Splunk Engineer with HLD for SIEM & SOAR implementation & SIEM Location: TCS – Hartford, CT

Role: Splunk Engineer with HLD for SIEM & SOAR implementation & SIEM
Location: TCS – Hartford, CT


Role Description:              1. Understand the customer environment and create HLD for SIEM & SOAR implementation2. Work with cross functional teams in enabling & implementing Splunk SIEM solution & log ingestion from the customer’s Security Stack.3. Enable OOB & custom usecases per customer requirement.4. Good experience in Splunk Query language5. Identity & implement possible automation scenarios leveraging Splunk Phantom.6. Responsible Security event triage and security incidents investigations, including support for forensics analysis.7. Conduct proactive threat and compromise analysis by reviewing reports to understand threat campaign(s) techniques, lateral movements, and extract indicators of compromise (IOCs).8. Lead the team with accountability to ensure overall delivery requirements are met9. Monitor, evaluate, and assist with the maintenance of assigned security systems in accordance with industry best practices to safeguard internal information systems and databases10. Analyze a variety of network and host-based security appliance logs determine the correct remediation actions and escalation paths for each incident.11. Ability to conduct packet analysis and articulate findings in order to fine-tune alerts12. Conduct advanced use case development leveraging all product features (trends + variables + hierarchal architectures, Pattern Discovery)13. Responsible for Security Incident Response and documentation of investigation reports14. Prioritize & determine events that are relevant for immediate action, 15. Maintain an expert understanding of vulnerabilities, response, and mitigation strategies used to support cyber security operations16. Serve as point of escalation for Level 1/2 analysts17. Tune the logging from all security appliances for relevant alerting levels 18. Work closely with all Security Operations staff to ensure 24×7 availability.

Competencies: Digital : Splunk

Experience (Years):         6-8

Essential Skills:  1. Expertise in SIEM & SOAR implementation by understanding the customer environment. 2. Team management with good Information security technical expertise and ability to frontend customer interactions3. Experience in Security Incident Response Lifecycle4. Experience in identifying & enabling SIEM & SOAR functionality using Splunk.5. Experience in defining SOC monitoring usecases and operationalizing them through SOPs, and SIEM based alerts / reports.6. Should understand the functioning of Security Technologies including EDR, Firewalls, Intrusion Prevention, Packet Capture tools, Remote access technologies etc.7. Security incident investigations using Next-Gen AV/ EDR solutions such as CrowdStrike, MS Defender,etc8. Experience in understanding and interpreting Threat intelligence from various external sources including validation of related IOCs in customer environment.9. Should have good conceptual understanding of Windows, Linux operating systems & Networking – TCP/IP Protocol Suite10. Understanding of common network services (web, mail, DNS, FTP, etc.), network vulnerabilities, and network attack patterns11. Possess knowledge and experience in Threat Ecosystem, remediating Malware, Rootkits and Botnets12. Strong analytical and problem solving skills13. Good organization skills to ensure coordination and smooth hand-offs between onshore & offshore/nearshore teams14. Strong communication (verbal and written) and interpersonal skills15. Project Management experience with an ability to mentor the team and meet delivery objectives

Desirable Skills: Certifications preferred – CISSP, GCIH, GCFA, CHFI, CEH, SEC+Experience in custom integrations & automation.Executive briefing & reporting skills with attention to detail

Country:              United States

Branch | City | Location:               TCS – Hartford, CT

HARTFORD

Hartford, CT

Mohd Adil | Talent Acquisition


Teamware Solutions Inc.

2838 E. LONG LAKE ROAD SUITE 210, TROY, MI 48085

M: 469-552-7783 | Mail: [email protected]

Connect me on – Linkedin


logo

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Most Voted
Newest Oldest
Inline Feedbacks
View all comments