Job Description:
The Information Security and Risk Management (ISRM) organization is seeking a Splunk SIEM Specialist Engineer to join our growing SIEM & Security Analytics team. This candidate will join a team in managing a large hybrid enterprise/cloud deployment of Splunk and Enterprise Security and partnering with our SOC, CIRT, Threat Detection, and Cyber Intel functions to deliver capabilities to improve their ability to defend Thomson Reuters from cyber threats.
Key Responsibilities:
Responsible for monitoring and stability of Splunk, and Enterprise Security SIEM platform
Create and optimize Splunk queries, dashboards and reports to support business and operational needs.
Monitor Splunk workplace health and platform troubleshooting and performance tuning
Splunk optimization by troubleshooting ingestion delays, parsing errors, and search performance issues
Managing Splunk infrastructure in AWS cloud, cloud operations experience is preferred
Onboard recent application and platform logs via syslog, endpoint agents, APIs, Cribl, HEC, DB Connect etc.
Experience in Managing Cribl Stream Deployments, good hands On is expected in managing Cribl Pipelines
Collaborate with our SOC, CIRT, Threat Detection, and Cyber Intel teams on operationalizing use cases within Splunk ES to detect threats
Create and maintain documentation to support SIEM platform
Embedding automation into the deployment and management of the Splunk and Cribl infrastructure and application
Implementation of industry best practices for managing an enterprise scale service and continuously seeking iterative improvements
Facilitate high availability and disaster recovery capabilities
Comfortable operating in a agile, rapid-changing, and innovative environment
An operating style that is collaborative, energetic, and results-oriented
Demonstrates the ability to employ judgment and experience to make rapid, complex decisions.