Senior Splunk Engineer
DXC Technology
صاحب عمل نشط
نشرت قبل 3 ساعات
أرسل لي وظائف مثل هذه
الجنسية
أي جنسية
جنس
غير مذكور
عدد الشواغر
1 عدد الشواغر
الوصف الوظيفي
الأدوار والمسؤوليات
Key Responsibilities:
- Design and implement end-to-end Splunk solutions including data ingestion, parsing, indexing, and search optimization.
- Develop and maintain custom correlation rules, alerts, dashboards, and visualizations to support security monitoring and incident response.
- Onboard new log sources from infrastructure, security, application, and cloud systems using best practices (e.g., via UF, HF, syslog, APIs).
- Perform regular health checks, indexer and search head performance tuning, license usage monitoring, and configuration backups.
- Support threat detection initiatives by translating security use cases into actionable Splunk queries and alerts.
- Assist in troubleshooting ingestion failures, parsing errors, and inefficient searches.
- Collaborate with SOC, threat intelligence, and infrastructure teams to ensure data relevance, completeness, and quality.
- Maintain Splunk Enterprise Security (ES) configurations, including CIM compliance, notables, and risk-based alerting (RBA).
- Implement and manage data retention policies and storage utilization in line with compliance requirements.
- Automate tasks and processes using scripts (Python, Bash, PowerShell) and configuration management tools where needed.
- Provide technical guidance and mentoring to junior Splunk engineers and analysts.
Required Skills & Experience:
- 5+ years of hands-on experience in SIEM engineering with at least 3 years focused on Splunk Enterprise or Splunk Cloud.
- Proficient in SPL (Search Processing Language), data onboarding, and CIM normalization.
- Experience integrating diverse log sources including firewalls, endpoints, cloud (AWS, Azure), identity systems, and threat intel feeds.
- Strong understanding of security operations, detection engineering, and incident response workflows.
- Familiarity with Splunk ES, UBA, ITSI, and SOAR (preferred but not mandatory).
- Experience with scripting and automation (Python, Bash, PowerShell).
- Good knowledge of networking, security protocols, and system administration (Windows/Linux).
الملف الشخصي المطلوب للمرشحين
Required Skills & Experience:
- 5+ years of hands-on experience in SIEM engineering with at least 3 years focused on Splunk Enterprise or Splunk Cloud.
- Proficient in SPL (Search Processing Language), data onboarding, and CIM normalization.
- Experience integrating diverse log sources including firewalls, endpoints, cloud (AWS, Azure), identity systems, and threat intel feeds.
- Strong understanding of security operations, detection engineering, and incident response workflows.
- Familiarity with Splunk ES, UBA, ITSI, and SOAR (preferred but not mandatory).
- Experience with scripting and automation (Python, Bash, PowerShell).
- Good knowledge of networking, security protocols, and system administration (Windows/Linux).
القطاع المهني للشركة
- تكنولوجيا المعلومات - خدمات البرمجيات
المجال الوظيفي / القسم
- سوفت وير تقنية المعلومات
الكلمات الرئيسية
- Senior Splunk Engineer
تنويه: نوكري غلف هو مجرد منصة لجمع الباحثين عن عمل وأصحاب العمل معا. وينصح المتقدمون بالبحث في حسن نية صاحب العمل المحتمل بشكل مستقل. نحن لا نؤيد أي طلبات لدفع الأموال وننصح بشدة ضد تبادل المعلومات الشخصية أو المصرفية ذات الصلة. نوصي أيضا زيارة نصائح أمنية للمزيد من المعلومات. إذا كنت تشك في أي احتيال أو سوء تصرف ، راسلنا عبر البريد الإلكتروني abuse@naukrigulf.com