NC
Splunk SME
NR Consulting - India
๐ฎ๐ณ India
On-site
2 months ago
- Splunk
- SIEM
- Windows
- Linux
- Incident Response
- Python
- PowerShell
- AWS
- Azure
- GCP
2 months ago
Location: Chennai
Exp: 5+ Years
Job Description:
Key Responsibilities
- Design, implement, administer, and optimizeSplunk Enterprise andSplunk Enterprise Security (ES) environments.
- Develop and maintain dashboards, reports, alerts, and visualizations usingSPL (Search Processing Language).
- Integrate logs from various sources, including servers, network devices, cloud platforms, applications, and security tools.
- Build and maintain correlation searches, notable events, and detection use cases for security monitoring.
- Monitor system performance, troubleshoot issues, and optimize Splunk indexing and search efficiency.
- Support incident investigation, root cause analysis, and threat detection activities.
- Configure data onboarding, parsing, indexing, forwarding, and retention policies.
- Work closely with SOC, infrastructure, and application teams to enhance monitoring and security visibility.
- Perform platform upgrades, patching, and capacity planning.
- Prepare technical documentation, operational procedures, and knowledge base articles.
Required Skills
- 5+ years of hands-on experience withSplunk Enterprise administration and engineering.
- Strong expertise inSplunk Enterprise Security (ES) and SIEM implementations.
- Advanced knowledge ofSPL (Search Processing Language).
- Experience integrating Windows, Linux, network, cloud, and application logs.
- Familiarity with cybersecurity concepts, threat detection, MITRE Telecommunication&CK, and incident response.
- Experience with Universal Forwarders, Indexers, Search Heads, Deployment Server, and Cluster Management.
- Knowledge of scripting (Python, Shell, or PowerShell) for automation is an added advantage.
- Excellent troubleshooting, analytical, and communication skills.
Preferred Qualifications
- Splunk Core Certified Power User,Splunk Enterprise Certified Admin, orSplunk Enterprise Security Certified Admin.
- Experience with cloud platforms (AWS, Azure, or GCP) and security tools is preferred.
Splunk SME ยท NR Consulting - India