T
Splunk Enterprise Security Specialist
Hyderabad, Telangana, India · 全职
抢先申请
- 经验
- 7–10 yrs
- 薪水
- —
- 职位空缺
- 1
- 发布
- 2小时前
- 工作模式
- 在办公室
- 学历
- 任何毕业生
- 合格
- Applicants must be graduates in any discipline with 7 to 10 years of expertise in Splunk Enterprise Security.
- 恢复
- 需要申请
你的工作地点
职位描述
About the Company
Tata Consultancy Services is a leading IT services, consulting, and business solutions provider with over five decades of experience collaborating with some of the world's largest enterprises. Their commitment to innovation and shared expertise aims to bring purposeful transformation to the future.
Job Overview and Responsibilities
- Oversee and maintain the Splunk Enterprise Security (ES) environment, managing core components such as Data Models, Correlation Searches, Notable Events, Threat Intelligence Framework, Asset & Identity, and Content Management.
- Design, develop, and fine-tune security detection use cases based on the MITRE ATT&CK framework, utilizing SPL scripting and Splunk ES correlation searches to enhance threat detection.
- Deploy and enhance Risk-Based Alerting (RBA) mechanisms by crafting risk rules and modifiers, optimizing detection to minimize false positives and maximize alert accuracy.
- Onboard multiple security data sources, ensure proper normalization through the Common Information Model (CIM), address data ingestion and parsing issues, and maintain high-quality data for security analytics.
- Work closely with Security Operations Center (SOC) and security teams to broaden detection capabilities, validate security use cases, assist in incident investigations, and continuously improve the Splunk security platform.
Eligibility and Requirements
- Requires a minimum of 7 to 10 years of professional experience in Splunk Enterprise Security administration and development.
- Must hold a graduate degree from any discipline.
技能
SOC Collaboration
Incident Investigation Support
MITRE ATT&CK framework knowledge
Splunk Enterprise Security administration
SPL scripting
Security detection engineering
Risk-Based Alerting implementation
Security data onboarding and normalization
Common Information Model (CIM)
Data parsing and troubleshooting