Apply Edge Start your job search

Senior Splunk SIEM Engineer -Managed Services Consultant

FNRCO · Jeddah, Makkah, Saudi Arabia

Apply & track with Apply Edge
Job Description:5yrs + exp is required. Administration of Splunk Enterprise environment (eg: deployment of solution, user management, managing the licenses, upgrades and patch deployment, addition or deletion of log sources, configuration, management, change management, report management, manage backup and recovery etc.)Onboarding new log sources.Security Use case development using Splunk Enterprise Security, Construction of SIEM content required to produce Content Outputs (e.g., correlation rules, reports, report templates, queries)Manage support tickets with SIEM support, as necessary.Track log sources and perform troubleshooting if the log source is not sending logs to Splunk.Periodically review existing Splunk Configurations and propose any new enhancements as applicable.Continuously review and develop use-cases, dashboards, alerts and reports.Create and add custom correlation rules for devices based on business requirements.Support the audits conducted by the regulators in the Kingdom and provide the relevant evidence from SIEM solution.Develop parsing rules for non-standard logsConfigure threat feeds/IoC’s/Sigma rules/advisories provided by the regulators, if any, as well as global recognized organizations.Administration for Splunk UBA environment.Ingesting CIM-compliant data, raw events, and HR data from the Splunk Platform into Splunk UBA.Managing UBA health using the Splunk UBA Monitoring App and performing backups/failovers