Wazuh SOC L1 Monitoring

Job ID: 39911999

Budget: ₹12,500 – ₹37,500 INR

I need a hands-on security specialist to stand up and run Level-1 SOC monitoring with Wazuh. The job centres on installing, configuring, and optimising the Wazuh manager and agents so that I receive meaningful, real-time insight across our mixed Linux and Windows estate.

Scope of work
• Deploy and harden Wazuh components, including agent rollout to all Linux and Windows hosts.
• Collect logs from our servers, user endpoints, and selected cloud services, funnelling everything into Wazuh for correlation.
• Craft and tune detection rules that flag genuine threats while keeping false positives low.
• Build intuitive Kibana/Elastic dashboards so I can visualise alerts, asset status, and overall security posture at a glance.
• Configure alerting workflows and concise incident reports that land in email or Slack the moment a high-priority event fires.
• Map rules and reporting to the specific controls required for PCI-DSS, ISO 27001, and GDPR, showing which alerts satisfy which clauses.
• Provide clear, actionable recommendations for continuous improvement based on trends you observe during the engagement.

Deliverables
1. Working Wazuh deployment with agents enrolled and verified.
2. Custom ruleset and alert thresholds documented in Git or a shared repo.
3. Dashboard pack and reporting templates ready for daily SOC use.
4. Short runbook covering routine checks, rule updates, and compliance mappings.
5. Knowledge-transfer session (video or live) so my team can operate the platform confidently.

I value concise communication, accurate documentation, and secure implementation practices. If you have proven Wazuh experience and can deliver the above end-to-end, I’m ready to get started.