Splunk SIEM Engineer / Splunk Administrator
Jeddah, Makkah Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 10 小时前
- Work mode
- In office
- Eligibility
- Candidates must be currently residing in Saudi Arabia to qualify for this position.
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Company
Emdad Excellence, a subsidiary of the renowned Emdad Group, specializes in delivering innovative and compliant human resources and workforce solutions tailored for the Saudi Arabian market. Operating from its Riyadh headquarters and backed by a strong capital foundation and a large employee base, the company blends over two decades of expertise with thorough understanding of local laws to support organizational growth through customized HR solutions.
Role Overview
We are seeking a skilled Splunk SIEM Engineer / Splunk Administrator to join an MNC client based in Jeddah, Saudi Arabia. This is a full-time onsite opportunity aimed at managing and enhancing the Splunk Enterprise and SIEM environments, focusing on security and automation initiatives within the organization.
Key Responsibilities and Duties
- Manage and administer Splunk Enterprise deployments, including configuration, upgrades, license and user management, as well as routine patching and backups.
- Handle troubleshooting and maintenance of log ingestion processes, ensuring smooth onboarding of various log sources.
- Develop and maintain SIEM use-cases such as correlation rules, dashboards, alerting mechanisms, reports, and customized queries tailored for security monitoring.
- Implement parsing rules to accommodate non-standard logs and integrate advanced security features including Threat Intelligence, IoCs, Sigma rules, and security advisories.
- Support compliance audits and regulatory demands related to SIEM within Saudi Arabia.
- Administer and monitor Splunk User Behavior Analytics (UBA), including health checks, backups, failover processes, and management of CIM-compliant and HR-related data.
- Collaborate closely with the automation leadership team driving RPA initiatives as part of the AMS program.
Requirements and Qualifications
- Minimum of 5 years’ professional experience with Splunk and SIEM technologies.
- Proven expertise in deploying and administering Splunk Enterprise platforms.
- Skillful in log source integration, debugging ingestion issues, and managing Splunk components like Enterprise Security and UBA.
- Strong ability to build and customize complex correlation rules, dashboards, and reports for security analytics.
- Experience with parsing and interpreting non-standard log formats.
- Knowledge in configuring and utilizing advanced security tools including Threat Intelligence and Sigma rules.
- Familiarity with SIEM-related audit processes and regulations in the Saudi Arabian context.
- Demonstrated troubleshooting and ongoing support capabilities for SIEM environments.
- Candidates must currently reside in Saudi Arabia; applications from outside the country will not be entertained.
Additional Details
Location: Jeddah, Saudi Arabia
Client: Leading multinational corporation
Industry
HR Services