A cybersecurity solutions firm in California is seeking a Splunk SIEM Security Engineer/Architect. The ideal candidate will have over 3 years of experience in architecting and configuring Splunk, along with skills in security analysis and managing a Splunk environment. Responsibilities include onboarding new data sources, configuring correlation searches, and implementing security policies. A great opportunity for those looking to enhance their career in cybersecurity.
Qualifications
3+ years of experience architecting and configuring Splunk.
Ability to manage and optimize the Splunk environment.
Implementing new Correlation Rules and performing security analysis.
Responsibilities
Onboard new data sources to the Splunk environment.
Configuration of Correlation Searches and Dashboard Searches.
3 plus years of experience in Spunk (SIEM) Security Enterprise: architecting, configuring, deploying, and customizing the tool, preferably both in supporting the application and utilizing the application for information security monitoring, incident response, and compliance
Onboard new data sources to the Splunk environment as required by the customer Cybersecurity Team for monitoring by the client SOC
Configuration of Correlation Searches, Dashboard Searches, Risk Modifiers, Threat Intelligence Feeds, Workflow Actions and Enterprise Security content
Validate and Manage all Splunk forwarders reporting into the Splunk environment
Manage and optimize the Splunk environment, Enterprise Security Module and Phantom Module.
Implement new Correlation Rules (Correlation Searches) in the Splunk environment Enterprise Security Module
Ability to perform security analysis, development and implementation of security policies, standards, and guidelines
Perform ongoing development for additional use case and SIEM tuning.
Experience with implementation of Log Management and Analytics products - Splunk