Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
EI

Senior Privilege Access Monitoring Implementation Specialist

Expert In Recruitment Solutions
πŸ‡ΊπŸ‡Έ United States
On-site
Senior
1 month ago
  • Splunk
  • Cortex
  • SIEM
  • Incident Response
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV
Our client is seeking aSenior Privilege Access Monitoring Implementation Specialist to design, build, and optimize enterprise-grade privilege access event monitoring and alerting infrastructure, focusing on implementing intelligent correlation logic, SOAR workflows, and alert tuning to enhance security operations maturity and reduce false positives at scale.

Responsibilities & Qualifications

  • Design and implement privilege access event monitoring logic and correlation searches within Splunk, translating security requirements into operational detection rules
  • Develop intelligent alert routing, filtering, suppression, and enrichment logic to optimize alert quality and reduce false positives
  • Build and optimize Splunk correlation searches, Risk-Based Alerting (RBA) rules, and custom alert rules tailored to privilege access monitoring use cases
  • Design, develop, and deploy SOAR workflows and playbooks (Cortex XSOAR/Demisto) to automate incident handling and integrate with ticketing and SIEM platforms
  • Create monitoring dashboards, reports, and metrics to track alert health, tuning effectiveness, and operational KPIs
  • Test implementations against historical datasets and validate alert performance; document all searches, workflows, playbooks, and operational procedures
  • Provide knowledge transfer, training, and runbook development to security operations and incident response teams

Requirements

  • 5–8 years of experience in security operations, SIEM engineering, and privilege access monitoring or related disciplines
  • Advanced proficiency withSplunk, including correlation searches, Risk-Based Alerting, alert tuning, and custom rule development
  • Hands-on experience withSOAR platforms (Cortex XSOAR and/or Demisto) and SOAR playbook development
  • Strong background inPrivileged Access Management (PAM) concepts and enterprise privilege access event detection and monitoring
  • Demonstrated expertise in alert tuning, false positive reduction, and alert enrichment logic design
  • Proven ability to integrate SIEM, SOAR, and ticketing systems; experience with incident handling workflows is essential
  • 1099, C2C, or W2 contract eligibility required

Senior Privilege Access Monitoring Implementation Specialist Β· Expert In Recruitment Solutions

Auto apply with Likeremote