Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
EI

Senior Privilege Access Monitoring Implementation Specialist

Expert In Recruitment Solutions
πŸ‡ΊπŸ‡Έ United States
On-site
Senior
1 month ago
  • Splunk
  • Cortex
  • SIEM
  • Incident Response
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV


Title: Senior Privilege Access Monitoring Implementation Specialist
Location: Remote
Work Arrangement: Remote
Duration: 12-Month Contract
Experience Range: 5-8 years

Our client is seeking a Senior Privilege Access Monitoring Implementation Specialist to design, build, and optimize enterprise-grade privilege access event monitoring and alerting infrastructure, focusing on implementing intelligent correlation logic, SOAR workflows, and alert tuning to enhance security operations maturity and reduce false positives at scale.

Responsibilities & Qualifications

Design and implement privilege access event monitoring logic and correlation searches within Splunk, translating security requirements into operational detection rules
Develop intelligent alert routing, filtering, suppression, and enrichment logic to optimize alert quality and reduce false positives
Build and optimize Splunk correlation searches, Risk-Based Alerting (RBA) rules, and custom alert rules tailored to privilege access monitoring use cases
Design, develop, and deploy SOAR workflows and playbooks (Cortex XSOAR/Demisto) to automate incident handling and integrate with ticketing and SIEM platforms
Create monitoring dashboards, reports, and metrics to track alert health, tuning effectiveness, and operational KPIs
Test implementations against historical datasets and validate alert performance; document all searches, workflows, playbooks, and operational procedures
Provide knowledge transfer, training, and runbook development to security operations and incident response teams
Requirements

5–8 years of experience in security operations, SIEM engineering, and privilege access monitoring or related disciplines
Advanced proficiency with Splunk, including correlation searches, Risk-Based Alerting, alert tuning, and custom rule development
Hands-on experience with SOAR platforms (Cortex XSOAR and/or Demisto) and SOAR playbook development
Strong background in Privileged Access Management (PAM) concepts and enterprise privilege access event detection and monitoring
Demonstrated expertise in alert tuning, false positive reduction, and alert enrichment logic design
Proven ability to integrate SIEM, SOAR, and ticketing systems; experience with incident handling workflows is essential

Senior Privilege Access Monitoring Implementation Specialist Β· Expert In Recruitment Solutions

Auto apply with Likeremote