Source description
About the role
Implement RBA : Develop and implement RBA strategies within Splunk ES to reduce alert noise and focus on high-fidelity alerts. Develop RBA components : Build and implement actionable alerts, workflow actions, risk incident rules, and risk scores. Create dashboards and reports: Design custom dashboards to visualize risk scores and provide context for analysts. Correlate data: Use Splunk's capabilities to correlate disparate events to identify patterns of risky behavior. Build custom solutions : Develop custom machine learning (ML) models to augment alerting and create automated workflows to improve efficiency. Content Development : Develop advanced security content, including dashboards, reports, and alerts, to highlight risk details, health analysis, and risk suppression specific to RBA environments. Data : Collaborate with application and system owners to onboard new data sources (e.g., from Windows, Linux, cloud services like AWS/Azure) and ensure proper parsing and enrichment for effective analysis within RBA. Correlate various data sources, such as logs from operating systems, applications, and cloud providers, into Splunk to feed RBA models.
More at True Zero Technologies
Related open roles
Zero Trust Lead (R-00179)
New York · Washington DC · Hybrid
SIEM Analyst II (R-00173)
United States · Onsite
Cyber Security Analyst-Senior Level (R-00172)
United States · Onsite
ZScaler Engineer (R-00171)
Remote · United States
Cybersecurity Operations Analyst II (R-00170)
Washington DC · Onsite
Mid Cyber Security Analyst-Intermediate Level (R-00169)
United States · Hybrid
