.Associate Director DDIT ISC CSOC OnboardingJob ID: REQ-10023036Date: Sep 26, 2024Location: MexicoSummaryCSOC Engineering will be an integral part of the Novartis Cyber Security Operations Center (CSOC). The CSOC is an advanced global team passionate about the active defense against the most sophisticated cyber threats and attacks. By leveraging various tools and resources, the CSOC Engineer Lead will help to proactively detect, investigate, and mitigate both emerging and persistent threats that pose a risk to Novartis' networks, systems, users, and applications.The main objective of the CSOC Engineering Lead is to design, develop, implement, and manage dataflow pipelines and integrate them with SIEM platforms such as Sentinel and Splunk. The Data onboarded to SIEM will be crucial for CSOC Analysts and the content development and SOAR Engineers to develop monitoring alerts and automation playbooks.Collaboration with internal and external stakeholders, including Novartis' internal teams, external vendors, and Product/Platform engineers, will be a crucial aspect of this role. The CSOC Engineering Lead will work closely with these stakeholders to understand and integrate various data sources. This may involve utilizing services such as Cribl, Syslog NG, Azure Monitoring Agent, Universal Forwarder, etc.Furthermore, the CSOC Engineering Lead will work in close partnership with the CSOC stakeholders, including TDR, THR, Forensic, Content Development, and SOAR teams. Their expertise and collaboration will be instrumental in quickly resolving any data onboarding requests or issues that arise.Overall, the CSOC Engineering Lead role is pivotal in ensuring the proactive defense of Novartis' critical assets, systems, and infrastructure against the ever-evolving landscape of cyber threats.About the RoleMAJOR ACCOUNTABILITIESIn addition to accountabilities listed above in Job Purpose:Lead and manage a geographically distributed team of skilled engineers, providing guidance and support while leveraging their diverse skill sets and personalities.Evaluate and review performance metrics and KPIs to ensure the onboarding team is meeting targets and delivering efficient and effective results.Take accountability for the team's performance in various areas, including but not limited to data onboarding to:SIEM platforms such as Sentinel and SplunkSupporting audit requests and reportsEngaging with product teams to address technical challengesManaging stakeholders' commitmentsAct as the primary point of contact for first-level escalations, addressing any issues or concerns that arise and ensuring timely resolution.Develop and maintain comprehensive documentation to facilitate knowledge sharing and ensure quality outcomes are consistently achieved.Drive a culture of continuous improvement and innovation within the team, identifying opportunities to optimize processes and enhance efficiency