Source description
About the role
JD: Manage and administer Splunk Enterprise Security (ES), including Data Models, Correlation Searches, Notable Events, Threat Intelligence Framework, Asset & Identity, and Content Management. Design, develop, and tune security detection use cases aligned with the MITRE ATTACK framework using SPL and Splunk ES correlation searches. Implement and optimize Risk-Based Alerting (RBA), including risk rules, risk modifiers, and detection tuning to reduce false positives and improve alert fidelity. Onboard and normalize security data sources using CIM, troubleshoot data ingestion/parsing issues, and ensure data quality for security analytics. Collaborate with SOC & security teams to enhance detection coverage, validate use cases, and support incident investigations and continuous improvement of the Splunk security platform. Strong foundation in Splunk Platform Engineering. Capable of independently administering Splunk Enterprise Security. Experienced in building high-quality detections using MITRE ATT&CK. Practical understanding of Risk-Based Alerting (RBA) and detection tuning. Able to bridge platform operations with security detection engineering while working closely with SOC teams. JD: Manage and administer Splunk Enterprise Security (ES), including Data Models, Correlation Searches, Notable Events, Threat Intelligence Framework, Asset & Identity, and Content Management. Design, develop, and tune security detection use cases aligned with the MITRE ATTACK framework using SPL and Splunk ES correlation searches. Implement and optimize Risk-Based Alerting (RBA), including risk rules, risk modifiers, and detection tuning to reduce false positives and improve alert fidelity. Onboard and normalize security data sources using CIM, troubleshoot data ingestion/parsing issues, and ensure data quality for security analytics. Collaborate with SOC & security teams to enhance detection coverage, validate use cases, and support incident investigations and continuous improvement of the Splunk security platform. Strong foundation in Splunk Platform Engineering. Capable of independently administering Splunk Enterprise Security. Experienced in building high-quality detections using MITRE ATT&CK. Practical understanding of Risk-Based Alerting (RBA) and detection tuning. Able to bridge platform operations with security detection engineering while working closely with SOC teams.
More at Orbus International