Ensign InfoSecurity

Intern, SIEM Engineer

Ensign InfoSecurity

IndonesiaFull timePosted Aug 3, 2026

Job description

Ensign is hiring !

Key Responsibilities

Assist in integrating new log sources (servers, firewalls, endpoints, cloud services, applications) into the SIEM platform. Use Case / Detection Rule Development : Help build, test, and tune correlation rules, alerts, and detection use cases to identify suspicious or malicious activity. Dashboard & Report Creation : Create and maintain dashboards, visualizations, and reports for security monitoring and compliance purposes.

Alert Triage & Tuning : Support the SOC team in reviewing alerts, reducing false positives, and improving signal-to-noise ratio. Log Parsing & Normalization : Assist with parsing, normalizing, and enriching raw log data so it's usable for analysis. Documentation : Document SIEM configurations, standard operating procedures (SOPs), playbooks, and detection logic.

Incident Support : Assist analysts during security incident investigations by pulling relevant logs/queries from the SIEM. Health Monitoring : Help monitor SIEM system health, data ingestion rates, and license/storage usage. Research : Stay current on emerging threats, MITRE ATT&CK techniques, and translate them into new detection content.

Compliance Support : Assist with audit and compliance log retention/reporting requirements (e.g., PCI-DSS, ISO 27001, SOC 2). Required / Preferred Skills Basic understanding of networking (TCP/IP, DNS, firewalls) and operating systems (Windows/Linux). Familiarity with security concepts: threat detection, incident response, log analysis.

Exposure to at least one SIEM tool (Splunk, QRadar, Sentinel, ELK/Elastic) — coursework, labs, or certs count. Basic scripting/query language skills (SPL, KQL, Python, or regex). Understanding of common attack techniques (phishing, malware, lateral movement) — MITRE ATT&CK familiarity is a plus. Analytical thinking, attention to detail, and good documentation habits.

Currently pursuing a degree in Cybersecurity, Computer Science, IT, or related field. Nice-to-Have Certifications: Security+, CySA+, Splunk Fundamentals, or similar. Experience with cloud security (AWS/Azure/GCP logging). Prior CTF, home lab, or SOC simulation experience. Learning Outcomes for the Intern Hands-on SIEM administration and content development experience.

Real-world exposure to SOC workflows and incident response. Understanding of enterprise logging architecture and detection engineering lifecycle.