- Company Name
- Chrome Technologies
- Job Title
- CONSULTANT ANALYSTE SÉCURITÉ (SIEM RSA NETWITNESS)
- Job Description
-
**Job Title**
RSA NetWitness SIEM Security Consultant
**Role Summary**
Provide expert consultancy to configure, maintain, and enhance an RSA NetWitness SIEM platform, driving optimal threat detection, incident correlation, and operational efficiency for security teams.
**Expectations**
Assume ownership of SIEM operations, resolve integration issues, add detection models and log sources, tune rules, and document processes. Must bring 3+ years of hands‑on RSA NetWitness experience and a deep understanding of SIEM/SOAR architecture.
**Key Responsibilities**
- Administer and manage the RSA NetWitness SIEM (Logs, Packets, Endpoint, Orchestrator).
- Add, integrate, normalize, and validate log sources; update parsers, feeds, and detection content.
- Tune rules and correlation logic to reduce false positives and improve alert relevance.
- Design, implement, and maintain incident detection models and new log integrations (firewalls, EDR, IDS, application servers, etc.).
- Conduct threat intelligence and vulnerability monitoring; propose and implement detection/automation improvements.
- Author and maintain technical documentation, SOPs, and integration guides.
- Collaborate with SOC analysts for incident analysis, qualification, and escalation.
- Ensure SIEM availability, performance, security, and continuous improvement.
**Required Skills**
- Proven proficiency in RSA NetWitness Platform (Logs, Packets, Endpoint, Orchestrator).
- Minimum 3 years deploying, configuring, and maintaining NetWitness SIEM solutions.
- Strong networking fundamentals (TCP/IP, DNS, HTTP, etc.) and experience with Windows/Linux systems.
- Expertise in threat hunting, forensics, and MITRE ATT&CK framework.
- Experience integrating diverse log sources (firewalls, EDR, IDS, application servers, etc.).
- Deep understanding of SIEM/SOAR architecture, automation, and orchestration.
- Ability to tune rules, reduce false positives, and write detection logic.
- Excellent technical writing, documentation, and communication skills.
- Analytical mindset with strong problem‑solving capabilities.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Cybersecurity, or related field **OR** equivalent professional experience.
- Preferred certifications: Security+, CISSP, CISM, RSA Security Certified Worker (RCW), or similar.