L3 SIEM Admin
Skills
About This Role
Job Purpose
To lead the administration, configuration, optimization, and advanced operations of the organization’s SIEM platforms, primarily supporting Splunk SIEM, while also supporting environments utilizing other SIEM technologies such as QRadar and ArcSight, ensuring effective log ingestion, attack detection, threat analysis, incident investigation support, and continuous improvement of SOC monitoring capabilities, including coordination across teams and support for SIEM platform transition or migration activities when required
Key Responsibilities
- Administer, configure, maintain, and optimize enterprise SIEM platforms in production environments.
- Perform SIEM architecture tuning, performance optimization, and capacity management.
- Configure and maintain correlation rules, alerts, dashboards, and detection policies to support advanced threat detection.
- Lead onboarding, parsing, normalization, and ingestion of logs from infrastructure, applications, endpoints, network, and cloud services.
- Perform advanced log and attack analysis to support threat detection and SOC investigations.
- Act as escalation point for complex incidents requiring deep log and platform analysis.
- Support incident response activities by providing log intelligence and assisting investigation and forensic activities when required.
- Troubleshoot SIEM platform issues and support operational problem resolution.
- Coordinate investigations and operational activities across SOC, Incident Response, Vulnerability Management, Infrastructure, and application teams.
- Develop automation scripts and integrations using scripting languages to improve SOC operational efficiency.
- Support SIEM platform transition or migration initiatives including data source onboarding, validation, and detection use case alignment.
- Ensure SIEM platform availability, scalability, and storage efficiency.
- Maintain technical documentation, operational procedures, and configuration standards.
- Support audit, compliance, and regulatory monitoring requirements through log analysis and reporting
Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, IT or related field.
• Splunk Cybersecurity Defense Analyst
- CISSP, GCIH, GCIA, or equivalent GIAC certifications
- GSEC or SOC-related certifications
- Years of Experience
- 5 to 7 years of experience in cybersecurity operations with at least 3+ years of hands-on experience administering Splunk SIEM platforms.
- Nature of
Experience
- SOC operations and incident investigation experience
- Enterprise SIEM operations in production environments
- Coordination with infrastructure and security teams
- Experience in regulated/compliance environments
Skills
- Log and attack analysis using Splunk, QRadar, or ArcSight
- SIEM management and configuration for performance tuning and advanced threat detection
- Troubleshooting, incident coordination, and collaboration with SOC teams
- Threat analysis and incident response support using forensic investigation techniques
- Scripting and programming knowledge (Python, Bash, PowerShell)
- Log onboarding, parsing, and normalization
- Correlation rule and detection use case development
- Knowledge of threat detection frameworks such as MITRE ATT&CK
- Experience handling network, endpoint, cloud, and application logs
- Strong analytical and troubleshooting skills
Skills
- English and/or Arabic language skills (written and spoken)
Your resume, rewritten
for this exact role.
Sign up free — Base Career tailors your CV to this job description in 60 seconds.
01 / 05
Resume Tailored to This Job

Your keywords, structure, and story — rewritten to match this exact role and pass ATS filters.
Free · No card · 60 seconds
02 / 05
Cover Letter for This Role, Done

Job-specific cover letters written in Gulf professional tone — ready in seconds, not hours.
Free · No card · 60 seconds
03 / 05
See How Well You Fit This Role

AI match score with clear reasons — know your fit before investing time in the application.
Free · No card · 60 seconds
04 / 05
Apply in One Click

Autofill any application form on Workday, LinkedIn, Bayt, Greenhouse — with your tailored content.
Free · No card · 60 seconds
05 / 05
Track It. Follow Up at the Right Time.

Visual pipeline for every application with AI-timed follow-up reminders so nothing slips.
Free · No card · 60 seconds
2.2K+
Cover Letters & Follow-ups
1.8K+
Resumes Tailored
190.5K+
Jobs Tracked
Trusted by professionals at
Stop applying blindly.
Start getting hired.
Base Career automates the hardest parts of job searching — apply smarter, not harder.
AI Resume in 60s
Your resume rewritten for this exact role using the job description as the brief.
ATS-Optimized
Get past automated screening filters with the right keywords matched to each job.
Application Tracker
Track every job, follow-up, and interview in one visual kanban board.
Free plan · No credit card required