Descripción del puesto
About The Business
Trust, resilience and security connecting for enduring success and responsible business
With competencies encompassing capital markets, control assurance, contractual exposure and insurance claims, and security services, our RA professionals offer a wealth of experience across a spectrum of industries. This is a great place to build a career and make an impact that really matters.
We help clients address various aspects of Cyber and other strategic risks to their organizations to inform risk-based strategic choices, prepare to respond to disruption, assess and manage full-lifecycle enterprise risks, as well as strategize and respond to risks associated with the reliability and protection of data, associated processes and technology. We provide advisory and managed services to help senior executives spot, assess, manage, and respond to risks and/or catastrophic unforeseen incidents that could undermine their competitive position or jeopardize their critical assets, reputation and/or financial standing.
Our objective is to help clients develop and implement strategies for IT risk management and aim to help clients find the appropriate balance between risk management and cost containment. Our integrated solutions covering: Cyber Strategy, Cyber Security, Cyber Vigilance, Cyber Resilience.
Work you'll do
作为SOC安全工程师,您将负责企业安全运营平台的规划、建设及持续优化,围绕Splunk、ELK等SIEM平台开展日志接入、检测能力建设、安全自动化及平台运维工作,不断提升SOC整体检测能力和运营效率。
主要工作包括:
一、SIEM平台建设与运维
基本要求
SIEM平台
熟悉以下一种或多种平台:
熟悉:
日志采集
熟悉以下一种或多种:
具有以下任意平台安全经验:
安全知识
熟悉:
能够使用以下至少一种语言:
优先条件
满足以下任一条件者优先:
具有以下认证之一优先:
For more than 100 years of history, Deloitte witnessed also had the honor to be part of the economic boom in China by providing industry-leading audit & assurance, consulting, risk advisory, financial advisory, tax & business advisory services to nearly 90% of the Fortune Global 500 Chinese companies and thousands of private companies. Deloitte China today carries on our centenary professionalism and strives to become the undisputed leader in professional services in China with strong responsibility and capabilities in digitalization and multidisciplinary services.
Deloitte has been named China's Top Employer since 2006, Universum's Most Attractive Employer in China since 2008, and the Best Workplaces in Greater China since 2019.
All qualified applicants will receive consideration for employment regardless of their background, experience, identity, ability or thinking style, and if you need assistance during the application process for accessibility reasons this is available upon request. The preferred candidate will be subject to background screening by Deloitte China or by their external third-party provider.
Accessibility assistance
If you need assistance or an accommodation during the recruitment process for accessibility reasons, there will be an opportunity for you to let us know what you need once you begin your application.
Ready to take on new challenges? Apply now!
Stay connected for the latest career opportunities, follow us on Deloitte China Social Media.
Trust, resilience and security connecting for enduring success and responsible business
With competencies encompassing capital markets, control assurance, contractual exposure and insurance claims, and security services, our RA professionals offer a wealth of experience across a spectrum of industries. This is a great place to build a career and make an impact that really matters.
We help clients address various aspects of Cyber and other strategic risks to their organizations to inform risk-based strategic choices, prepare to respond to disruption, assess and manage full-lifecycle enterprise risks, as well as strategize and respond to risks associated with the reliability and protection of data, associated processes and technology. We provide advisory and managed services to help senior executives spot, assess, manage, and respond to risks and/or catastrophic unforeseen incidents that could undermine their competitive position or jeopardize their critical assets, reputation and/or financial standing.
Our objective is to help clients develop and implement strategies for IT risk management and aim to help clients find the appropriate balance between risk management and cost containment. Our integrated solutions covering: Cyber Strategy, Cyber Security, Cyber Vigilance, Cyber Resilience.
Work you'll do
作为SOC安全工程师,您将负责企业安全运营平台的规划、建设及持续优化,围绕Splunk、ELK等SIEM平台开展日志接入、检测能力建设、安全自动化及平台运维工作,不断提升SOC整体检测能力和运营效率。
主要工作包括:
一、SIEM平台建设与运维
- 负责 Splunk Enterprise / Splunk Enterprise Security(ES)平台部署、配置及日常运维
- 负责 ELK(Elasticsearch、Logstash、Kibana)平台建设及维护
- 负责平台升级、性能优化、容量规划及高可用架构维护
- 负责 Heavy Forwarder、Indexer、Search Head、Deployment Server 等组件管理
- 持续优化平台稳定性、可用性及检索性能
- 负责网络设备、服务器、云平台、终端、数据库、业务系统等日志接入
- 编写日志解析规则(Parsing)、字段提取及标准化
- 建立统一日志规范及数据质量检查机制
- 完成 CIM(Common Information Model)字段映射
- 优化日志采集性能及存储策略
- AWS / Azure / 阿里云
- Kubernetes / Docker
- Windows / Linux
- Firewall / WAF / IDS / IPS
- EDR / XDR
- IAM / AD / Entra ID
- 数据库及业务应用
- 设计和开发SOC检测规则(Detection Use Cases)
- 编写Correlation Search、告警规则及风险检测模型
- 持续优化误报率,提高检测准确率
- 基于MITRE ATT&CK框架设计检测能力
- 建立检测内容版本管理及生命周期管理
- 基于Python开发SOC自动化工具
- 对接SOAR平台,实现自动化响应
- 集成威胁情报(Threat Intelligence)
- 开发REST API接口,实现平台联动
- 自动化完成IOC富化、告警关联及工单流转
- 持续优化SOC平台整体性能
- 建立平台监控及健康检查机制
- 编写平台建设文档、Runbook及标准化流程
- 配合威胁狩猎、事件响应及重大安全事件调查
- 支持安全审计及合规检查
基本要求
- 本科及以上学历,网络安全、计算机相关专业
- 一年以上SOC、安全平台或SIEM相关工作经验
- 良好的沟通能力及团队协作能力
- 具备较强的问题分析及解决能力
SIEM平台
熟悉以下一种或多种平台:
- Splunk Enterprise
- Splunk Enterprise Security(ES)
- ELK
- XSIAM
熟悉:
- Linux
- Windows Server
日志采集
熟悉以下一种或多种:
- Syslog
- Splunk Universal Forwarder
- Heavy Forwarder
- Fluent Bit
- Filebeat
- Winlogbeat
具有以下任意平台安全经验:
- AWS
- Microsoft Azure
- Alibaba Cloud
安全知识
熟悉:
- Windows安全日志
- Linux日志
- 网络安全
- MITRE ATT&CK
- 安全事件分析
- SIEM检测逻辑设计
能够使用以下至少一种语言:
- Python
- PowerShell
- Bash
优先条件
满足以下任一条件者优先:
- 有Splunk Enterprise Security项目经验
- 有ELK平台建设经验
- 有Detection Engineering经验
- 有Threat Hunting经验
- 有SOAR平台经验
- 有MISP、OpenCTI等威胁情报平台经验
具有以下认证之一优先:
- Splunk Enterprise Certified Admin
- Splunk Enterprise Security Certified Admin
- Elastic Certified Engineer
- Microsoft SC-200
- Microsoft AZ-500
- AWS Security Specialty
- CISSP
- GCIH
- GCIA
For more than 100 years of history, Deloitte witnessed also had the honor to be part of the economic boom in China by providing industry-leading audit & assurance, consulting, risk advisory, financial advisory, tax & business advisory services to nearly 90% of the Fortune Global 500 Chinese companies and thousands of private companies. Deloitte China today carries on our centenary professionalism and strives to become the undisputed leader in professional services in China with strong responsibility and capabilities in digitalization and multidisciplinary services.
Deloitte has been named China's Top Employer since 2006, Universum's Most Attractive Employer in China since 2008, and the Best Workplaces in Greater China since 2019.
All qualified applicants will receive consideration for employment regardless of their background, experience, identity, ability or thinking style, and if you need assistance during the application process for accessibility reasons this is available upon request. The preferred candidate will be subject to background screening by Deloitte China or by their external third-party provider.
Accessibility assistance
If you need assistance or an accommodation during the recruitment process for accessibility reasons, there will be an opportunity for you to let us know what you need once you begin your application.
Ready to take on new challenges? Apply now!
Stay connected for the latest career opportunities, follow us on Deloitte China Social Media.
¿Listo para aplicar?
Esta oferta fue agregada desde LinkedIn. Al hacer clic serás redirigido al sitio original para completar tu postulación.
Aplicar en la fuente ↗