Stand out for this role — generate a tailored resume and cover letter in about a minute.
PT Karya Solusi Prima Sejahtera is seeking a SOC Platform Engineer to own architecture, maintenance, and health of security platforms. You will design high-volume log pipelines and build API integrations to automate incident workflows.
The ideal candidate has 5–7 years in Infra/DevOps, with 3+ years in Splunk ES environments, and strong Linux/Windows, Python, and IaC skills. This role is based in Jakarta, with a focus on 24/7 platform availability.
Manage the full lifecycle of SOC platforms (SIEM, SOAR, EDR, TIP) including architecture, maintenance (patching), and health monitoring. Design and manage high-volume log data processing pipelines (cloud, network, endpoint) to ensure consistent parsing and formatting. Build custom API integration scripts to connect various security platforms and automate incident handling workflows (playbooks). Ensure efficient query performance, optimize log storage (retention/tiering), and implement data model integrations aligned with standards (CIM/RBA). Ensure 24/7 SOC platform operation by implementing backup strategies, disaster recovery, and redundancy management.
Key responsibilities
Manage full lifecycle of SOC platform (SIEM, SOAR, EDR, TIP) from architecture, maintenance (patching), to health monitoring
Design and manage high-volume log data processing pipelines (cloud, network, endpoint) for consistent parsing and formatting
Build custom API integration scripts to connect security platforms and automate incident handling workflows (playbooks)
Ensure efficient query performance and optimize log storage (retention/tiering)
Implement data model integrations aligned with standards (CIM/RBA)
Implement backup strategies, disaster recovery, and redundancy management for 24/7 platform operation
About you
Minimum 5–7 years of experience in Infrastructure Engineering, DevOps, Cloud Architecture, or Enterprise Systems Administration
Minimum 3+ years of specific experience designing, deploying, and managing large-scale Splunk environments (including Splunk Enterprise Security / ES)
Proven experience managing large-volume log data processing architecture (multi-terabyte per day)
Proficiency in Linux operating system administration (RHEL/Ubuntu) and Windows Server
Proficiency in programming/scripting languages for automation: Python, Bash, or Go, and REST API integration (JSON/XML)
Strong understanding of DevOps & Infrastructure as Code (IaC) using Terraform, Ansible, Docker, or Kubernetes
Experience in Splunk ES optimization: Data Model Acceleration (DMA), Common Information Model (CIM), and license savings/log filtering (e.g., Cribl Stream, Heavy Forwarder)
Splunk certifications (Splunk Enterprise Certified Architect, Splunk Core Certified Consultant, or Splunk Enterprise Security Certified Admin) – valued
Infrastructure/security certifications (CISSP, AWS Certified Solutions Architect, or Azure Solutions Architect) – valued