- Company Name
- Chrome Technologies
- Job Title
- Consultant analyste sécurité - RSA NetWitness
- Job Description
-
**Job Title**
Security Analyst Consultant – RSA NetWitness SIEM
**Role Summary**
Provide expert consultancy to correct, optimize, and extend an RSA NetWitness SIEM deployment. Lead integration of new log sources, development of detection models, tuning of correlation rules, and continual platform enhancement to improve alert relevance and operational efficiency.
**Expectations**
- 3+ years of continuous, hands‑on experience with RSA NetWitness (Log, Packet, Endpoint, Orchestrator).
- Proven ability to deploy, configure, and maintain RSA NetWitness environments.
- Strong analytical mindset with threat‑hunting, forensics, and MITRE ATT&CK expertise.
**Key Responsibilities**
- **SIEM Administration & Management** – Add, integrate, normalize, and validate log sources; update parsers, feeds, and detection content; ensure SIEM availability, performance, and security.
- **Continuous Improvement & Threat Watch** – Monitor emerging threats, RSA feature releases; propose and implement enhancements to detection, correlation, and operational processes; author technical documentation, integration guides, and procedures.
- **Detection & Correlation Tuning** – Refine rules to reduce false positives, improve incident relevance; create and maintain correlation rules and alerts that detect abnormal behaviors.
- **SOC Support** – Collaborate with SOC analysts to analyze, qualify, and triage incidents.
**Required Skills**
- Mastery of RSA NetWitness Platform (Logs, Packets, Endpoint, Orchestrator).
- Deep knowledge of networking, Windows/Linux systems, and protocols (TCP/IP, DNS, HTTP, etc.).
- Expertise in cybersecurity, threat hunting, digital forensics, and MITRE ATT&CK framework.
- Proven experience integrating diverse log sources (firewalls, EDR, IDS, application servers, etc.).
- Understanding of SIEM/SOAR architectures and automation processes.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Relevant certifications (e.g., RSA NetWitness Certified, CISSP, CISM, CCNA/CCNP, CompTIA Security+).