Splunk Cyber Security Solutions Engineer

BCforwardMorrisville, NC
412d$104,000 - $110,885Remote

About The Position

The Splunk Cyber Security Solutions Engineer is responsible for tuning and configuring Splunk Core and Splunk Enterprise Security services. This role involves developing use cases with CISO end users, assisting in the development of advanced security use cases, and participating in the design and implementation of technology solutions to support a Continuous Monitoring Program. The engineer will also provide training and workshops for CISO teams and support incident investigations and systems maintenance during off-hours and weekends.

Requirements

  • Extensive experience (5+ years) in information security operations or related IT functions.
  • Bachelor's Degree in Computer Science, Information Technology, or Information Security (Master's preferred).
  • Strong communication and collaboration skills, both oral and written.
  • Understanding of network protocols, operating systems, applications, and device event telemetry.

Nice To Haves

  • Experience with SAAS- or cloud-hosted Splunk implementation.
  • Understanding of network defense tools (firewall, IPS/IDS, WAF/CDN, etc.).
  • Familiarity with endpoint defense tools (EDR, anti-malware).

Responsibilities

  • Tune and configure Splunk Core and Splunk Enterprise Security services.
  • Develop actionable alerts and workflows for Splunk as a SIEM tool.
  • Create and implement apps and knowledge objects like dashboards, reports, and data models.
  • Collaborate with the Splunk Architect/Admin to promote private knowledge objects to global knowledge objects.
  • Assist and train the CISO Splunk Engineering team on data lifecycle support.
  • Host workshops for CISO teams and analysts on searching and content development.
  • Develop automation to improve efficiency of CISO workflows using Splunk.
  • Create advanced security use cases in Splunk.
  • Develop risk rules and incident rules to alert on significant cyber events.
  • Create custom dashboards for Risk Based Alerting (RBA).
  • Configure incident response and remediation workflows for notable events.
  • Develop custom machine learning models for anomaly detection in alerting.
  • Work with stakeholders to implement and maintain event logging from various systems.

Benefits

  • Major medical insurance
  • Health Savings Account (HSA)
  • Dental insurance
  • Vision insurance
  • Employer-provided group life insurance
  • Voluntary life insurance
  • Short-term disability
  • Long-term disability
  • 401k

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Industry

Professional, Scientific, and Technical Services

Education Level

Bachelor's degree

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service