Cyber Security - SIEM content developer

Cisco - Egypt - Egypt

While reading our job description, please remember - we understand from experience that not ticking every box on the skills sections stops many from applying. You should apply if you feel you are the right person for the job and have the aptitude to learn and deliver results 🙂

· Strong understanding of Endpoint Detection and Response (EDR) concepts, with specific experience in implementing and managing Fidelis and HX platforms. · Proficiency in writing code and queries for cybersecurity analysis and monitoring using Splunk, including knowledge of Splunk Search Processing Language (SPL). · Experience in cyber threat detection, incident response, and endpoint security. · In-depth knowledge of cybersecurity principles, practices, and best practices. · Familiarity with scripting languages such as Python, as well as experience in creating custom scripts for automating tasks in a cybersecurity context. · Ability to analyze and interpret security data, and communicate findings effectively to stakeholders. · A strong troubleshooting background with the ability to diagnose and resolve issues related to EDR agents, including but not limited to configuration problems, connectivity issues, and false positives/negatives. · Experience in writing and implementing detection rules within EDR platforms, including the ability to create custom rules tailored to specific threats and environments. · Proficiency in working with YARA rules, including the capability to attach and integrate YARA rules within the EDR environment for enhanced threat detection and response. · Proficiency in data integration within Splunk, including the ability to ingest and normalize data from various sources such as logs, databases, and APIs. · Expertise in creating and optimizing data extraction processes using regular expressions (regex) within Splunk, enabling efficient and accurate extraction of relevant information from raw data. · Experience with field extractions, event parsing, and transforming data into a format suitable for analysis and visualization within Splunk. · Understanding of Splunk's props.conf and transforms.conf configurations to effectively extract, transform, and route data within the Splunk platform. · Knowledge of Splunk's Common Information Model (CIM) for standardizing and normalizing data inputs to facilitate correlation and analysis across different data sources. · Proficiency in scripting languages commonly used in a Red Hat environment, such as Bash scripting for automation and system administration tasks. · Experience with Red Hat-specific tools and technologies, including Red Hat Enterprise Linux (RHEL) and its associated scripting and automation frameworks. · Familiarity with package management and software deployment on Red Hat-based systems, including creating and maintaining scripts for efficient software installation and updates. · Understanding of Red Hat's security features and best practices, including the ability to script and configure security measures within Red Hat environments.

Why Cisco

#WeAreCisco, where each person is unique, but we bring our talents to work as a team and make a difference powering an inclusive future for all. We embrace digital, and help our customers implement change in their digital businesses. Some may think we’re “old” (36 years strong) and only about hardware, but we’re also a software company. And a security company. We even invented an intuitive network that adapts, predicts, learns and protects. No other company can do what we do – you can’t put us in a box! But “Digital Transformation” is an empty buzz phrase without a culture that allows for innovation, creativity, and yes, even failure (if you learn from it.) Day to day, we focus on the give and take. We give our best, give our egos a break, and give of ourselves (because giving back is built into our DNA.) We take accountability, bold steps, and take difference to heart. Because without diversity of thought and a dedication to equality for all, there is no moving forward. So, you have colorful hair? Don’t care. Tattoos? Show off your ink. Like polka dots? That’s cool. Pop culture geek? Many of us are. Passion for technology and world changing? Be you, with us!

Post date: Today
Publisher: Laimoon
Post date: Today
Publisher: Laimoon