Log Source Onboarding: Assist in integrating new log sources (servers, firewalls, endpoints, cloud services, applications) into the SIEM platform.
Use Case / Detection Rule Development: Help build, test, and tune correlation rules, alerts, and detection use cases to identify suspicious or malicious activity.
Dashboard & Report Creation: Create and maintain dashboards, visualizations, and reports for security monitoring and compliance purposes.
Alert Triage & Tuning: Support the SOC team in reviewing alerts, reducing false positives, and improving signal-to-noise ratio.
Log Parsing & Normalization: Assist with parsing, normalizing, and enriching raw log data so it's usable for analysis.
Documentation: Document SIEM configurations, standard operating procedures (SOPs), playbooks, and detection logic.
Incident Support: Assist analysts during security incident investigations by pulling relevant logs/queries from the SIEM.
Health Monitoring: Help monitor SIEM system health, data ingestion rates, and license/storage usage.
Research: Stay current on emerging threats, MITRE ATT&CK techniques, and translate them into new detection content.
Compliance Support: Assist with audit and compliance log retention/reporting requirements (e.g., PCI-DSS, ISO 27001, SOC 2).
Required / Preferred Skills
Basic understanding of networking (TCP/IP, DNS, firewalls) and operating systems (Windows/Linux).
Familiarity with security concepts: threat detection, incident response, log analysis.
Exposure to at least one SIEM tool (Splunk, QRadar, Sentinel, ELK/Elastic) — coursework, labs, or certs count.
Basic scripting/query language skills (SPL, KQL, Python, or regex).
Understanding of common attack techniques (phishing, malware, lateral movement) — MITRE ATT&CK familiarity is a plus.
Analytical thinking, attention to detail, and good documentation habits.
Currently pursuing a degree in Cybersecurity, Computer Science, IT, or related field.
Nice-to-Have
Certifications: Security+, CySA+, Splunk Fundamentals, or similar.
Experience with cloud security (AWS/Azure/GCP logging).
Prior CTF, home lab, or SOC simulation experience.
Learning Outcomes for the Intern
Hands-on SIEM administration and content development experience.
Real-world exposure to SOC workflows and incident response.
Understanding of enterprise logging architecture and detection engineering lifecycle.