|
Key Responsibilities:
|
- Manage Splunk SIEM services within the SOC environment.
- Implement scalable Splunk-based SIEM solutions following best practices.
- Define data ingestion strategies, parsing logic, and correlation rules.
- Onboard new log sources and ensure proper integration with Splunk SIEM.
- Monitor and maintain critical log sources; troubleshoot and resolve issues promptly.
- Optimize telemetry for improved data collection, correlation, and reporting.
- Collaborate with SOC and threat intelligence teams to develop detection use cases.
- Create dashboards, alerts, and reports for proactive threat monitoring.
- Perform system updates, version upgrades, and feature rollouts.
- Ensure CIM compliance, field extractions, and data normalization.
- Maintain SIEM performance and troubleshoot Splunk-related issues.
- Evaluate and deploy Splunk apps and add-ons as needed.
- Document SIEM workflows, configurations, and operational procedures.
- Support continuous process improvements to enhance SOC efficiency. Work cross-functionally with IT, DevOps, and security teams.
|
|
Characteristics:
|
- Profound knowledge and hands-on experience with Splunk SIEM, UEBA and other related technologies like CRIBL.
- Understanding of SOC workflows, MITRE ATT&CK framework, and threat detection methodologies.
- Ability to correlate data across multiple sources to identify patterns and anomalies.
- Strong understanding of cloud and network technologies, essential for efficient log source onboarding.
- Proven technical capabilities in a complex, fast-paced SOC environment.
- Ability to diagnose and troubleshoot log source issues related to cloud and network infrastructures.
- Strong understanding of SOC operations, cybersecurity principles, and best practices.
- Excellent problem-solving skills and the ability to make decisions under pressure.
- Ability to collaborate effectively with a variety of team members, including interfacing with customers to resolve issues.
- High proficiency in written and verbal communication
|