Search by job, company or skills

Splunk Architect

Early Applicant
  • Posted 17 hours ago
  • Be among the first 10 applicants

Job Description

Hiring: L4 Active Splunk Enterprise Certified Architect

We're looking for a L4 Active Splunk Enterprise Certified Architect

Key Skills:

  • Lead the assessment of the client's SIEM platform, ensuring thorough evaluation and documentation of its current state.
  • Obtain and review all relevant documentation related to the SIEM deployment, including architecture diagrams, data flow diagrams, process flows, and procedures.
  • Track and report on information security controls and their effectiveness, making recommendations for improvements.
  • Contribute to creating documentation required for ongoing security support and maintenance of Security Platforms
  • Support the Security Assurance function by providing operational requirements for projects.
  • Assist client to make log sources CIM compliant.
  • Analyze the SIEM platform across focus areas following SIEM Assessment Framework, which includes:
  • System Architecture: Evaluate SIEM's system components (forwarders, search heads, indexers, etc.), assess non-functional requirements (availability, scalability, performance, data retention, monitoring), review the health monitoring process, and examine the current integration with the ServiceNow Security Incident Response (SIR) module.
  • Data Management: Evaluate data management processes including data source onboarding and prioritization, data pipelines, log streaming, data quality and normalization, and data enrichment.
  • Use Case Development: Evaluate intake, prioritization, development, and detection-as-code processes.
  • Governance: Evaluate the existing governance framework, operating and interaction models, relevant policies and standards, governing committees and working groups, and training programs.

Required Skills:

  • Active Splunk Enterprise Certified AdministratorArchitect credential.
  • 7+ years of hands-on experience with Splunk ES.
  • Proven experience in managing and leading SIEM assessments with a focus on Splunk.
  • Strong understanding of SIEM system components, data management processes, use case development, and governance frameworks.
  • Strong communication and leadership skills, with the ability to lead a team of consultants and interact effectively with client teams

Please share your profiles at [Confidential Information]

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 152930251

Beware of Scammers

We don’t charge money for job offers