أبلاي إيدج ابدأ البحث عن عمل

Senior Splunk SIEM Engineer -Managed Services Consultant

FNRCO · Jeddah, Makkah, Saudi Arabia

قدّم وتابع مع أبلاي إيدج
Job Description:5yrs + exp is required. Administration of Splunk Enterprise environment (eg: deployment of solution, user management, managing the licenses, upgrades and patch deployment, addition or deletion of log sources, configuration, management, change management, report management, manage backup and recovery etc.)Onboarding new log sources.Security Use case development using Splunk Enterprise Security, Construction of SIEM content required to produce Content Outputs (e.g., correlation rules, reports, report templates, queries)Manage support tickets with SIEM support, as necessary.Track log sources and perform troubleshooting if the log source is not sending logs to Splunk.Periodically review existing Splunk Configurations and propose any new enhancements as applicable.Continuously review and develop use-cases, dashboards, alerts and reports.Create and add custom correlation rules for devices based on business requirements.Support the audits conducted by the regulators in the Kingdom and provide the relevant evidence from SIEM solution.Develop parsing rules for non-standard logsConfigure threat feeds/IoC’s/Sigma rules/advisories provided by the regulators, if any, as well as global recognized organizations.Administration for Splunk UBA environment.Ingesting CIM-compliant data, raw events, and HR data from the Splunk Platform into Splunk UBA.Managing UBA health using the Splunk UBA Monitoring App and performing backups/failovers