Source description
About the role
Implement RBA : Develop and implement RBA strategies within Splunk ES to reduce alert noise and focus on high-fidelity alerts. Develop RBA components : Build and implement actionable alerts, workflow actions, risk incident rules, and risk scores. Create dashboards and reports: Design custom dashboards to visualize risk scores and provide context for analysts. Correlate data: Use Splunk's capabilities to correlate disparate events to identify patterns of risky behavior. Build custom solutions : Develop custom machine learning (ML) models to augment alerting and create automated workflows to improve efficiency. Content Development : Develop advanced security content, including dashboards, reports, and alerts, to highlight risk details, health analysis, and risk suppression specific to RBA environments. Data : Collaborate with application and system owners to onboard new data sources (e.g., from Windows, Linux, cloud services like AWS/Azure) and ensure proper parsing and enrichment for effective analysis within RBA. Correlate various data sources, such as logs from operating systems, applications, and cloud providers, into Splunk to feed RBA models.
More at True Zero Technologies
Related open roles
Cloud/Identity Engineer (R-00183)
New York · Washington DC · Hybrid
Network Operations Lead (R-00182)
New York · Washington DC · Hybrid
API Workflow Developer (R-00180)
Remote · United States
API Senior Engineer (R-00166)
Remote · United States
Splunk Engineer - Consultant Certified / ES Accreditation Required (R-00062)
United States · Onsite
Elastic Engineer with TS Clearance (R-00056)
Las Vegas · Onsite
