Source description
About the role
Key Responsibilities - Monitor and analyze security alerts and events using Splunk SIEM. - Perform incident triage, investigation, and escalation in line with SOC procedures. - Respond to security incidents such as phishing attacks, malware infections, unauthorized access, and suspicious activities. - Conduct log analysis across multiple systems including endpoints, servers, network devices, and cloud environments. - Develop and fine-tune Splunk searches, dashboards, alerts, and correlation rules. - Participate in threat hunting activities to proactively identify hidden threats. - Support the incident response lifecycle (Detection, Analysis, Containment, Eradication, Recovery). - Document incidents, findings, and remediation actions in detail. - Collaborate with internal teams (IT, Network, Security Engineering) for issue resolution. - Stay updated with the latest cybersecurity threats, vulnerabilities, and attack techniques. Required Skills - Hands-on experience with Splunk (log analysis, dashboards, alerting, SPL queries). - Robust understanding of SOC operations and SIEM tools. - Knowledge of incident response processes and procedures. - Familiarity with: - Network protocols (TCP/IP, DNS, HTTP/HTTPS) - Firewalls, IDS/IPS, endpoint security tools - Basic understanding of cybersecurity frameworks and best practices. - Ability to analyze large volumes of logs and identify anomalies. - Strong analytical and problem-solving skills. .
More at KPMG Assurance and Consulting Services