Home

Cloud Security SME specialized in Splunk ES and XSOAR, Network Security SME at Remote, Remote, USA
Email: [email protected]
From:

Shikha,

KPG99

[email protected]

Reply to:   [email protected]

Hi,

Hope you are doing well.

Please find the job description below and let me know your interest.

Position:

 Cloud Security SME specialized in Splunk ES and XSOAR / Network Security SME

Visa: USC or GC Only

 Location: Remote

Duration: 6+ Month

MOI:  Phone and Video 

Cloud Security SME specialized in Splunk ES and XSOAR Splunk skillset

Requirements:-

Strong hands-on working experience in Splunk Installation and UNIX

management, Splunk architecture and components including search heads,

indexers and forwarders.

Installed, configured, and maintained Splunk Add ons and Apps such

as but not limited to:

Splunk Add-On for AWS, Splunk Add-On for Windows, and Google

Workspace for Splunk.

Creation of new dashboards, reports or analytics

 Managed a clustered environment with multiple indexers and search

heads.

  Administered both Splunk Enterprise and Splunk Enterprise Security.

  Worked closely with various Security and Platform Engineering teams

to onboard new data from various sources.

 Creation of new alerts, custom rules.

 Maintaining the security of splunk and its related components and

indexes Maintaining current patch levels for all splunk components including

the Linux host OS patching and upgrading

 Performing major version upgrades including the Linux host OS,

Splunk components as necessary

 Troubleshooting and resolving splunk issues as necessary

 Candidates with Splunk Enterprise Security Certified Admin or Splunk

Certified Cybersecurity Defense Analyst certification will be preferred.

XSOAR skillset Requirements:

Experience in XSOAR with ability to configure existing and/or

create new Incident Types, Incident Fields, Classifications & Mappings

Ability to build new or modify existing Playbooks, including

implementation of Generic Polling and similar tasks

Ability to configure and manage Threat Intelligence Management (TIM)

features in XSOAR

Custom Skills:

At least 5+ years of experience in the IT industry with strong

technical knowledge on AWS Infrastructure & security services (EC2, ELB,

Guardduty, Conf

Hands on experience in terraform IaC deployments and ability to

implement security automation.

Strong experience working on enterprise security solutions such as

WAF, IPS, DDOS, and SIEM.

Good technical experience managing products like Splunk enterprise

security, Tenable Nessus, PaloAlto firewall, Cortex XSOAR.

 Good understanding of security controls related to regulatory

requirements, such as NIST, PCI, ISO 27001, HIPAA compliance etc

Architecture certification (Google, Amazon, Azure) from a major

cloud platform.

Information Security Certification is a plus: ISO 27001, CISSP or

CISM or other equivalent.

Experience working on FedRamp compliant projects is a plus.

What You Bring To The Team:

Can work autonomously, deliver with minimal supervision from a

set of requirements

Demonstrated ability to think strategically about business, product,

and technical challenges

Has excellent communication skills to work as a member of a team

Ability to function in an agile-based environment and provide good

daily feedback on team stand-up call Good communication skills verbal /

written

Deliverables:

-Process Flows

 -Mentor and Knowledge transfer to client project team members

 -Participate as primary, co and/or contributing author on any and

all project deliverables associated with their assigned areas of
responsibility

-Participate in data conversion and data maintenance

-Provide best practice and industry specific solutions -

  Advise on and provide alternative (out of the box) solutions

-Provide thought leadership as well as hands on technical

 configuration/development as needed.

 -Participate as a team member of the functional team

  -Perform other duties as assigned.

Keywords: information technology green card Colorado
[email protected]
View all
Thu Aug 31 21:35:00 UTC 2023

To remove this job post send "job_kill 592852" as subject from [email protected] to [email protected]. Do not write anything extra in the subject line as this is a automatic system which will not work otherwise.


Your reply to [email protected] -
To       

Subject   
Message -

Your email id:

Captcha Image:
Captcha Code:


Pages not loading, taking too much time to load, server timeout or unavailable, or any other issues please contact admin at [email protected]
Time Taken: 0

Location: ,