Role & responsibilities
- Minimum of 5-8 years of prior experience in SIEM Technologies, Information Security Expertise in SIEM solutions like Splunk Tool.
- Expertise in building use cases around NIST and MITRE ATT&CK; framework to enable detection at various stages of a cyber attack.
- Implementation of use cases using SPL/KQL with complex correlation across different data sources.
- Development of dashboards/workbooks, alerts.
- Implementation of SOAR workflows using Logic Apps, Phantom, Demisto etc.
- Scripting knowledge of python is an added advantage.
- Assist in administration, maintenance and optimization of the Splunk Enterprise and Splunk ES.
- Integrating log sources with Sentinel using REST API.
- Working knowledge in Azure services like Security center, azure monitor, log analytics, NSG,Storage, Azure Functions,defender ATP, etc.
- Experience of threat intelligence and threat hunting is added advantage.
📌 Senior Associate - Cyber Security SIEM Splunk (Hyderabad)
🏢 PwC
📍 Hyderabad