Job Description Experience: 4–8+ years
n Primary Skills:
n n Strong hands-on experience with Splunk Enterprise Security (ES).
n Experience implementing and supporting SIEM platforms, preferably Splunk.
n Good understanding of SOAR platforms (Splunk SOAR preferred; experience with Cortex XSOAR, IBM Resilient, Microsoft Sentinel Automation, or similar products is also acceptable).
n Security use case development and content engineering.
n Detection engineering, correlation searches, dashboards and reporting.
n Incident investigation and threat hunting.
n MITRE ATT&CK; framework, Cyber Kill Chain and SOC processes.
n Log onboarding, parsing, CIM normalisation and data models.
n Experience integrating security products such as Firewalls, EDR, IAM, Cloud and Network Security solutions.
n Solid troubleshooting and customer-facing consulting skills.
n n Preferred Certifications:
n n Splunk Enterprise Security Certified Admin
n Splunk Core Consultant / Power User
n Splunk SOAR certifications (desirable)
n Security+, CEH, CISSP or equivalent (advantage)
n