We are seeking an experienced CRIBL SME (Log Forwarding) to join our Cyber Security team. The ideal candidate will have strong expertise in Security Operations Center (SOC) operations, Cribl, Splunk, and security event monitoring. The role involves managing log collection and forwarding, monitoring security events, investigating threats, and supporting incident response activities in a 24x7 SOC environment.
Key Responsibilities
- Monitor and analyze security events in a 24x7 Security Operations Center (SOC) environment.
- Configure, manage, and optimize CRIBL for log routing, filtering, and forwarding.
- Administer and monitor security events using Splunk SIEM.
- Perform threat analysis, threat detection, and security incident investigations.
- Create and maintain Splunk dashboards, alerts, and reports.
- Analyze security logs and correlate events from multiple data sources.
- Develop and implement security use cases for threat detection and monitoring.
- Investigate security alerts and raise incidents through ServiceNow for further action.
- Utilize the MITRE ATT&CK; Framework to identify and analyze cyber threats.
- Identify vulnerabilities, suspicious activities, and potential security breaches.
- Collaborate with security, infrastructure, and application teams to improve security monitoring capabilities.
- Support continuous improvement of security monitoring and incident response processes.
Required Skills
- Robust hands-on experience with CRIBL (Log Forwarding/Log Management).
- Extensive experience with Splunk SIEM.
- Experience working in a 24x7 SOC environment.
- Knowledge of Threat Analysis, Threat Hunting, and Incident Response.
- Experience in Security Event Correlation and Log Analysis.
- Hands-on experience with ServiceNow Incident Management.
- Good understanding of Cyber Security concepts and frameworks.
- Knowledge of MITRE ATT&CK; Framework.
- Experience creating Splunk dashboards, alerts, and reports.