SIEM/EDR Specialist

SIEM/EDR Specialist

08 Jan 2025
Georgia, Augusta, 30917 Augusta USA

SIEM/EDR Specialist

Our CompanyAt Teradata, we believe that people thrive when empowered with better information. That’s why we built the most complete cloud analytics and data platform for AI. By delivering harmonized data, trusted AI, and faster innovation, we uplift and empower our customers and our customers’ customers to make better, more confident decisions. The world’s top companies across every major industry trust Teradata to improve business performance, enrich customer experiences, and fully integrate data across the enterprise.What You'll DoWe are seeking a skilled and detail-oriented SIEM and EDR Specialist to join our Security Operations team. This role involves designing, managing, and optimizing SIEM (Security Information and Event Management) and EDR (Endpoint Detection and Response) solutions to enhance the organization's cybersecurity posture. The ideal candidate will leverage their expertise to detect, investigate, and respond to security incidents, ensuring the protection of our systems, data, and users.Key Responsibilities

Configure, manage, and maintain SIEM and EDR platforms to ensure optimal performance and coverage.

Develop and refine detection rules, correlation alerts, and threat hunting queries in the SIEM environment.

Analyze logs, network traffic, and endpoint telemetry to identify and respond to potential security threats.

Lead incident response activities, including containment, eradication, and recovery efforts.

Collaborate with IT and other security teams to integrate new data sources and improve threat detection capabilities.

Stay up-to-date on the latest threat intelligence, vulnerabilities, and attack techniques to continuously enhance detection and response strategies.

Conduct regular health checks of SIEM and EDR platforms, troubleshoot issues, and implement upgrades.

Develop and maintain comprehensive documentation for processes, configurations, and playbooks.

Provide training and mentorship to junior team members and act as a subject matter expert for SIEM and EDR technologies.

What Makes You a Qualified Candidate

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field. Equivalent experience may be considered.

3-5 years of hands-on experience managing and configuring SIEM platforms (e.g., Splunk, QRadar, LogRhythm, Sentinel, Palo Alto Cortex).

3+ years of experience with EDR solutions (e.g., CrowdStrike, Carbon Black, SentinelOne, Cortex)

Experience in Migrating EDR and SIEM Platforms.

Proven experience in incident response and threat hunting.

Strong understanding of log management, event correlation, and security event analysis.

Proficiency in scripting and automation (e.g., Python, PowerShell) to streamline processes.

Familiarity with common attack frameworks (MITRE ATT&CK, Cyber Kill Chain).

Solid grasp of networking concepts, operating systems (Windows/Linux), and cybersecurity principles.

Experience with cloud security monitoring (AWS, Azure, or GCP).

Relevant certifications such as GCIA, GCIH, CEH, CISSP, CISM, or vendor-specific certifications (e.g., Splunk Certified Architect, Cortex Certified etcCrowdStrike Certified Falcon Administrator).

What You Will Bring

Analytical Mindset: Strong problem-solving skills with the ability to analyze complex data sets to identify anomalies and potential threats.

Attention to Detail: A meticulous approach to configuration, troubleshooting, and incident documentation.

Collaboration: Excellent interpersonal skills with the ability to work effectively across teams in high-pressure environments.

Adaptability: A proactive attitude and willingness to stay updated on emerging security trends and tools.

Communication Skills: Clear and concise communication, both verbal and written, to convey technical details to diverse audiences.

Passion for Cybersecurity: A genuine interest in defending against evolving cyber threats and a commitment to continuous learning.

Pay Rate: $121,900.00 - $152,300.00 - $182,800.00 AnnuallyWhy We Think You’ll Love TeradataWe prioritize a people-first culture because we know our people are at the very heart of our success. We embrace a flexible work model because we trust our people to make decisions about how, when, and where they work. We focus on well-being because we care about our people and their ability to thrive both personally and professionally. We are an anti-racist company because our dedication to Diversity, Equity, and Inclusion is more than a statement. It is a deep commitment to doing the work to foster an equitable environment that celebrates people for all of who they are.#LI-CP2Teradata invites all identities and backgrounds in the workplace. We work with deliberation and intent to ensure we are cultivating collaboration and inclusivity across our global organization.​We are proud to be an equal opportunity and affirmative action employer. We do not discriminate based upon race, color, ancestry, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related conditions), national origin, sexual orientation, age, citizenship, marital status, disability, medical condition, genetic information, gender identity or expression, military and veteran status, or any other legally protected status.Pay Rate: 121900.0000 - 152300.0000 - 182800.0000 AnnuallyStarting pay for the successful applicant will depend on geographic location, internal equity, job-related knowledge, skills, and candidate experience. Learn more about Teradata’s competitive Total Rewards package at https://www.teradata.com/About-Us/Careers/Benefits

Related jobs

  • JOB SUMMARY

  • Executive Assistant to the Commissioner (Office Specialist II Supervisor)

  • Job Description

  • Job Description

  • Position Summary

  • Summary THIS IS A NATIONAL GUARD TITLE 32 EXCEPTED SERVICE POSITION. This National Guard position is for a IT SPECIALIST (NETWORK/SYSADMIN), Position Description Number D2728000 and is part of the ME DCSLOG, National Guard. Responsibilities This position is located at the JFHQ-State, Deputy Chief of Staff for Logistics (DCSLOG) (G4/J4), Sustainment Automation Support Management Office (SASMO). The primary purpose of this position is to provide support for Automated Logistics Information Systems and Programs to all Stat/Territory activities/organizations and perform a wide range of specialized methods/techniques for planning; analyzing and identifying problems in order to develop and implement resolutions to administrative and systemic programs throughout the organization. DUTIES: 1. Serves as an advisor to the Supervisory Logistics Information Technology (LIT) Specialist (SASMO) and Systems Administrator on all Combat Service Support (CSS) Automated Logistics Systems and Programs. Exercises knowledge and oversight for all matters pertaining to the fielding and operation of Automated Logistics System and Programs. Utilizes an extensive knowledge of logistics programs/operations and a clear understanding of automated systems to manage projects and programs for systems integration of CSS automation. Identifies funding requirements to support SASMO operations, justifies and submits budget requirements for State/Territory operating budget, and executes funds received. Is the technical expert within the State/Territory responsible for providing technical and functional guidance for serviced Automated Logistics Systems and Programs. Serves as project leader/supervisor responsible for developing, assigning, and coordinating duties and projects for LIT systems administrators. Serves as the senior LIT systems administrator responsible for planning, coordinating, modifying, implementing, and troubleshooting to support customer needs. Reviews SASMO Standard Operating Procedures (SOPs) to ensure they are current (i.e., help desk, repair operations, etc.). Evaluates trouble tickets escalated from the help desk, setting priorities on a weekly and monthly basis. Coordinates automation initiatives with State G6 and G3 elements. Operates as the Quality Control Specialist for the Quality Control Program and Quality Control Plan. Oversees a variety of studies, analyses, and reports regarding the integrity of all LIT systems. Conducts quality inspections, customer feedback, and continuous improvement initiatives associated with the Quality Control Plan. (35%) 2. Perform Software conversion, hardware fielding and continuous support. Researches and resolves hardware, software, and applications program problems by troubleshooting and working with user, NGB support agencies, and/or manufacturer/vendors/representatives as required. Develops/implements programs to ensure software and vulnerabilities updates are applied in proper order. Coordinates and communicates with Department of the Army (DA), National Guard Bureau (NGB), and Program Executive Office/Program Manager, regarding CSS operations and automated systems support, problem resolution, software upgrades and change packages. Assists functional users in automated CSS systems management and operation. Provides advisory services for functional users. Provides requested information gathered through the analysis of available documentation such as functional user manuals, regulations, operations manuals, and technical support manuals. Provides assistance to functional users in the identification of computer problems, troubleshooting diagnostics and resolution of technical problems identified in trouble tickets and initial setup of serviced Automated Logistics System computers to include loading software, configuring modem and network card(s), assigning Internet Protocol (IP) addresses with correct subnet, connectivity to the network as required, coordinating with other support personnel and completing technical inspections. Provide hands on technical support to all State/Territory unit Logistics Automation Systems in order to provide uninterrupted operation and support. Resolves issues and problems concerning the effectiveness and efficiency of automated logistical systems administrative and systemic work operations. Utilizes knowledge of logistics management principles, policies, and procedures to implement, establish, and execute operational plans and policies for the Automated Logistics Systems. Represents the DCSLOG as the primary POC responsible for the functional implementation and sustainment of varied automation information management systems. (15%) 3. Analyzes requirements, manages, and coordinates automated logistics information system hardware and peripherals pertaining to the receipt, distribution, installation, and life cycle management of devices that are directed to be managed at unit/State/Territory level. Installs, tests, and evaluates automated logistics information system hardware. Manages the State/Territory CSS automation hardware tactical computer exchange (TCX) (aka equipment float) program and ensures accountability of exchanges. Requirements Conditions of Employment Qualifications Military Grades: Warrant Officer CW4 & Below, Enlisted. GENERAL EXPERIENCE: Experience, education or training that has provided a basic knowledge of data processing functions and general management principles that enabled the applicant to understand the stages required to automate a work process. Experience may have been gained in work such as computer operator or assistant, computer sales representative, program analyst, or other positions that required the use or adaptation of computer programs and systems. SPECIALIZED EXPERIENCE: Must have at least 36 months experience, education, or training that approaches techniques and requirements appropriate to an assigned computer applications area or computer specialty area in an organization. Experience planning the sequence of actions necessary to accomplish the assignment where this entailed coordination with others outside the organizational unit and development of project controls. Experience that required adaptations of guidelines or precedents to meet the needs of the assignment. Experience preparing documentation on cost/benefit studies where is involved summarizing the material and organizing it in a logical fashion. Education If you are using Education to qualify for this position, You must provide transcripts or other documentation to support your Educational claims. To receive credit for Education, you must provide documentation of proof that you meet the Education requirements for this position. Additional Information If you are a male applicant who was born after 12/31/1959 and are required to register under the Military Selective Service Act, the Defense Authorization Act of 1986 requires that you be registered or you are not eligible for appointment in this agency (Register | Selective Service System : Selective Service System (sss.gov)).

  • Overview

Job Details

Jocancy Online Job Portal by jobSearchi.