The Next-Gen SIEM/XDR Architect will lead the integration of AI security agents with SIEM, SOAR, and XDR systems, ensuring effective data transformation and connectivity. This role involves collaborating with security operations teams, designing high-performance data workflows, and developing threat intelligence feeds while leveraging knowledge of various security frameworks and programming in Python.
- Lead the integration of AI security agents with existing SIEM, SOAR, and XDR systems and data platforms, ensuring seamless connectivity and data transformation.
- Collaborate with security operations teams to gather requirements and ensure AI agents can effectively utilize security data.
- Design and implement scalable and high-performance data transformation processes to optimize AI agent functionality.
- Develop and maintain data feeds compatible with frameworks like MITRE ATT&CK to enhance threat intelligence.
- Build and organize security information platforms to support the deployment and operation of AI security agents.
- Build and integrate security content to be leveraged by AI security agents
- Extensive experience in developing and integrating SIEM and XDR systems, with hands-on knowledge of products such as IBM QRadar, Splunk, Microsoft Sentinel, Palo Alto Cortex XSOAR/XSIAM, Crowdstrike Falcon, etc.
- Experience with formats leveraged in security operations such as ECS, CIM, OCSF, Sigma, STIX/TAXII, etc.
- Strong background in threat intelligence, detection engineering, and cybersecurity analytics.
- Proficiency in programming with Python and experience with cloud platforms, particularly AWS.
- Proven track record of working closely with security operations centers, threat intelligence teams, and incident response processes.
- Familiarity with machine learning and AI techniques as applied to cybersecurity.
- Willingness to work with clients as necessary
Top Skills
Python
Similar Jobs
Be an Early Applicant
As a Platform Support Engineer at ZS, you will assist clients with SaaS application functionality and configuration, develop documentation to streamline troubleshooting, and resolve software related issues while collaborating with various internal teams.
The Accessibility Consultant will test and validate user interfaces for accessibility compliance, consult clients on implementing digital accessibility, and ensure the quality of client systems. Responsibilities include defining test plans, conducting manual tests, and working with assistive technology tools to enhance usability for individuals with disabilities.
As a Site Reliability Engineer I, you will maintain the health and reliability of games and services at Take-Two. Your responsibilities include monitoring infrastructure, providing on-call support, troubleshooting incidents, and managing cloud services across multiple platforms. You'll ensure seamless operations and communication during outages, focusing on enhancing system performance and scalability.
What you need to know about the Chennai Tech Scene
To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.