HamburgerMenu
hirist

Job Description

Description :

Key Responsibilities :


- Administer, monitor, and maintain Splunk Enterprise/Splunk Cloud environments, including indexers, search heads, and forwarders.

- Onboard and normalize security and system logs, ensuring accurate parsing, field extractions, and CIM compliance.

- Create and tune dashboards, alerts, reports, and analytics that support security operations and incident response.

- Monitor and troubleshoot Splunk health, performance, and data ingestion issues; perform root cause analysis and resolution.

- Use SPL (Search Processing Language) to build custom searches, use cases, and visualizations.

- Work with SOC engineers and security analysts to refine use cases and support investigations.

- Maintain documentation, runbooks, and standard operating procedures for Splunk operations.

- Participate in platform upgrades, patching, and configuration changes following ITIL/change management practices.

Required Qualifications :


- Bachelors degree in computer science, IT, Cybersecurity, or related field.

- 3-6 years experience in Splunk administration, SIEM operations, or cybersecurity engineering.

- Strong hands-on experience with Splunk Enterprise/Splunk Cloud, including data onboarding and management.

- Proficiency in SPL and building dashboards and reports.

- Experience with log ingestion methods such as UF, HEC, Syslog, DB Connect and data normalization.

- Working knowledge of Linux/Unix and basic networking concepts.

- Solid understanding of cybersecurity fundamentals, including threat detection, incident analysis, and SIEM monitoring.

Preferred Skills :


- Splunk certifications such as Splunk Core Certified Admin, Splunk Enterprise Security Admin, or equivalent.

- Experience with Splunk Enterprise Security (ES), ITSI, or additional SIEM platforms.

- Cloud log ingestion experience (AWS, Azure, GCP).

- Scripting skills (Python, Shell, PowerShell) for automation and custom tasks.

- Familiarity with ITIL frameworks and change management processes.

Why Join Us :


- Opportunity to work with cutting-edge cybersecurity technologies

- Flexible remote work environment

- Learning and certification support

- Exposure to global SIEM and security initiatives


info-icon

Did you find something suspicious?

Similar jobs that you might be interested in