Upload Button Icon Add office photos
filter salaries All Filters

28 ColorTokens Jobs

Platform Administrator - NextGen SIEM

4-9 years

Bangalore / Bengaluru

1 vacancy

Platform Administrator - NextGen SIEM

ColorTokens

posted 1mon ago

Job Role Insights

Flexible timing

Job Description

    • Deploy, configure, and maintain the NextGen SIEM platform (e.g., Stellar Cyber, Splunk, Sentinel, QRadar, Chronicle, Exabeam etc).
    • Perform regular updates, patches, and upgrades to ensure platform security and functionality.
    • Monitor platform health, performance, and availability, ensuring optimal uptime.
2.Log Source Management
    • Onboard new log sources, ensuring proper data ingestion and parsing from various environments (endpoints, servers, cloud platforms, applications).
    • Troubleshoot and resolve issues related to log ingestion, parsing, and formatting.
    • Maintain log retention policies in alignment with compliance requirements.
3.Rule and Use Case Management
    • Develop, deploy, and fine-tune detection rules, correlation use cases, and alerts.
    • Continuously update use cases based on emerging threats, business needs, or compliance mandates.
    • Collaborate with SMEs and SOC analysts to refine detection capabilities and reduce false positives.
4.Integration and Automation
    • Integrate the SIEM platform with other security tools (EDR, microsegmentation solution, vulnerability scanners, etc.).
    • Design and implement automation workflows for incident detection, investigation, and response.
5.Platform Security and Compliance
    • Enforce platform access control policies, ensuring role-based access and least privilege principles.
    • Ensure the SIEM adheres to regulatory compliance standards (e.g., SOC2, ISO 27001).
    • Conduct regular audits and ensure the platform is free of vulnerabilities.
6.Collaboration and Support
    • Work closely with SOC analysts, threat hunters, and engineers to align the SIEM capabilities with security goals.
    • Provide technical support to users of the SIEM platform.
    • Offer training and documentation for security teams on effective SIEM usage.
    • Be available round the clock in case of any incidents with the platform
7.Performance Monitoring and Optimization
    • Monitor and optimize storage and indexing performance.
    • Proactively identify bottlenecks and improve platform scalability.
    • Generate reports on platform performance and alerting effectiveness.
8.Incident Support
    • Assist the SOC team with root cause analysis and advanced investigations.
    • Ensure forensic data is readily available during incident response.
Education and Certifications:
  • Bachelor s degree in Computer Science, Information Security
  • Relevant certifications such as Splunk Certified Admin, Microsoft Certified: Security Operations Analyst Associate, QRadar Certification, or similar NextGen SIEM certifications are highly desirable along with CISSP
Experience:
  • 8+ years of experience in managing SIEM platforms (traditional or NextGen).
  • Strong hands-on experience with at least one NextGen SIEM platform (e.g., Stellar Cyber, Splunk, Sentinel, Chronicle, Exabeam).
  • Experience with log management, rule creation, and data onboarding.
  • Familiarity with scripting languages (e.g., Python, PowerShell) for automation.
Technical Skills:
  • In-depth understanding of log formats, protocols (e.g., Syslog, JSON, XML), and data pipelines.
  • Proficiency in querying languages (e.g., KQL, SPL, AQL).
  • Experience with integration of SIEMs with security tools like EDR, SOAR, NDR, and threat intelligence platforms.
  • Knowledge of security frameworks such as MITRE ATT&CK, NIST, or CIS.
Soft Skills:
  • Strong analytical and troubleshooting skills.
  • Excellent verbal and written communication skills.
  • Ability to work collaboratively in a fast-paced environment.
Preferred Skills:
  • Familiarity with cloud-based security solutions (e.g., AWS, Azure, Google Cloud).
  • Experience in implementing machine learning or anomaly detection in SIEM use cases.
  • Exposure to SOAR tools (e.g., Palo Alto Cortex XSOAR, Splunk Phantom).
Key Metrics for Success:
  • Uptime and performance of the SIEM platform.
  • Number of new log sources and use cases onboarded.
  • Reduction in false positives and tuning of alerts.
  • Timely resolution of platform-related issues.
  • Alignment of the platform with business and security requirements

Employment Type: Full Time, Permanent

Read full job description

ColorTokens Interview Questions & Tips

Prepare for ColorTokens roles with real interview advice

What people at ColorTokens are saying

What ColorTokens employees are saying about work life

based on 61 employees
79%
89%
75%
86%
Flexible timing
Monday to Friday
No travel
Day Shift
View more insights

ColorTokens Benefits

Submitted by Company
Health
Office Life and Perks
Vacation and Time Off
Career Development
Compensation
Submitted by Employees
Work From Home
Health Insurance
Soft Skill Training
Child care
Team Outings
Education Assistance +6 more
View more benefits

Compare ColorTokens with

Palo Alto Networks

3.9
Compare

FireEye

4.3
Compare

Gen

4.0
Compare

Check Point Software Technologies

3.8
Compare

Trend Micro

4.3
Compare

McAfee

4.0
Compare

Fortinet

4.2
Compare

CrowdStrike

4.1
Compare

CyberArk

3.8
Compare

Proofpoint

4.1
Compare

Aurigo

4.7
Compare

Peel-works

3.7
Compare

Prime Focus Technologies

3.4
Compare

ZIGRAM

3.2
Compare

Yodlee

3.8
Compare

Algonomy

4.0
Compare

Fleetx.io

3.7
Compare

Fingent

4.4
Compare

Bravura Solutions

3.9
Compare

Infiniti Software Solutions

4.6
Compare

Similar Jobs for you

Compliance Specialist at Deloitte

Mumbai

5-9 Yrs

₹ 6.5-16.5 LPA

Principal Information Security Engineer at First American (India) Pvt Ltd

Bangalore / Bengaluru

6-10 Yrs

₹ 20-22 LPA

Director at Leena AI

Gurgaon / Gurugram

10-14 Yrs

₹ 12-16 LPA

Compliance and Regulatory Manager at BT Group

Gurgaon / Gurugram

7-12 Yrs

₹ 14-19 LPA

Compliance and Regulatory Manager at BT e-Serv (India) Pvt. Ltd.

Gurgaon / Gurugram

7-11 Yrs

₹ 12-17 LPA

Director at Minkasu

Coimbatore, Bangalore / Bengaluru

10-20 Yrs

₹ 25-31 LPA

Senior Software Engineer at Bajaj Finserv Ltd.

Pune

5-10 Yrs

₹ 25-30 LPA

Senior Staff Engineer at Nagarro Software Pvt. Ltd

Remote

10-15 Yrs

₹ 30-33 LPA

Senior Manager at NETENRICH TECHNOLOGIES PVT LTD

Hyderabad / Secunderabad, Bangalore / Bengaluru

7-12 Yrs

₹ 12-16 LPA

Senior Associate at RSM Delivery Center Private Limited (India)

Gurgaon / Gurugram

2-4 Yrs

₹ 18-20 LPA

Platform Administrator - NextGen SIEM

4-9 Yrs

Bangalore / Bengaluru

1mon ago·via naukri.com

ColorTokens - Security Analyst - SIEM (1-2 yrs)

1-2 Yrs

19d ago·via hirist.com

Senior SOC Manager

12-15 Yrs

Bangalore / Bengaluru

26d ago·via naukri.com

Principal Client Success

8-10 Yrs

Bangalore / Bengaluru

27d ago·via naukri.com

Technical Recruiter

2-5 Yrs

Bangalore / Bengaluru

27d ago·via naukri.com

Senior Product Marketing Manager

14-15 Yrs

Bangalore / Bengaluru

1mon ago·via naukri.com

Technical Trainer

5-10 Yrs

Bangalore / Bengaluru

1mon ago·via naukri.com

Solution Architect

8-13 Yrs

Bangalore / Bengaluru

1mon ago·via naukri.com
write
Share an Interview