T
Splunk Enterprise Security Specialist
Hyderabad, Telangana, India · Jornada completa
Sé el primero en postularte
- Experiencia
- 7–10 años
- Salario
- —
- Vacantes
- 1
- Al corriente
- Hace 2 horas
- Modo de trabajo
- En la oficina
- Educación
- Cualquier graduado
- Elegibilidad
- Applicants must be graduates in any discipline with 7 to 10 years of expertise in Splunk Enterprise Security.
- Reanudar
- Se requiere solicitud
Dónde trabajarás
Descripción del trabajo
About the Company
Tata Consultancy Services is a leading IT services, consulting, and business solutions provider with over five decades of experience collaborating with some of the world's largest enterprises. Their commitment to innovation and shared expertise aims to bring purposeful transformation to the future.
Job Overview and Responsibilities
- Oversee and maintain the Splunk Enterprise Security (ES) environment, managing core components such as Data Models, Correlation Searches, Notable Events, Threat Intelligence Framework, Asset & Identity, and Content Management.
- Design, develop, and fine-tune security detection use cases based on the MITRE ATT&CK framework, utilizing SPL scripting and Splunk ES correlation searches to enhance threat detection.
- Deploy and enhance Risk-Based Alerting (RBA) mechanisms by crafting risk rules and modifiers, optimizing detection to minimize false positives and maximize alert accuracy.
- Onboard multiple security data sources, ensure proper normalization through the Common Information Model (CIM), address data ingestion and parsing issues, and maintain high-quality data for security analytics.
- Work closely with Security Operations Center (SOC) and security teams to broaden detection capabilities, validate security use cases, assist in incident investigations, and continuously improve the Splunk security platform.
Eligibility and Requirements
- Requires a minimum of 7 to 10 years of professional experience in Splunk Enterprise Security administration and development.
- Must hold a graduate degree from any discipline.
Habilidades
SOC Collaboration
Incident Investigation Support
MITRE ATT&CK framework knowledge
Splunk Enterprise Security administration
SPL scripting
Security detection engineering
Risk-Based Alerting implementation
Security data onboarding and normalization
Common Information Model (CIM)
Data parsing and troubleshooting