Minimum of 2 years experience in Security Operations or related field., At least 3 years of Splunk Administration experience or certification., Over 1 year of experience in Enterprise Security is preferred., Working knowledge of Linux systems and networking concepts..
Key responsibilities:
Perform deployment and configuration of Splunk environments and applications.
Conduct health checks, performance tuning, and troubleshooting within Splunk systems.
Develop and implement security detection capabilities and strategies.
Collaborate with clients and internal teams to improve security and system performance.
Report This Job
Help us maintain the quality of our job listings. If you find any issues with this job post, please let us know.
Select the reason you're reporting this job:
SP6 is a niche technology firm advising organizations on how to best leverage the combination of big data analytics and automation across distinct (3) practice areas: * Cybersecurity Operations and Cyber Risk Management (including automated security compliance and security maturity assessments) * Fraud detection and prevention * IT and DevOps Observability and Site Reliability Each of these distinct domains is supported by SP6 team members with subject matter expertise in their respective disciplines. SP6 provides Professional Services as well as ongoing Co-Managed Services in each of these solution areas. We also assist organizations in their evaluation and acquisition of appropriate technology tools and solutions. SP6 operates across North America and Europe.
Join North America’s top Splunk Services Partner! SP6 is seeking a highly motivated individual to join our growing Co-Managed Services team. Managed Services (MS) Splunk Engineers serve as the subject matter experts in advancing Splunk.
You will work and gain exposure in large multifaceted and intricate customer environments that have a multitude of different technologies. Additionally, you will work in collaboration with the engineers and analysts from SP6 customers to perform a wide array of tasks to ensure systems are secure, compliant, and performant.
How You’ll Drive Success:
Deployment Maturity
Creating quarterly customer maturity roadmaps
Splunk Enterprise and app upgrades (to approved versions)
Installation and configuration of Splunk-certified applications and add-ons
Creating and modifying roles and user group associations
Modifying indexes and data retention policies
On-boarding new data sources
Re-architecture of syslog aggregation for Splunk or extensive modification to syslog configuration
Re-architecture of authentication into Splunk
Expanding log source collection of an existing source type
Participating in Executive Business Reviews (EBRs)
Health & Performance
Deployment health checks & architecture reviews
System performance tuning
Troubleshooting issues within the Splunk environment, including silent log source monitoring
Reducing license usage on data sources
Periodic review of errors/warnings reported by internal Splunk logs
Log normalization (CIM)
Custom script development
Security Expertise
Creating quarterly customer security roadmaps
Implement and maintain detection capabilities across Splunk deployments
Assist customers in developing a comprehensive strategy for effective detection of malicious activity
Coordinate with internal and external teams to improve the accuracy of detection capabilities and implement best practice mitigations and automated response capabilities
Conduct detection gap analyses & customer security workshop calls
Document and communicate detection capabilities and gaps clearly and effectively leveraging multiple industry frameworks including MITRE ATT&CK, the Cyber Kill Chain, and NIST
Advise on data source prioritization
Research and innovate net new mitigation, detection, and response capabilities given input from industry trends, customer feedback, and research
To Be Successful:
2+ years of experience in Security Operations or a related field (MSSP/MDR)
3+ years of Splunk Admin experience or Splunk Admin certification
1+ years of Enterprise Security experience desired
Working knowledge in various distributions of Linux
1+ years of systems administrator, IT operations, or related experience
Good understanding of Networking concepts (OSI layers, network security concepts)
Strong troubleshooting, problem solving, and abstract reasoning abilities