Splunk SIEM Security Engineer-100%Remote at Remote, Remote, USA |
Email: [email protected] |
From: Gulshan, Stellent IT [email protected] Reply to: [email protected] Information Security Engineer 100%Remote Phone+Skype 6+Month Job Description We are seeking a candidate to help us grow and improve our Cybersecurity Ops SIEM Engineering team. Our team handles the end-to-end process of onboarding a variety of log sources to the Splunk based SIEM. This function interfaces with many different teams and requires both a wide and deep understanding of several different information technology and cybersecurity concepts and how they function and apply to a corporate enterprise environment. The candidate should have an established background in information security and should have experience with both the configuration and integration of security logs to Splunk in a medium to large organization. The candidate will be assisting the US Cybersecurity Engineering Team in the organizations migration to Splunk Cloud. This entails the configuration of existing log sources using Splunk Universal Forwarder agents and re-configuration of legacy syslog based to point to newly deployed CRIBL ingestion layers. This implies coordinating Change tickets, validating and documenting changes including tracking and reporting of efforts. Duration: Possibility of extensions No opportunity for FTE conversion The candidate will be assisting in the organizations migration to a Splunk Cloud environment which requires experience in a multitude of concepts: 5-10 years of experience *Bilingual in English/Spanish Configuration of Security logs on multiple sources Understanding of Firewall and Network concepts Validation of Security logs in Splunk SIEM/CRIBL Recognizing and identifying issues and creative problem-solving solutions Designing, implementing, and executing testing procedures and documentation/reporting Communicating effectively across several different teams and entities Effective communication as to the status of weekly, monthly, and quarterly project deadlines and deliverables Effective, precise, and detailed documentation in regard to the SIEM integration of log sources The candidate should have experience with the following tools: Splunk (Advanced user-level) and CRIBL (basic) General IT technologies (Windows, Red Hat Linux, Firewalls, Proxy, Databases, AWS (intermediate) JIRA (or any agile based platform) ServiceNow Confluence GitHub collaboration experience Keywords: information technology Splunk SIEM Security Engineer-100%Remote [email protected] |
[email protected] View all |
Thu Aug 29 01:01:00 UTC 2024 |