Become a pivotal part of our security team as a Senior SIEM, Incident Response, and SecOps Engineer. This role positions you at the heart of our innovation group, driving initiatives around SIEM technology (specifically Splunk), SOAR (Security Orchestration, Automation, and Response), and operational security excellence.
The ideal candidate will have deep technical knowledge across various cybersecurity tools and technologies, solid understanding of information security and networking principles, and extensive experience collaborating with diverse stakeholders. You will act as a Subject Matter Expert (SME) for Splunk Enterprise, helping achieve robust security monitoring and incident response capabilities while improving operational efficiency.
Requirements: Splunk Skills:
Extensive experience with Splunk Enterprise, Splunk Enterprise Security (ES), and Splunk Cloud implementations.
Knowledge of Splunk architecture, clustering, CIM, TSTATS, and operational management.
Ability to create custom SIEM rules, correlations, dashboards, and reports tailored to organizational requirements.
Programming and Automation:
Proficiency in scripting languages, including Python and Bash, for workflow automation and integration development.
Familiarity with REST APIs, SQL, NoSQL databases, and Regular Expressions.
SOAR Implementation:
Experience developing SOAR capabilities such as playbooks, integrations, automated actions, and workflows.
Security Fundamentals:
Strong understanding of cybersecurity principles across host and network layers.
Familiarity with investigative methods, malware analysis techniques, and incident response frameworks.
Experience: Minimum of 4 years in a similar role, demonstrating expertise in SIEM and incident response.
Certifications: Preferred SIEM vendor-related certifications such as Splunk Certified Architect or Splunk Certified Consultant.
Systems Expertise: Experience in Mac, UNIX/Linux environments.
Communication: Strong written and oral communication skills, with the ability to convey complex technical concepts to non-technical stakeholders.
A proactive, self-driven attitude with the ability to work independently or as part of a collaborative team with minimal supervision.
Strong analytical and problem-solving skills to identify risks, reduce false positives, and optimize security workflows.
Passion for improving processes, enhancing tools, and staying updated with industry best practices and security innovations
This position is open to all candidates.