Cyber SIEM
Mission
With the increasing need for advanced detection to protect the bank there is a requirement for talented and motivated people to join an expanding Cyber Security team. This team works with the latest and best technology in order to combat advanced attackers, making the bank and its customers safer.
Functions
- Creating/Develop Advanced Use cases to feed SOC (Security Operation Center) into various SIEM (Splunk, Microsoft Sentinel)
- Ensure Data Ingestion quality regarding Cyber Security Use Cases.
- Diagnosis and revision of Cyber Security Use Cases using SIEM (Splunk) to optimize Detection capabilities.
- Development of specific Cyber Content ( KPI , Dashboards, reports)
- Create improvements in processes and procedures (use-case exceptions Management and Maintenance etc.)
- Create technical documentation around the Cyber content deployed in the SIEM
- Develop cloud specific detection capabilities (Azure, AWS)
- Understanding of internal and external Threat Scenarios, how to identify these threats within the Santander group.
Requirements
Education:
- Degree: Information Technology, computer science, computer engineering, network technology or similar.
Desirable certifications:
- SANS GSEC
- Splunk Certifications and Courses
- CISSP
- CISA
- GCIA
Competences:
- Strong analytical and problem solving skills
- Process and procedure adherence
- Excellent inter-personal skills
- Strong communication skills, both written and verbal
Languages
English Advanced
Spanish
Experience
- 3+ years of experience in Information technology and cybersecurity
- Understanding of Cyber Security Operation
- Excellent Knowledge on Data analysis of event Logs , Logging standards and normalization
- Deep knowledge in Log Management or Security Information and Event Management (SIEM) Administration. Especially on parsing and correlation. (Desirable SIEM Splunk).
- Cybersecurity/Network/Systems Platforms Knowledge ( Firewalls, Antivirus, Intrusion systems, Authentication systems, malware detection, WAF, proxy, Windows, Unix etc)
- Cloud Environments Experience (Azure and AWS)
- Knowledge in BIG data infrastructures and data mining
- Good knowledge in regular expressions
- Knowledge in Content Creation and best practices
- Programming capabilities and script languages (Python, VBS, Java, JavaScript, powershell, Perl etc.)
