Senior Security Engineer - Splunk Sentinel and Cribl

HELP INFORMATION TECHNOLOGY CONSULTANCY - SOLE PROPRIETORSHIP L.L.C

Dubai

On-site

AED 300,000 - 550,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Job summary

HELP INFORMATION TECHNOLOGY CONSULTANCY - SOLE PROPRIETORSHIP L.L.C. in Dubai seeks an experienced Security Operations Engineer to administer Splunk SIEM and related apps, and to extend these for specialized analytics.

You will integrate Splunk with various data sources, work with application and infrastructure teams, and support Defender ATP, Azure security products, and Nessus/Tenable deployments in a large enterprise environment.

Qualifications

  • 7+ years in Security Operations Center, Managed Security, or client network environment.
  • Experience with SPLUNK SIEM and advanced tuning.
  • Experience with Cribl.
  • Knowledge of EDR and Azure security products.

Responsibilities

  • Administer Splunk and Splunk Apps to develop or extend apps for specialized functionality.
  • Integrate Splunk with a wide variety of legacy data sources.
  • Engage app and infra teams to establish best practices for Splunk data and visualizations.
  • Implement and support Microsoft security technologies and Defender ATP/Azure security products.

Skills

Splunk SIEM
Azure Cloud
Nessus
EDR Carbon Black
Threat Hunting

Tools

Cribl
ArcSight
LogRhythm

Job description

Administering Splunk and Splunk Apps to include developing new or extending existing Apps to perform specialized functionality Integrating Splunk with a wide variety of legacy data sources Engaging application and infrastructure teams to establish best practices for utilizing Splunk data and visualizations Design implement and support solutions with Microsoft security technologies such as Azure Cloud Access Security Broker Office 365Advanced Threat Protection O365 ATP Microsoft Defender ATP and their integrations used to deliver internet-scale intelligence and managed security products Implement administer Microsoft Defender ATP Azure Cloud Access Security Broker Azure Threat Protection security products within customer environment Manage and oversee day-to-day activities of Azure IP platform and ensure adherence to enterprise standards in project execution methodology requirements gathering quality assurance and continuous improvement Handle the implementation deployment support of Nessus scan engines and Tenable Security Center and peripherals with Engineering SOC TIU and IR Maintain local and network credentials Tenable Security Center and provisions access to vulnerability scanning systems Integrate Nessus TSC with other security and IT systems management tools Document vulnerabilities and work on vulnerability mitigation with agreed SLA Managing CB sensors including deployment operation management maintenance update upgrade patching and administration Should be able to create watchlists to detect indicators of compromise IOCs and malicious behavior of new threats Hands on in writing queries in CB to search the desired events Assess customer needs and expectations design solutions to meet those needs and then implement the design Quickly build and solve a problem using a new technology to determine viability Serve as a primary responder for Managed Security customer systems taking ownership of client configuration issues and tracking through resolution

Requirements
  • College degree or equivalent training with experience working in a Security Operations Center, Managed Security, or client network environment.
  • Minimum 7 years of professional experience supporting and maintaining SPLUNK SIEM System.
  • 5-6 years of experience with advanced tuning of Splunk SIEM content.
  • Experience in Cribl.
  • Professional experience working with networks and network architecture.
  • Information security knowledge in one or more areas such as EDR – Enterprise end-point security products (e.g., McAfee e-Policy Orchestrator, Virus Scan, Anti-Spyware, Host Data Loss Protection, Endpoint Encryption, etc.).
  • Practical hands-on experience in EDR (Carbon Black), Vectra, and Microsoft Azure.
  • Splunk, Azure Log analytics, or equivalent big data engine experience.
  • Experience with MS Azure Information Protection and technologies, including solution architecture, deployment, management, and support in a large global enterprise.
  • General security knowledge, certificates on Splunk Admin, Splunk Architect, Splunk Consultant is a must. Also, good to have is Azure, Managed vulnerability (Nessus/Tenable), EDR (Carbon Black) and Firewall related security certifications.
  • Knowledge of Linux and Windows Operating Systems.
  • Experience with various other SIEM security products such as: Splunk, ArcSight, Nitro, or LogRhythm and infrastructure components such as proxies, firewalls, IDS/IPS, and DLP.
  • Experience working with clients in a service delivery function.
  • Shift flexibility, including the ability to provide after-hours support when needed.
  • Experience working with internal and client ticketing and knowledge base systems for Incident and Problem tracking as well as procedures.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Microsoft Defender Suite & Sentinel
Senior Security Engineer - Microsoft Defender Suite & Sentinel

Help AG, an e& enterprise company • Dubai

On-site
AED 300,000 - 520,000
Health insurance
Career progression
Wellness campaigns
+5
Senior Splunk & Azure Security Engineer
Senior Splunk & Azure Security Engineer

HELP INFORMATION TECHNOLOGY CONSULTANCY - SOLE PROPRIETORSHIP L.L.C • Dubai

On-site
AED 300,000 - 550,000
Lead SOC Engineer (SIEM) (CPX)
Lead SOC Engineer (SIEM) (CPX)

CPX • Abu Dhabi

On-site
AED 550,000 - 750,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

MEX Group • Dubai

On-site
Senior Security Engineer - Sentinel & Splunk (Hybrid)
Senior Security Engineer - Sentinel & Splunk (Hybrid)

Help AG, an e& enterprise company • Dubai

On-site
AED 300,000 - 520,000
Health insurance
Career progression
Wellness campaigns
+5
Senior IT Security Operations Engineer (Russian & Sri Lankan Nationals)
Senior IT Security Operations Engineer (Russian & Sri Lankan Nationals)

VaporVM • Dubai

On-site
AED 350,000 - 480,000
Splunk Admin/ Specialist
Splunk Admin/ Specialist

CyberGate Defense L.L.C • Abu Dhabi

On-site
AED 120,000 - 180,000
Senior IT Security Operations Engineer
Senior IT Security Operations Engineer

VaporVM • Dubai

On-site
AED 250,000 - 390,000
Senior SOC Engineer - Azure Defender XDR
Senior SOC Engineer - Azure Defender XDR

CPX • Abu Dhabi Emirate

On-site
AED 320,000 - 520,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

ITHR Technologies Consulting LLC • Dubai

On-site
AED 220,000 - 380,000