Hiring.Camp

Intern, SIEM Engineer

Ensigninfosecurity

·

Yesterday

Location
Indonesia
Type
Internship
Department
Engineering
Seniority
Internship
Source
Workday

Description

Ensign is hiring !

Key Responsibilities

  • Log Source Onboarding: Assist in integrating new log sources (servers, firewalls, endpoints, cloud services, applications) into the SIEM platform.
  • Use Case / Detection Rule Development: Help build, test, and tune correlation rules, alerts, and detection use cases to identify suspicious or malicious activity.
  • Dashboard & Report Creation: Create and maintain dashboards, visualizations, and reports for security monitoring and compliance purposes.
  • Alert Triage & Tuning: Support the SOC team in reviewing alerts, reducing false positives, and improving signal-to-noise ratio.
  • Log Parsing & Normalization: Assist with parsing, normalizing, and enriching raw log data so it's usable for analysis.
  • Documentation: Document SIEM configurations, standard operating procedures (SOPs), playbooks, and detection logic.
  • Incident Support: Assist analysts during security incident investigations by pulling relevant logs/queries from the SIEM.
  • Health Monitoring: Help monitor SIEM system health, data ingestion rates, and license/storage usage.
  • Research: Stay current on emerging threats, MITRE ATT&CK techniques, and translate them into new detection content.
  • Compliance Support: Assist with audit and compliance log retention/reporting requirements (e.g., PCI-DSS, ISO 27001, SOC 2).
     

Required / Preferred Skills

  • Basic understanding of networking (TCP/IP, DNS, firewalls) and operating systems (Windows/Linux).
  • Familiarity with security concepts: threat detection, incident response, log analysis.
  • Exposure to at least one SIEM tool (Splunk, QRadar, Sentinel, ELK/Elastic) — coursework, labs, or certs count.
  • Basic scripting/query language skills (SPL, KQL, Python, or regex).
  • Understanding of common attack techniques (phishing, malware, lateral movement) — MITRE ATT&CK familiarity is a plus.
  • Analytical thinking, attention to detail, and good documentation habits.
  • Currently pursuing a degree in Cybersecurity, Computer Science, IT, or related field.
     

Nice-to-Have

  • Certifications: Security+, CySA+, Splunk Fundamentals, or similar.
  • Experience with cloud security (AWS/Azure/GCP logging).
  • Prior CTF, home lab, or SOC simulation experience.
     

Learning Outcomes for the Intern

  • Hands-on SIEM administration and content development experience.
  • Real-world exposure to SOC workflows and incident response.
  • Understanding of enterprise logging architecture and detection engineering lifecycle.

Skills

PythonAWSAzureGCPLinuxCybersecuritySIEMSOCSplunkTCP/IPComplianceSOC 2ISO 27001