Job Summary
We are seeking a SIEM Analyst to support Cyber Detect foundational capabilities, including centralized logging and monitoring, using CrowdStrike Falcon Next-Gen SIEM and ONUM. The role will support the migration of log sources from existing platforms such as Splunk Cloud, CRIBL, and Syslog-NG to CrowdStrike Falcon Next-Gen SIEM. The analyst will be responsible for log source migration, data validation, monitoring, parsing validation, and ensuring complete and accurate security log coverage.
Key Responsibilities
• Support data bifurcation from the existing SIEM environment to CrowdStrike Falcon Next-Gen SIEM to facilitate migration activities.
• Coordinate implementation of requirements for data bifurcation and log source migration.
• Coordinate validation of network bandwidth and proxy capacity requirements supporting log data bifurcation from the ingestion layer to CrowdStrike Falcon Next-Gen SIEM.
• Monitor potential log outages and maintain visibility into log sources reporting to the SIEM.
• Validate that required log data is properly migrated and meets applicable security and compliance requirements.
• Analyze log source data to confirm parsing rules are functioning as expected.
• Validate required log fields and ensure applicable Common Information Model (CIM) compliance.
• Support centralized logging and monitoring operations across US SIEM environments.
• Work with security and technology teams to troubleshoot log ingestion, parsing, and monitoring issues.
• Support onboarding and configuration of log sources across SIEM and centralized logging environments.
Required Qualifications
• Experience with CrowdStrike Falcon Next-Gen SIEM, ONUM, and Splunk Enterprise Security (ES) in SIEM, security monitoring, log onboarding, and centralized logging environments.
• Experience with SIEM environments and common IT and security technologies such as CrowdStrike Falcon, ONUM, CRIBL, firewalls, proxy, DNS, VPN, Active Directory, Windows, and Linux.
• Experience implementing and configuring log sources to report to SIEM and centralized logging and monitoring solutions.
• Experience with platforms such as Splunk, CRIBL, Syslog-NG, or equivalent logging and SIEM technologies.
• Knowledge of log source onboarding, logging requirements, monitoring, parsing, and data validation.
• Familiarity with Jira, ServiceNow CMDB, and Confluence.
• Familiarity with the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
• Familiarity with the Federal Financial Institutions Examination Council (FFIEC) Cybersecurity Assessment Tool (CAT).
• Strong analytical and troubleshooting skills with the ability to validate log completeness, data quality, and required fields.
• Strong communication and collaboration skills.
Preferred Qualifications
• Experience supporting SIEM migration or modernization initiatives.
• Experience working with large-scale centralized logging and monitoring environments.
• Experience validating log volume, event types, enriched fields, and parsing accuracy.
• Experience working in banking or financial services environments.
• Knowledge of security monitoring and cyber detection processes.