Search Jobs

     


Contract: SIEM/ArcSight/IRP - Business System Analyst / Saudi Arabia

This job has expired or may no longer be taking applications, but other similar jobs are available.
 Click here to shortlist this job 1-CLICK Apply With Employer or Register Now
Added:2020-02-19
Location: Saudi Arabia
Salary:Competitive
Duration:Contract
Apjid3
Education: Minimum bachelor in Computer Science, or Information technology or in similar field.

Concentration: Information Security and Cybersecurity

Minimum experience: atleast 10 years of experience in the field of network security and cybersecurity.

Job Titles: Business System Analyst

 

 

ArcSight/IRP:

 

Candidate shall be fluent in SIEM, Incident Response Platform solution. , should know how to configure and maintain on ArcSight collectors, should be able to manage end devices to make sure they are sending logs to ArcSight collectors.

Candidate shall be able to develop the playbooks in IRP, and manage the IRP components.

 

In addition candidate shall be able to perform following duties:

 

  1. Install, configure, upgrade, maintain and fine tuning of security systems (SIEM, LM solution, TIP, Forensic tools, and IRP) components.
  2. Identify, Develop, implement, and test and fine tune threat cases in ArcSight.
  3. Ensure the system security baselines include sending the security related event logs to security and logging systems.
  4. Send security related events in a format supported by the security system and approved by the security operation team such as CEF, Syslog.
  5. Regularly Provide updated asset inventory (number of devices, device names, device type, Software version, System criticality, IP addresses, system log dictionary etc.)
  6. Respond to cybersecurity incidents & remediate system related security incidents.
 

Network firewall / Intrusion Prevention System (IPS):

 

Candidate shall be capable of installing, configuring, administrating and troubleshooting the network firewall and IPS solution on MPLs network.

 

In addition candidate shall be able to perform following duties:

 

  1. Install, configure and manage network firewalls.
  2. Configure security polices, firewall filters, and security zones in security network environment.
  3. Install the IPS on security network and fine tune the configuration based on network environment.
  4. Establish process and procedures related to all configuration, policies and rules.
  5. Investigate all triggered incidents and provide proper remediation for each incident.
 

Vulnerability management and compliance management:

 

Candidate shall be capable of configuring, managing and troubleshooting the VM and compliance tools (Nessus and Tripwire). Candidate must be skilled in Center of Internet Security (CIS) baseline.

 

In addition candidate shall be able to perform following duties:

 

  1. install, configure and manage VM tool & devices inventory.
  2. Scan the security network on monthly bases, identify security holes and missing security updates and patches.
  3. Based on the scan result, execute and install all needed security updates and patches.
  4. generate and Provide monthly vulnerability reports to management.
  5. Install, configure and manage compliance tool.
  6. scan inventory on weekly bases on security network
  7. implement and modify CIS benchmark in security network.
  8. establish, update, and manage security baseline on monthly bases.
  9. Run security compliance scan on monthly bases, identify compliance gaps on all low end devices.
  10. Based on the scan result, configure and update baseline on each device that is missing security gaps.
  11. Establish process and procedures related to VM and compliance tool.
 

Network Access Control:

 

Candidate shall be capable of installing, configuring and administrating the network access control solution in security network environment.

 

In addition candidate shall be able to perform following duties:

 

  1. Install all necessary hardware & software and configure the NAC solution in security network environment.
  2. Gather list of all devices on the network and establish necessary network access control list.
  3. Manage all permissions required for NAC authentication.
  4. Apply roles and permission for all users who are able to authenticate the devices.
  5. Establish process and procedures related to NAC.
 

Education: Minimum bachelor in Computer Science, or Information technology or in similar field.

Concentration: Information Security and Cybersecurity

Minimum experience: atleast 10 years of experience in the field of network security and cybersecurity.

Job Titles: Business System Analyst

 

 

ArcSight/IRP:

 

Candidate shall be fluent in SIEM, Incident Response Platform solution. , should know how to configure and maintain on ArcSight collectors, should be able to manage end devices to make sure they are sending logs to ArcSight collectors.

Candidate shall be able to develop the playbooks in IRP, and manage the IRP components.

 

In addition candidate shall be able to perform following duties:

 

  1. Install, configure, upgrade, maintain and fine tuning of security systems (SIEM, LM solution, TIP, Forensic tools, and IRP) components.
  2. Identify, Develop, implement, and test and fine tune threat cases in ArcSight.
  3. Ensure the system security baselines include sending the security related event logs to security and logging systems.
  4. Send security related events in a format supported by the security system and approved by the security operation team such as CEF, Syslog.
  5. Regularly Provide updated asset inventory (number of devices, device names, device type, Software version, System criticality, IP addresses, system log dictionary etc.)
  6. Respond to cybersecurity incidents & remediate system related security incidents.
 

Network firewall / Intrusion Prevention System (IPS):

 

Candidate shall be capable of installing, configuring, administrating and troubleshooting the network firewall and IPS solution on MPLs network.

 

In addition candidate shall be able to perform following duties:

 

  1. Install, configure and manage network firewalls.
  2. Configure security polices, firewall filters, and security zones in security network environment.
  3. Install the IPS on security network and fine tune the configuration based on network environment.
  4. Establish process and procedures related to all configuration, policies and rules.
  5. Investigate all triggered incidents and provide proper remediation for each incident.
 

Vulnerability management and compliance management:

 

Candidate shall be capable of configuring, managing and troubleshooting the VM and compliance tools (Nessus and Tripwire). Candidate must be skilled in Center of Internet Security (CIS) baseline.

 

In addition candidate shall be able to perform following duties:

 

  1. install, configure and manage VM tool & devices inventory.
  2. Scan the security network on monthly bases, identify security holes and missing security updates and patches.
  3. Based on the scan result, execute and install all needed security updates and patches.
  4. generate and Provide monthly vulnerability reports to management.
  5. Install, configure and manage compliance tool.
  6. scan inventory on weekly bases on security network
  7. implement and modify CIS benchmark in security network.
  8. establish, update, and manage security baseline on monthly bases.
  9. Run security compliance scan on monthly bases, identify compliance gaps on all low end devices.
  10. Based on the scan result, configure and update baseline on each device that is missing security gaps.
  11. Establish process and procedures related to VM and compliance tool.
 

Network Access Control:

 

Candidate shall be capable of installing, configuring and administrating the network access control solution in security network environment.

 

In addition candidate shall be able to perform following duties:

 

  1. Install all necessary hardware & software and configure the NAC solution in security network environment.
  2. Gather list of all devices on the network and establish necessary network access control list.
  3. Manage all permissions required for NAC authentication.
  4. Apply roles and permission for all users who are able to authenticate the devices.
  5. Establish process and procedures related to NAC.


    How to Apply









    Latest Jobs - contract managerdeputy project managermarine project managerelectrical & automation manager (uk residents only)process engineering managergeophysical leadprocess engineer (senior)quantity surveyor – planning & cost controlbim technician-roads/drainagecommissioning specialist/engineer (ethelene plant)structural leads/4 hana program leadsenior site interior designerff&e designerhse management systems coordinatorsenior road engineersenior structural engineerconstruction site managerdrainage engineerchief surveyorsurveyorlearn arabicstructure inspectorroad inspectortraffic inspectormep inspectorhead of piping engineeringpipeline package managersite coordinator (construction manager, oil & gas)material engineerstructural lead (oil & gas, construction)surface & protection leadcivil project managerproject hsse manager (nebosh)bidding managershes specialist - 1. incident 2. w1a 3. offsitessafety culture headshes systems headlead of security offplotsconstruction management/superintendent services staff engineer operationsprocurement specialistlead quantum engineer / data stewarthse engineer romeautomation managerprincipal mechanical engineere&i plannersr. contracts engineer (projects technical)schedule specialistarea mechanical completion manager - processsenior engineer marine systems
    V
    © All rights reserved, 2001 - 2024