Job Summary
We are looking for a skilled Security Transformation Practitioner with strong experience in Splunk Enterprise, Splunk Enterprise Security (ES), and Splunk UBA. The role involves managing and optimizing the SIEM platform, developing security use cases, and ensuring effective threat detection and monitoring across enterprise environments.
Key Responsibilities
- Administer and support Splunk Enterprise environments including deployment, configuration, upgrades, patching, licensing, and performance management.
- Manage log onboarding, data ingestion, and troubleshooting of log source issues.
- Ensure data quality and CIM compliance across ingested data.
- Develop and maintain Splunk ES security use cases, including correlation searches, dashboards, alerts, and reports.
- Create and tune custom correlation rules to improve threat detection and reduce false positives.
- Integrate and manage threat intelligence feeds, IoCs, Sigma rules, and security advisories.
- Develop parsing rules for non-standard log formats.
- Provide incident and ticket support for SIEM-related issues in production environments.
- Administer Splunk UBA, including data ingestion, system health monitoring, backups, and failover management.
- Support security audits and compliance requirements by providing SIEM evidence and reports.
- Continuously review and enhance Splunk configurations, dashboards, and detection capabilities.
Required Skills & Experience
- 5+ years of experience in SIEM / SOC / Security Engineering roles
- Strong hands-on experience with Splunk Enterprise and Splunk Enterprise Security (ES)
- Experience with Splunk UBA administration
- Strong knowledge of log onboarding, CIM data model, and SPL queries
- Experience in building correlation searches, dashboards, and security alerts
- Knowledge of threat intelligence integration (IoCs, feeds, Sigma rules)
- Strong troubleshooting and analytical skills in SOC environments
- Experience supporting security audits and compliance requirements
Preferred Skills
- Knowledge of MITRE ATT&CK framework
- Splunk certifications (preferred)
- Basic scripting knowledge (Python or SPL automation)
Also, You can forward your CV through below link for more upcoming Job vacancies: https://cv-fnrco.com