employees to adapt to their roles quickly.
- Support monitoring analysis incident investigation and other tasks (less than 10% focus):
- Assist in monitoring and investigating incidents when issues arise.
- Support assigned tasks and complete them as required.
Requirements
- A bachelors degree in Information Technology or Cybersecurity (mandatory).
- Preferred certifications in cybersecurity: CEH CHFI etc.
- Preferred certifications in managing security solutions like QRadar Splunk Sentinel F5 PaloAlto or similar.
- Professional Knowledge
- Knowledge of Windows and Linux server operating systems.
- Understanding of computer networks: network models (OSI TCP/IP) network protocols (IP HTTP) networking devices (router switch) etc.
- Knowledge of common attack forms and how to recognize and analyze them: phishing malware brute force DoS/DDoS C2 connections web attacks etc.
- Knowledge of log collection mechanisms: agent syslog.
- Understanding of the structure and content of various log types: Windows events audit logs access logs.
- Proficient in using various SIEM and XDR solutions: QRadar Splunk Sentinel Helix or other similar solutions.
- Good communication skills: effectively listen to gather complete information and convey messages clearly and coherently.
- Document drafting skills: produce balanced and clean reports.
Contact: Dung Nguyen or Nhat Anh Nguyen
Due to the immense number of applicants only shortlisted candidates will be contacted
A bachelor's degree in Information Technology or Cybersecurity (mandatory). Preferred certifications in cybersecurity: CEH, CHFI, etc. Preferred certifications in managing security solutions like QRadar, Splunk, Sentinel, F5, PaloAlto, or similar. Professional Knowledge Knowledge of Windows and Linux server operating systems. Understanding of computer networks: network models (OSI, TCP/IP), network protocols (IP, HTTP), networking devices (router, switch), etc. Knowledge of common attack forms and how to recognize and analyze them: phishing, malware, brute force, DoS/DDoS, C2 connections, web attacks, etc. Knowledge of log collection mechanisms: agent, syslog. Understanding of the structure and content of various log types: Windows events, audit logs, access logs. Proficient in using various SIEM and XDR solutions: QRadar, Splunk, Sentinel, Helix or other similar solutions. Good communication skills: effectively listen to gather complete information and convey messages clearly and coherently. Document drafting skills: produce balanced and clean reports. Contact: Dung Nguyen or Nhat Anh Nguyen Due to the immense number of applicants, only shortlisted candidates will be contacted