Senior Integration Engineer
Gallant Collective · Sri Lanka
Apply & track with Apply EdgePrimary functionTo articulate and define value-added use cases working with project managers and other skill groupsActively administer and manage different technologies such as Splunk SIEM, rsyslog forwarders and HEC data feeds.Define and document the best practice techniques, processes, templates, and architecture diagrams for use of the broader teamRequired work experienceProvide advice on structure of logs, understanding of logs, custom log ingestion, parser creation, parser validation and use case creationsEducate skill groups and other stakeholders about reports and dashboard abilities to provide value focused outcome. Write, review and maintain the knowledgebase articlesDevise innovative integration of security toolsets that enable automated discovery, remediation, and alerting as a means of improving the security posture while also reducing effortsDesign, configure, integrate and deploy open source and commercial tools to monitor systems and enrich the overall Security capabilityCreate custom parsers; generate custom dashboards and reports, deliver integration activitiesMandatory Qualifications / ExperienceSplunk Admin AND Splunk Cloud Admin Certifications and successfully completed Splunk system Admin and Data Admin coursesAt least five (5) years of security operational management experience (including at least two (2) years on Splunk SIEM and trained in Splunk SIEM, at least one (1) year on Splunk and trained in Splunk or Azure Security Centre)Excellent communication (written and oral) and interpersonal skillsPreferred Qualifications / ExperienceHolds at least a university degree and at minimum two (2) cyber security certificationsDemonstrated experience of scripting i.e., PowerShell, Python, Node.js, PerlTechnical qualification examples – CEH, MCSE (Azure Security Centre), CISSP, CCNP, MCSE