Primary Skills:
Robust hands-on experience with Splunk Enterprise Security (ES).
Experience implementing and supporting SIEM platforms, preferably Splunk.
Positive understanding of SOAR platforms (Splunk SOAR preferred; experience with Cortex XSOAR, IBM Resilient, Microsoft Sentinel Automation, or similar products is also acceptable).
Security use case development and content engineering.
Detection engineering, correlation searches, dashboards and reporting.
Incident investigation and threat hunting.
MITRE ATT&CK; framework, Cyber Kill Chain and SOC processes.
Log onboarding, parsing, CIM normalization and data models.
Experience integrating security products such as Firewalls, EDR, IAM, Cloud and Network Security solutions.
Robust troubleshooting and customer-facing consulting skills.
Preferred Certifications:
Splunk Enterprise Security Certified Admin
Splunk Core Consultant / Power User
Splunk SOAR certifications (desirable)
Security+, CEH, CISSP or equivalent (advantage)