We are seeking SIEM Engineer (Splunk) to support the ongoing
operations and optimization of our Splunk -based log management infrastructure.
These resources will play a critical role in ensuring effective log ingestion,
alerting, dashboarding, and system performance across both on -premises and
cloud environments.
Key Responsibilities (Project -Specific):
1. Splunk
Infrastructure Management: Maintain and optimize Splunk environments
(on -premise and cloud).
2. Ensure
consistent and reliable log ingestion from diverse systems and
applications.
3. Data
Onboarding & Management: Define and implement data onboarding
processes, field extractions, and normalization.
4. Collaborate
with asset -owning teams to ensure forwarder coverage and log
completeness.
5. Alerting
& Dashboards: Create and maintain dashboards and custom SPL queries
for operational visibility.
6. Ensure
accuracy and effectiveness of alerting mechanisms within Splunk.
7. Troubleshooting
& Support: Investigate and resolve issues related to Splunk alerts
and data ingestion.
8. Provide
solutions and recommendations for improving system performance.
9.
Automation
& Documentation: Assist in developing automation tools for efficient
Splunk management.
10. Document
procedures, configurations, and architectural changes.
Education:
- Bachelor’s
degree in Information Security, Computer Science, or a related field. A
Master’s degree in Cybersecurity or Business Management is preferred.
Required Skill Set:
- Proficiency
in Splunk Query Language (SPL) for creating searches, alerts, and
dashboards.
- Experience
with Splunk data onboarding, field extractions, and log normalization.
- Familiarity
with AWS Cloud environments and integration with Splunk.
- General
scripting knowledge (Python preferred) for automation and tooling.
- Strong
troubleshooting skills and ability to resolve complex Splunk -related
issues.
- Experience
collaborating with cross -functional teams in enterprise environments.
- Robust
documentation and communication skills.
- Ability
to manage time effectively and meet operational goals.