Get more replies from employers
Send a job-specific resume in minutes.
Russell Tobin is seeking an experienced SIEM Engineer to monitor and optimize Splunk-based security monitoring. The role includes data onboarding, CIM mapping, and proactive issue identification across Windows and Linux sources, devices, and security tools.
Responsibilities cover tuning searches, updating configurations per advisories, and coordinating with IT and Cyber teams to resolve onboarding and performance issues.
Monitor SIEM Server Storage, CPU and Memory Usage and perform necessary action.
Update splunk configurations based on security advisory
SIEM Infra Tuning and Performance Optimization
Monitor SIEM data sources proactively to identify issues in the environment (ex: Index Cluster / Search head cluster issues / etc)
Data Onboarding (Including first level assessment, UAT Testing before live)
Integration numerous logs sources including servers (Windows & Linux), devices and security tools like NAC, PAM, NBAD, IPS DAM, DLP, AV etc.
Data Parser and CIM Mapping Configuration
Troubleshoot, investigate and remediate identified SIEM issues
Monitor and troubleshoot the servers that have stopped reporting
Troubleshooting issues with search scheduler management
Search head tuning and optimization, for missed searches, failed jobs and scheduling searches etc.
Liaise with IT support groups & service providers to resolve outstanding issues such log onboarding (e.g. HF related issue – Core team, source related issue – Cyber team to coordinate)
Reconcile Splunk servers periodically
Update Splunk built documents, whenever there are changes to Splunk deployment architecture
Prepare/update Splunk guide for agent installations