Total-TECH Co.
” The Job Description”
- Deploy, manage, and maintain XDR and EPP agents across all endpoints and servers.
- Investigate and respond to malware, exploits, and fileless attack incidents.
- Optimize detection by tuning security policies and reducing false positives.
- Integrate endpoint telemetry with SIEM/XDR platforms for unified visibility. Prepare and deliver monthly endpoint risk and compliance reports.
- Design, deploy, and manage Splunk SIEM architecture including indexers, forwarders, and syslog collectors.
- Integrate logs from firewalls, endpoints, NDR, DLP, WAF, SOAR, cloud, and SaaS platforms into a unified SIEM.
- Develop custom detection rules, dashboards, and correlation searches to identify threats.
- Tune and optimize syslog parsing, field extractions, and indexing to ensure performance and cost efficiency.
- Collaborate with Threat Intelligence & SOAR (Engineer 8) to automate response workflows.
- Manage log retention policies to ensure compliance with frameworks like NCA, PCI DSS, and GDPR.
- Deliver weekly security dashboards and monthly SIEM health and detection performance Report.
