Support the implementation of priority use cases and review and evaluate the effectiveness of deployed use cases.
This engagement will include the following:
• Support use case implementation of CLIENT’s (22) priority use cases
• Assess effectiveness of the current set of (23) use cases for any potential gaps in logic, approach, and coverage
• Support log and data source verification
• Assess component naming and stamp with use case numbers for quick reference (e.g. rules, reports, emails/communications)
• Support QRadar rules review to identify and remove duplicates, disabled or invalid custom rules
Additional Skills:
Security - 7 + years,
Qradar- 5+ years,
SIEM - 5+ years,
Security Operations - 7+ years,