Role Overview
The SIEM Team Lead is responsible for managing the day-to-day SIEM operations team, ensuring platform health, log-source availability, detection quality, timely resolution of technical issues, and effective support to Security Operations Center (SOC) operations.
Key Responsibilities
- Lead and manage the SIEM team, allocating daily operational activities and monitoring delivery.
- Act as the primary technical escalation point for complex SIEM issues.
- Monitor SIEM platform health, log ingestion, connectors, parsing, and data quality.
- Ensure critical log sources are onboarded, available, and continuously monitored.
- Review and manage detection and correlation rules, including tuning and false-positive reduction.
- Coordinate with SOC, infrastructure, cloud, network, and application teams to resolve SIEM-related issues.
- Track team activities, pending tasks, technical issues, and operational milestones.
- Ensure incidents and service requests are resolved within agreed SLA and OLA timelines.
- Review SIEM changes and ensure appropriate testing and implementation.
- Support the onboarding of new log sources, integrations, and security use cases.
- Review technical incidents, identify root causes, and implement corrective actions.
- Maintain SIEM standard operating procedures, runbooks, and technical documentation.
- Support SOC teams during major incidents and provide technical expertise.
- Participate in disaster recovery and business continuity testing to ensure SIEM monitoring continuity.
- Provide regular operational updates and reports to management.
Required Qualifications and Skills
- 5–7+ years of experience in SIEM, SOC, or cybersecurity operations.
- Strong hands-on experience with Microsoft Sentinel or another enterprise SIEM platform.
- Good knowledge of Kusto Query Language (KQL) and log analysis.
- Strong understanding of log ingestion and data connectors, analytics and detection rules, alert tuning, false-positive reduction, data parsing and normalization, SIEM troubleshooting and health monitoring, and use-case development and testing.
- Experience handling technical escalations and coordinating with multiple teams.
- Good understanding of incident, change, and problem management.
- Strong troubleshooting, leadership, and communication skills.
Preferred Qualifications
- Experience with Microsoft Sentinel, Microsoft Defender XDR, Microsoft Entra ID, and Azure security.
- Knowledge of SOAR, Automation Rules, Logic Apps, and Playbooks.
- Experience with Splunk, QRadar, ArcSight, or Trellix.
- Knowledge of MITRE ATT&CK, threat hunting, and threat intelligence.
- Experience with SIEM migration or onboarding projects.
- Knowledge of SIEM cost optimization and ingestion monitoring.
Preferred Certifications
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- GIAC Certified Incident Handler (GCIH) or GIAC Certified Intrusion Analyst (GCIA)
- ITIL 4
Key Performance Indicators
- SIEM platform and log-source availability.
- Timely resolution of technical escalations.
- SLA and OLA compliance.
- Successful onboarding of log sources and integrations.
- Improved detection quality and reduced false positives.
- Timely delivery of SIEM use cases and operational tasks.
- Reduction in recurring SIEM issues.
- Effective team performance and operational reporting.