Job Description:
- Manage and administer
Splunk Enterprise Security (ES)
, including Data Models, Correlation Searches, Notable Events, Threat Intelligence Framework, Asset & Identity, and Content Management.
- Design, develop, and tune
security detection use cases
aligned with the
MITRE ATT&CK;
framework using SPL and Splunk ES correlation searches.
- Implement and optimize
Risk-Based Alerting (RBA)
, including risk rules, risk modifiers, and detection tuning to reduce false positives and improve alert fidelity.
- Onboard and normalize security data sources using
CIM
, troubleshoot data ingestion/parsing issues, and ensure data quality for security analytics.
- Collaborate with SOC & security teams to enhance detection coverage, validate use cases, and support incident investigations and continuous improvement of the Splunk security platform.
Ideal Candidate Profile
- Robust foundation in Splunk Platform Engineering.
- Capable of independently administering Splunk Enterprise Security.
- Experienced in building high-quality detections using MITRE ATT&CK.;
- Practical understanding of Risk-Based Alerting (RBA) and detection tuning.
- Able to bridge platform operations with security detection engineering while working closely with SOC teams.
📌 Splunk ES (Hyderabad)
🏢 Tata Consultancy Services
📍 Hyderabad
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.