
Cybersecurity Specialist, Splunk Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Tennessee.
• Oversee, install, configure, and maintain Splunk cloud, on-premises, and various SIEM/log management tools.
• Create, audit, and enhance correlation rules while collaborating with ESOC to develop detections.
• Construct and uphold dashboards, reports, alerts, and visual representations.
• Generate and refine SPL queries and oversee knowledge objects management.
• Integrate and manage data sources such as syslog, HEC, forwarders, and APIs.
• Handle deployment servers and forwarders effectively.
• Ensure inputs, reporting, and alerting functions are maintained across Azure and AWS environments.
• Enhance system performance and suggest platform improvements.
• Create scripts and integrations utilizing Python, Bash, and PowerShell.
• Employ workflow automation tools with ServiceNow and other security/infrastructure platforms.
• Utilize regex for parsing, extraction, and automation tasks.
• Document data ingestion procedures and uphold access controls for compliance purposes.
• Establish configuration standards, policies, and procedures.
• Develop metrics to evaluate monitoring effectiveness.
• Address incidents and issues while incorporating changes through change-management processes.
• Train and guide ESOC personnel on SIEM functionalities and best practices.
• Collaborate with analysts and business stakeholders to ensure tools, dashboards, and applications fulfill requirements.
• Communicate effectively with teams and clients.
• Operate across Linux and Windows platforms.
• Leverage networking, workflow, and IT-reporting expertise.
• Bachelor’s Degree along with 5+ years of experience in cybersecurity operations or software analysis/programming, or a master’s degree with 3+ years of relevant experience.
• An additional 4 years of experience may be accepted as a substitute for a degree.
• Proven experience in administering and engineering Splunk.
• Required to obtain the Splunk Core Certified Admin certification within the first 3 months of employment.
• Must achieve the Azure AZ-900: Microsoft Azure Fundamentals certification within 6 months of employment.
• Must acquire the AWS Cloud Practitioner certification within 9 months of employment.
• Flexibility to work varied hours and be available for on-call duties during rotations.
• Must be a US Citizen.
• Flexible working hours.
• On-call availability during rotation periods.
EXL
Reli Group
Second Nature
ASRC Federal
Get handpicked remote jobs straight to your inbox weekly.