SIEM Architect & Engineer (CISO)

Avaloq Philippines Inc.

Philippines

Hybrid

PHP 1,400,000 - 2,800,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

Avaloq Philippines Inc. is seeking a seasoned Splunk Architect to design, implement, and manage our Splunk infrastructure across on-prem and cloud integrations.

You will deploy indexer and search head clusters, optimize existing deployments, monitor operations, and onboard data sources while collaborating with SecOps and engineering teams. The role requires deep SPL, scripting, and automation expertise, with strong knowledge of Linux/Windows, cloud providers (OCI preferred), and containerized

Qualifications

  • Splunk Architect or Splunk Consultant certification or proven Splunk Professional Services experience.
  • At least 5 years of general work experience as Splunk Architect or higher.
  • Experience in designing and implementing Security Operation Center with Splunk.
  • Strong understanding of all Splunk architecture components to include search head clustering, indexer clustering, deployment server and monitoring console.
  • Strong understanding of SPL.
  • Strong understanding of regular expressions and data pipelines.
  • Knowledge of platform and application automated deployment and version control software e.g. (Git, Terraform) within a physical environment.
  • Knowledge of Security components (Firewall, WAF, Vulnerability scanners, etc…).
  • Knowledge of Cloud Service Providers, preferably OCI.
  • Knowledge of SOAR is highly desirable.
  • Linux system administration skills, preferably RHEL.
  • Windows system administration skills.
  • Knowledge of Kubernetes and containerized architectures.
  • Understanding of network protocols/services and network infrastructures.
  • Ability to troubleshoot, diagnose and solve issues independently.
  • Excellent verbal and written communication skills.
  • Experience as part of a team supporting and maintaining an infrastructure.
  • Calm and logical approach during a critical event.

Responsibilities

  • Design, implement, and manage the Splunk infrastructure.
  • Deploy and manage Splunk indexer clusters and search head clusters.
  • Performing optimization of existing clustered Splunk deployments.
  • Monitor operations of Splunk platform to enable proactive issue identification, response, and resolution.
  • Interact with REST API endpoints.
  • Interact with RBDMS in SQL.
  • Onboard Threat Intelligence feeds and correlate with data.
  • Assist Security Analysts providing them consultancy to leverage the Splunk environment.
  • Drive the operational model transformation of SecOps.

Skills

Splunk architecture
Security operations
SPL
Python
Bash
PowerShell
Git
Terraform
REST API
SQL
OCI
Kubernetes
Linux
Windows

Tools

Git
Terraform
REST API
SQL

Job description

Company Description

Founded and headquartered in Switzerland, Avaloq is continuously expanding its global footprint with around 2,500 colleagues in 12 countries, and more than 170 clients in 35 countries. We are an industry-leading provider of wealth management technology and services for financial institutions around the world, including private banks and wealth managers, investment managers, as well as retail and neo banks. Our research led approach and continual innovation is powered by the passion and creativity of our colleagues.

We are always looking for talented people to join us on our mission to orchestrate the financial ecosystem and democratize access to wealth management. Avaloq offers the opportunity to work closely with some of the world’s leading financial institutions as we jointly develop and shape careers. Championing a collaborative, supportive and flexible work environment empowers our colleagues to reach their full potential.

Job Description
  • Design, implement, and manage the Splunk infrastructure.
  • Deploy and manage Splunk indexer clusters and search head clusters.
  • Performing optimization of existing clustered Splunk deployments.
  • Monitor operations of Splunk platform to enable proactive issue identification, response, and resolution.
  • Integrate Splunk with a wide variety of legacy data sources, industry leading commercial security tools and Cloud Service provider facilities.
    • Build Splunk Technology Add-ons.
    • Build custom script in the following languages (Python, Bash, PowerShell, VBscripts).
    • Build Splunk apps to be deployed on thousands of Splunk Universal Forwarders.
    • Interact with REST API endpoints.
    • Interact with RBDMS in SQL.
  • Effectively and efficiently onboard data sources, create indexes and data model, create CIM compliant data mapping, establish health monitoring and KPIs.
  • Manage Splunk knowledge objects (Apps, Dashboards, Saved Searches, Scheduled Searches, Alerts. etc..)
  • Manage Splunk Role Based Access Control.
  • Design and implement Correlation Searches in Splunk Enterprise Security.
  • Maintain and extend correlation between Asset&Identity and Splunk Enterprise Security framework.
  • Onboard Threat Intelligence feeds and correlate with data.
  • Assist Security Analysts providing them consultancy to leverage the Splunk environment.
  • Drive the operational model transformation of SecOps.
  • Identify technology gaps, security gaps, develop solutions and make recommendations for continuous improvement.
Qualifications
  • Splunk Architect or Splunk Consultant certification or proven Splunk Professional Services experience.
  • At least 5 years of general work experience as Splunk Architect or higher.
  • Experience in designing and implementing Security Operation Center with Splunk.
  • Strong understanding of all Splunk architecture components to include search head clustering, indexer clustering, deployment server and monitoring console.
  • Strong understanding of SPL.
  • Strong understanding of regular expressions and data pipelines.
  • Knowledge of platform and application automated deployment and version control software e.g. (Git, Terraform) within a physical environment.
  • Knowledge of Security components (Firewall, WAF, Vulnerability scanners, etc…).
  • Knowledge of Cloud Service Providers, preferably OCI.
  • Knowledge of SOAR is highly desirable.
  • Linux system administration skills, preferably RHEL.
  • Windows system administration skills.
  • Knowledge of Kubernetes and containerized architectures.
  • Understanding of network protocols/services and network infrastructures.
  • Ability to troubleshoot, diagnose and solve issues independently.
  • Excellent verbal and written communication skills.
  • Experience as part of a team supporting and maintaining an infrastructure.
  • Calm and logical approach during a critical event.
Additional Information

We realize that managing work life balance is a challenge we all face in our daily lives and in order to support with this we are pleased to offer hybrid and flexible working for most of our Avaloqers to maintain work life balance and still continue our fantastic Avaloq culture in our global offices.

In Avaloq we are proud to embrace diversity and understand the success of our business is built on the power of different opinions, we are whole heartedly committed to fostering an equal opportunity environment and inclusive culture where you can be your true authentic self.

We hire, compensate and promote regardless of origin, age, gender identity, sexual orientation or any other fantastic traits that make us all unique, we have done our best to write this advert in an inclusive and neutral way.

#LI-Hybrid

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM Architect And Engineer CISO
SIEM Architect And Engineer CISO

Avaloq • Philippines

Hybrid
PHP 1,200,000 - 2,400,000
Hybrid work model
SIEM Architect & Engineer (CISO)
SIEM Architect & Engineer (CISO)

Avaloq Group • Philippines

Hybrid
PHP 1,200,000 - 1,800,000
Hybrid work
Inclusive culture
SIEM Architect & Engineer (CISO)
SIEM Architect & Engineer (CISO)

Avaloq • Philippines

Hybrid
PHP 1,800,000 - 3,500,000
Java Developer
Java Developer

Avaloq • Makati

Hybrid
PHP 1,808,000 - 2,713,000
Observability Engineer
Observability Engineer

Avaloq • Metro Manila

Hybrid
PHP 1,200,000 - 2,400,000
Senior Splunk SIEM Architect & SecOps Lead
Senior Splunk SIEM Architect & SecOps Lead

Avaloq • Philippines

Hybrid
PHP 1,200,000 - 2,400,000
Hybrid work model
Tech Lead / Senior Software Engineer
Tech Lead / Senior Software Engineer

Avaloq • Makati

Hybrid
PHP 1,800,000 - 3,000,000
Modern Offices
Ownership
Meaningful problems
+3
Expert Software Engineer - Securities Operations
Expert Software Engineer - Securities Operations

Avaloq • Philippines

On-site
CHF 110,000 - 140,000
Hybrid work model
Flexible working
Cloud Security Engineer
Cloud Security Engineer

Avaloq • Metro Manila

Hybrid
PHP 900,000 - 1,500,000
Hybrid work arrangement
Flexible working hours
Inclusive culture
+1
Senior Splunk SIEM Architect — Hybrid & SecOps Expert
Senior Splunk SIEM Architect — Hybrid & SecOps Expert

Avaloq • Philippines

Hybrid
PHP 1,800,000 - 3,500,000