Search by job, company or skills

This job is no longer accepting applications

Job Description

Greetings from TCS!!

Role; Splunk ES

Experience: 6 to 12 years

Location: Hyderabad/Chennai/Bangalore/indore/Mumbai

Job Description:

  • Manage and administer Splunk Enterprise Security (ES), including Data Models, Correlation Searches, Notable Events, Threat Intelligence Framework, Asset & Identity, and Content Management.
  • Design, develop, and tune security detection use cases aligned with the MITRE ATT&CK framework using SPL and Splunk ES correlation searches.
  • Implement and optimize Risk-Based Alerting (RBA), including risk rules, risk modifiers, and detection tuning to reduce false positives and improve alert fidelity.
  • Onboard and normalize security data sources using CIM, troubleshoot data ingestion/parsing issues, and ensure data quality for security analytics.
  • Collaborate with SOC & security teams to enhance detection coverage, validate use cases, and support incident investigations and continuous improvement of the Splunk security platform.

Ideal Candidate Profile

  • Strong foundation in Splunk Platform Engineering.
  • Capable of independently administering Splunk Enterprise Security.
  • Experienced in building high-quality detections using MITRE ATT&CK.
  • Practical understanding of Risk-Based Alerting (RBA) and detection tuning.
  • Able to bridge platform operations with security detection engineering while working closely with SOC teams.

More Info

Job Type:
Industry:
Employment Type:

Job ID: 151360325

Beware of Scammers

We don’t charge money for job offers