Skill: Splunk
Experience Range: 5+ years
Joining Location: PAN India
We are currently planning to do a Walk-In Interview on 22nd November 2025 at TCS Chennai.
WALK IN DATE 22nd November 2025 (Saturday)
WALK IN LOCATION - Chennai/ Bangalore/ Hyderabad
Job Description:
Required Skills
- Strong understanding of log management and SIEM concepts.
- Proficiency in log source onboarding, parsing, and CIM compliance.
- Experience in content development (correlation rules, dashboards, alerts) and tuning.
- Solid troubleshooting skills for both Splunk platform and security content.
- Experience with Splunk administration, deployment, and health monitoring.
- Familiarity with SIEM optimization techniques and best practices.
- Ability to conduct gap analysis and develop actionable recommendations.
- Excellent communication and documentation skills.
- Relevant certifications (e.g., Splunk Certified Admin, Splunk Certified Architect) are a plus.
Good-to-Have:
- Splunk Certified Admin, Splunk Certified Architect) are a plus.
Roles and Responsibilities:
- Implement and configure Splunk SIEM solutions tailored to organizational security requirements.
- Onboard diverse log sources into Splunk, ensuring data is parsed and normalized according to the Common Information Model (CIM).
- Develop and maintain data models, field extractions, and event parsing logic.
- Design, develop, and tune detection rules, correlation searches, dashboards, and alerts.
- Continuously optimize content to reduce false positives and improve detection accuracy.
- Monitor and maintain the health, availability, and scalability of the Splunk environment.
- Perform regular platform optimization, including indexing, storage management, and search performance tuning.
- Administer Splunk components (indexers, search heads, forwarders, etc.) and manage upgrades/patches.
- Collaborate with stakeholders to ensure successful delivery of security monitoring capabilities.
- Conduct log source and use case gap analysis to identify coverage gaps and recommend enhancements.
- Work with security teams to develop new use cases aligned with evolving threat landscapes.