- Strong hands-on experience with Splunk Enterprise Security (ES).
- Experience implementing and supporting SIEM platforms, preferably Splunk.
- Valuable understanding of SOAR platforms (Splunk SOAR preferred; experience with Cortex XSOAR, IBM Resilient, Microsoft Sentinel Automation, or similar products is also acceptable).
- Security use case development and content engineering.
- Detection engineering, correlation searches, dashboards and reporting.
- Incident investigation and threat hunting.
- MITRE ATT&CK; framework, Cyber Kill Chain and SOC processes.
- Log onboarding, parsing, CIM normalization and data models.
- Experience integrating security products such as Firewalls, EDR, IAM, Cloud and Network Security solutions.
- Strong troubleshooting and customer-facing consulting skills.
Preferred Certifications:
- Splunk Enterprise Security Certified Admin
- Splunk Core Consultant / Power User
- Splunk SOAR certifications (desirable)
- Security+, CEH, CISSP or equivalent (advantage)