SIEM Management
منذ 22 ساعات
Doha, قطر
Malomatia
دوام كامل
مجانًا عبر البريد الإلكتروني أو Google
احفظ هذه الوظيفة وحافظ على تنظيم بحثك
قم بإنشاء حساب مجاني لحفظ الوظائف وإنشاء التنبيهات والعودة إلى هذه القائمة من لوحة التحكم الخاصة بك.
مجانًا عبر البريد الإلكتروني أو Google
بالمتابعة، فإنك توافق على الشروط & سياسة الخصوصية.
The SIEM Engineer will manage and optimize enterprise SIEM platforms, supporting security monitoring, log management, threat detection, and incident response across on-premises and cloud environments. The role requires hands-on experience with SIEM deployment, security tool integrations, log onboarding, detection rules, and cloud security monitoring, along with strong troubleshooting and analytical skills.
Responsibilities
• Designing, reviewing, implementing, testing, maintaining, and troubleshooting SIEM deployments and infrastructures.
• Responsible for managing arrangements of dependencies and pre-requisites for SIEM projects e.g., connectivity, storage, licenses, and other equipment).
• Responsible for implementing changes to the SIEM infrastructure (including patches, updates, and upgrades) and performing SIEM Health Checks; and for creating technically relevant detailed reports to track solution effectiveness and performance.
• Manage SIEM Appliance or Virtual Appliance (including OS and SIEM software).
• Configure backups, verify custom reports, manage log source groups, and validate log sources.
• Manage SIEM user accounts (create, delete, modify, etc.).
• Add /Remove log sources. Troubleshoot issues with log sources or systems with system owners and vendors, and report system defects and product enhancement / feature requests with vendors as needed.
• Be responsible for development of integrations, connectors, and parsers for new event sources
• Implementing security monitoring rules in a SIEM tooling, according to the business needs
• Assist with fully optimizing the SIEM system capabilities and identifying opportunities for automation to improve SIEM effectiveness and efficiency.
• Create rules and reports for compliance and audit requirements and create and manage Watch Lists for current threats.
• Create engineering and security documentation for internal and external needs including high level and low-level design of SIEM infrastructure, as-built documentation and documentation for custom connectors/parsers and integrations.
• Assist with designing and documenting work processes within the SOC.
• Responsible for mentoring and training of Junior SIEM Engineers.
• Perform other duties as assigned. Qualifications
Experience:
• Minimum 5 years of experience in Security Engineering, including at least 3 years of hands-on experience managing SIEM solutions. Educational
Qualifications:
• Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field. Required
Skills:
• Proven experience in designing and implementing SIEM solutions.
• Hands-on experience integrating security tools such as AV, AAA, Firewalls, DLP, and IDS/IPS with SIEM platforms.
• Experience implementing SIEM monitoring across cloud environments, including:
• AWS: CloudTrail, GuardDuty, VPC Flow Logs
• Azure: Activity Logs, Entra ID Sign-in Logs, Microsoft Defender for Cloud
• GCP: Cloud Audit Logs, VPC Flow Logs
• OCI: Audit Logs, Cloud Guard
• Strong hands-on experience with SIEM technologies such as Splunk, Microsoft Sentinel, and Google SecOps.
• Good understanding of Information Security regulations, frameworks, and requirements, with the ability to map security needs to appropriate SIEM solutions.
• Solid understanding of Information Security and Networking.
• Experience with scripting and query languages for SIEM data onboarding, such as Python, Regex, SPL, and KQL.
• Strong analytical, troubleshooting, and problem-solving skills, with a focus on identifying and addressing root causes.
• Excellent time management, organizational, and prioritization skills, with the ability to manage multiple stakeholders and competing priorities.
• Strong written and verbal communication skills, with the ability to explain complex technical concepts to non-technical stakeholders.
• Ability to work on-call, including nights and weekends, when required.
• Ability to work effectively in a high-demand, customer-focused environment and deliver quality results within agreed timelines. Desirable:
• Regional experience and familiarity with the Middle East.
• Experience working within an MSSP or MDR environment.
• Experience deploying and administering multiple SIEM technologies.
• Relevant certifications in Splunk, Microsoft Sentinel, Google SecOps, or other SIEM technologies. About Malomatia malomatia is a leading Qatar-based IT services and solutions provider, bringing together top Qatari and international talent to deliver innovative, end-to-end technology solutions that empower clients to achieve their strategic goals. Our mission Empowering Qatar’s businesses and governments to leap into the digital future with agile, knowledge-driven solutions. Our vision To become Qatar’s trusted knowledge partner in digital transformation, disrupting industries, shaping the future, and building a world-class tech ecosystem. Driving change that makes a real impact Since 2008, malomatia has been driving Qatar’s digital transformation through innovative, ISO-certified IT solutions. With expertise across key public and private sectors, we empower the nation’s vision with advanced services in cloud, cybersecurity, AI, and contact center excellence, elevating the role of technology in shaping Qatar’s sustainable future. Established in 2008, malomatia is a Qatari leader in IT services and digital transformation. We serve key sectors including Government, Healthcare, Education, Customs, and Transportation, delivering impactful solutions that support national development goals. Powered by a diverse team of skilled Qatari and international IT professionals, we deliver innovative, high-value digital solutions tailored to the unique needs of our clients. Our mission is to inspire customers to thrive through digital excellence, and we envision becoming the trusted partner of choice in building a smarter society through technology and talent. We are driven by core values that define our culture and approach: ownership, integrity, empathy, teamwork, transparency, agility, excellence, trust, and innovation. Join us in shaping the future of technology in Qatar
• Designing, reviewing, implementing, testing, maintaining, and troubleshooting SIEM deployments and infrastructures.
• Responsible for managing arrangements of dependencies and pre-requisites for SIEM projects e.g., connectivity, storage, licenses, and other equipment).
• Responsible for implementing changes to the SIEM infrastructure (including patches, updates, and upgrades) and performing SIEM Health Checks; and for creating technically relevant detailed reports to track solution effectiveness and performance.
• Manage SIEM Appliance or Virtual Appliance (including OS and SIEM software).
• Configure backups, verify custom reports, manage log source groups, and validate log sources.
• Manage SIEM user accounts (create, delete, modify, etc.).
• Add /Remove log sources. Troubleshoot issues with log sources or systems with system owners and vendors, and report system defects and product enhancement / feature requests with vendors as needed.
• Be responsible for development of integrations, connectors, and parsers for new event sources
• Implementing security monitoring rules in a SIEM tooling, according to the business needs
• Assist with fully optimizing the SIEM system capabilities and identifying opportunities for automation to improve SIEM effectiveness and efficiency.
• Create rules and reports for compliance and audit requirements and create and manage Watch Lists for current threats.
• Create engineering and security documentation for internal and external needs including high level and low-level design of SIEM infrastructure, as-built documentation and documentation for custom connectors/parsers and integrations.
• Assist with designing and documenting work processes within the SOC.
• Responsible for mentoring and training of Junior SIEM Engineers.
• Perform other duties as assigned. Qualifications
Experience:
• Minimum 5 years of experience in Security Engineering, including at least 3 years of hands-on experience managing SIEM solutions. Educational
Qualifications:
• Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field. Required
Skills:
• Proven experience in designing and implementing SIEM solutions.
• Hands-on experience integrating security tools such as AV, AAA, Firewalls, DLP, and IDS/IPS with SIEM platforms.
• Experience implementing SIEM monitoring across cloud environments, including:
• AWS: CloudTrail, GuardDuty, VPC Flow Logs
• Azure: Activity Logs, Entra ID Sign-in Logs, Microsoft Defender for Cloud
• GCP: Cloud Audit Logs, VPC Flow Logs
• OCI: Audit Logs, Cloud Guard
• Strong hands-on experience with SIEM technologies such as Splunk, Microsoft Sentinel, and Google SecOps.
• Good understanding of Information Security regulations, frameworks, and requirements, with the ability to map security needs to appropriate SIEM solutions.
• Solid understanding of Information Security and Networking.
• Experience with scripting and query languages for SIEM data onboarding, such as Python, Regex, SPL, and KQL.
• Strong analytical, troubleshooting, and problem-solving skills, with a focus on identifying and addressing root causes.
• Excellent time management, organizational, and prioritization skills, with the ability to manage multiple stakeholders and competing priorities.
• Strong written and verbal communication skills, with the ability to explain complex technical concepts to non-technical stakeholders.
• Ability to work on-call, including nights and weekends, when required.
• Ability to work effectively in a high-demand, customer-focused environment and deliver quality results within agreed timelines. Desirable:
• Regional experience and familiarity with the Middle East.
• Experience working within an MSSP or MDR environment.
• Experience deploying and administering multiple SIEM technologies.
• Relevant certifications in Splunk, Microsoft Sentinel, Google SecOps, or other SIEM technologies. About Malomatia malomatia is a leading Qatar-based IT services and solutions provider, bringing together top Qatari and international talent to deliver innovative, end-to-end technology solutions that empower clients to achieve their strategic goals. Our mission Empowering Qatar’s businesses and governments to leap into the digital future with agile, knowledge-driven solutions. Our vision To become Qatar’s trusted knowledge partner in digital transformation, disrupting industries, shaping the future, and building a world-class tech ecosystem. Driving change that makes a real impact Since 2008, malomatia has been driving Qatar’s digital transformation through innovative, ISO-certified IT solutions. With expertise across key public and private sectors, we empower the nation’s vision with advanced services in cloud, cybersecurity, AI, and contact center excellence, elevating the role of technology in shaping Qatar’s sustainable future. Established in 2008, malomatia is a Qatari leader in IT services and digital transformation. We serve key sectors including Government, Healthcare, Education, Customs, and Transportation, delivering impactful solutions that support national development goals. Powered by a diverse team of skilled Qatari and international IT professionals, we deliver innovative, high-value digital solutions tailored to the unique needs of our clients. Our mission is to inspire customers to thrive through digital excellence, and we envision becoming the trusted partner of choice in building a smarter society through technology and talent. We are driven by core values that define our culture and approach: ownership, integrity, empathy, teamwork, transparency, agility, excellence, trust, and innovation. Join us in shaping the future of technology in Qatar