Security Information and Event Management (SIEM) Operations

Posted:
9/12/2024, 5:09:05 PM

Location(s):
Quezon City, Metro Manila, Philippines ⋅ Metro Manila, Philippines

Experience Level(s):
Junior ⋅ Mid Level ⋅ Senior

Field(s):
IT & Security ⋅ Software Engineering

Ready to join Accenture’s team of empowered people? We’re looking for candidates with the following skills and experience for this role. Do you fit the profile? If you do, we’d love to hear from you!

 

In adherence to Accenture’s process of Identity Verification, your resume or CV must include your photo to ensure the accuracy of your application.

 

Who we are:

Accenture in the Philippines is a pioneer in Accenture’s global delivery network. Over the past 30 years, we have expanded our capabilities to become a powerhouse company providing end-to-end technology and business services. As part of Accenture’s global footprint in over 120 countries, covering 40-plus industries, we have been working with the biggest companies in the country and around the globe.

 

Innovation, a constant at Accenture, enables us to find new ways to stay ahead of our clients’ challenges. Our inclusive, diverse, and strong culture of equality helps us constantly drive innovation in the workplace. By combining our industry expertise and the deep skills of our people with the latest technologies and our uncompromising high-performance standards, we help organizations grow their business and succeed in the digital age.

 

What’s in it for you?

At Accenture you will work on meaningful and innovative projects, powered by the latest technologies. You’ll be immersed in industry best practices such as event-driven architectures and domain-driven designs.  Accenture will continually invest in your learning and growth. You'll work with Accenture’s certified practitioners, and Accenture will support you in growing your own tech stack and certifications.

Summary:

The SOC Analyst is responsible for monitoring and analyzing security events on an ongoing basis. The role involves investigating and responding to threats in a timely and effective manner, and where necessary, escalating incidents to the appropriate teams for in-depth analysis and/or resolution.

Roles and Responsibilities:

  • Monitors and analyzes Security Information and Event Management (SIEM) to identify security issues for remediation.

  • Recognizes potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information.

  • Evaluates/deconstructs malware (e.g., obfuscated code) through open-source and vendor-provided tools.

  • Communicates alerts to clients regarding intrusions and compromises to their network infrastructure, applications, and operating systems.

  • Prepares briefings and reports of analysis methodology and results.

  • Creates and maintains standard operating procedures and other similar documentation; ensures all documentation is up to date and standard.

  • Generates end-of-shift reports for documentation and knowledge transfer to subsequent analysts on duty.

  • Assists Entry-Level SOC analysts in building stronger skills.

  • Assists Team Leads with reporting, projects, administrative work as needed.

  • Support cyber defense functions to protect organizations from cyber security incidents that have potential to cause negative impact

  • Review suspicious threat activity via logs and security applications to determine the nature of a possible threat

  • Decide necessary remediation actions for a multitude of systems, including but not limited to Operating Systems, network firewalls/routers, AV systems and more

  • Create clear and concise writeups representing the overall summary, analysis, actions taken and recommendations for escalated incidents via a platform ticketing system

  • Validate operations during their shift and contact senior analysts for additional support/escalation

  • Monitor customer requests via their escalated tickets and inform the senior team for additional support

  • Investigate, document, and report on information security issues and emerging trends

  • Incident Response - reporting of cyber security incidents, mitigation advisement, quality review and after action

  • Use SOC monitoring tools and have a working understanding of systems such as, SIEM systems, Intrusion Detection System, Data Loss Prevention, Antivirus System, to review and analyze pre-defined events

  • Provide analysis and identify trends of security log data from a large number of heterogeneous security devices indicative of incidents

  • Suggest and request whitelisting and use case finetuning from Engineering team as applicable

  • Inform parsing issues to SOC Content / Platform Engineering team as applicable

  • Perform basic threat (retro) hunting leveraging an IoC-based approach

Open Positions:

  • Security Delivery Senior Analyst

  • Security Delivery Specialist/Team Lead

  • Security Delivery Associate Manager

  • Security Delivery Manager

Job Qualifications:

  • Minimum of 3 years of relevant experience

  • Experience in ticketing, monitoring systems, and working in a SOC environment.

  • Ability to analyze data, such as logs or packets captures, from various sources within the enterprise and draw conclusions regarding past and future security incidents.

  • Basic knowledge of client-server applications, multi-tier web applications, relational databases, firewalls, VPNs, Endpoint Detection and Response (EDR) and SIEM technologies.

  • Fundamental understanding of computer networking (TCP/IP), knowledge of Windows, Linux, and Information Security.

  • In-depth experience in performing security investigations across different platforms, including OS, networks, cloud, messaging, etc.

  • High-level knowledge of cybersecurity attack, and defense techniques.

  • Experience working with cloud cybersecurity tools.

  • Excellent analytical and problem-solving skills as well as interpersonal skills to interact with clients, team members, and upper management.

  • Proficient in both oral & written communication.

  • Graduate of any college degree in Computer Science or Information Security, or related technical field of expertise.

  • Must be willing to work on a shifting schedule and on site.

Location: Manila/Cebu

#LI-PH

About Accenture

Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent- and innovation-led company with 750,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. We are uniquely able to deliver tangible outcomes because of our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song. These capabilities, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities. Visit us at www.accenture.com

Equal Employment Opportunity Statement


All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law.

Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process.

Accenture is committed to providing veteran employment opportunities to our service men and women.

Accenture

Website: https://accenture.com/

Headquarter Location: Dublin, Dublin, Ireland

Employee Count: 10001+

Year Founded: 1989

IPO Status: Public

Last Funding Type: Grant

Industries: Business Information Systems ⋅ Construction ⋅ Consulting ⋅ Information Services ⋅ Information Technology ⋅ Infrastructure ⋅ Management Consulting ⋅ Outsourcing