Cyber SIEM

Mission

With the increasing need for advanced detection to protect the bank there is a requirement for talented and motivated people to join an expanding Cyber Security team. This team works with the latest and best technology in order to combat advanced attackers, making the bank and its customers safer.

Functions

  • Creating/Develop Advanced Use cases to feed SOC (Security Operation Center) into various SIEM (Splunk, Microsoft Sentinel)
  • Ensure Data Ingestion quality regarding Cyber Security Use Cases.
  • Diagnosis and revision of Cyber Security Use Cases using SIEM (Splunk) to optimize Detection capabilities.
  • Development of specific  Cyber Content ( KPI , Dashboards, reports)
  • Create improvements in processes and procedures (use-case exceptions Management and Maintenance etc.)
  • Create technical documentation around the Cyber content deployed in the SIEM
  • Develop cloud specific detection capabilities (Azure, AWS)
  • Understanding of internal and external Threat Scenarios, how to identify these threats within the Santander group.

Requirements

Education:

  • Degree: Information Technology, computer science, computer engineering, network technology or similar.

 

Desirable certifications:

  • SANS GSEC
  • Splunk Certifications and Courses
  • CISSP
  • CISA
  • GCIA

 

Competences:

  • Strong analytical and problem solving skills
  • Process and procedure adherence
  • Excellent inter-personal skills
  • Strong communication skills, both written and verbal

 

 Languages

English Advanced

Spanish

Experience

  • 3+ years of experience in Information technology and cybersecurity
  • Understanding of Cyber Security Operation
  • Excellent Knowledge on Data analysis of event Logs , Logging standards and normalization
  • Deep knowledge in Log Management or Security Information and Event Management (SIEM) Administration. Especially on parsing and correlation. (Desirable SIEM Splunk).
  • Cybersecurity/Network/Systems Platforms Knowledge ( Firewalls, Antivirus, Intrusion systems, Authentication systems, malware detection, WAF, proxy, Windows, Unix etc)
  • Cloud Environments Experience (Azure and AWS)
  • Knowledge in BIG data infrastructures and data mining
  • Good knowledge in regular expressions
  • Knowledge in Content Creation and best practices
  • Programming capabilities and script languages (Python, VBS, Java, JavaScript, powershell, Perl etc.)