Job Title: Security Engineer - Splunk Implementation
Location: Charlotte NC / Portland OR
Duration: 9+ Months Contract
Experience Level: 5-7 years
Job Description: - The requirement is to implement Azure Security Controls including EMS, Active Threat Detection and MFA solution.
Must-Have:
- Development of Splunk Knowledge Objects (Saved searches, reports, dashboards, data models, event types, field aliases, field extractions, macros, lookups, tags) to alert on potentially malicious activity or fulfill compliance/policy requirements.
- Understand data feeds of various security tools and logs that feed the SIEM. Ability to identify capabilities, quality issues with feeds, and recommend improvements.
- Perform day to day activities of the content life cycle, including creating new use cases, testing content; tuning, and removing content; and maintain associated documentation.
- Work with the other security functions and product SMEs to identify and resolve gaps within the existing content library.
- Maintain knowledge of the Experian infrastructure and tools understanding how these changes drive adjustments across the content process.
- Development of custom scripts as required to augment default SIEM functionality
Good-to-Have:
- Proficient with Splunk Processing Language (SPL). Able to bridge the gap between cyber threat hunting and SIEM content development.
- Knowledge of programming/scripting fundamentals- including regex.
- Should be able to create Use cases, workflow and data flow documentation
- Exposed to best practice design & Implementation methodology
- Willingness to proactively provide input for improvements
- Experience with Problem and Change Management processes and applications
- Excellent written and verbal communication skills.
- Excellent leadership skills and teamwork skills. Results oriented, high energy, self-motivated.
Responsibilities: - Document current security design and process in Spunk
- Work with security teams and Splunk engineering team to implement Splunk
- Integrate new log sources to Spunk
- Help/Support to speed up the work in security projects
- Help in defining base rule base in Splunk ESM
Disclaimer: This web page contains privileged and confidential information intended only for use by a potential job seeker. If you are not the intended recipient of this information, you are hereby notified that you may not disseminate, copy or take any action based on the contents published here.
Apply by creating/using account