Senior Splunk Security Engineer

NYC IT Inc
New York, NY, United States
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$156,000.0 - $176,800.0
Working hours
Regular working hours
Job source

Tech stack

Bash Shell Cloud Computing CompTIA Security+ Cyber Security Databases Intrusion Detection and Prevention Intrusion Detection Systems Python (Programming Language) Network Security Log Analysis Windows PowerShell Security Information and Event Management
+7 more
Software Vulnerability Management EndPointSecurity Data Logging Scripting Cloud Platform System Splunk Network Server

Job description

  • Administer and support Splunk Enterprise/Cloud environments, including Search Heads, Indexers, Deployers, Deployment Servers, Heavy/Universal Forwarders, and Splunk applications.
  • Onboard and normalize application, database, network, cloud, and endpoint log sources.
  • Develop and maintain Splunk dashboards, reports, alerts, searches, and threat detection use cases.
  • Monitor security events, analyze logs, investigate incidents, and support SOC operations and incident response.
  • Develop automation using PowerShell, Python, and Bash to improve operational efficiency, reporting, and security processes.
  • Support endpoint security, including EDR, endpoint hardening, vulnerability remediation, patch validation, and compliance reporting.
  • Monitor firewall and network security logs, support user access reviews, audits, security documentation, architecture diagrams, POAM tracking, and remediation validation.

Requirements

We are seeking a Senior Splunk Security Engineer with 7+ years of experience supporting enterprise cybersecurity environments. The ideal candidate will have strong hands-on experience with Splunk Enterprise and/or Splunk Cloud, SIEM engineering, security operations, threat detection, scripting, automation, endpoint security, and incident response., * Strong 7+ years of experience with Splunk Enterprise and/or Splunk Cloud.

  • Experience onboarding log sources and developing detection logic.
  • Knowledge of enterprise logging, including application, web, database, security, and endpoint logs.
  • Experience with PowerShell, Python, and Bash scripting.
  • Experience with Endpoint Detection & Response (EDR) tools.
  • Knowledge of incident response procedures.
  • Understanding of log correlation and threat detection techniques.
  • Experience with IDS/IPS and host-based security tools.
  • Strong analytical, problem-solving, verbal, and written communication skills.

Preferred Certifications

  • Splunk Enterprise Certified Admin or Architect.
  • CISSP, CEH, GCIH, Security+, or equivalent cybersecurity certifications.

Benefits & conditions

Work Schedule

  • Business Hours: Monday - Friday, 9:00 AM - 5:00 PM
  • Work Week: 35 hours per week, including a one-hour unpaid lunch break
  • Work Arrangement: Hybrid (3 days onsite, 2 days remote). Applicants must reside in New York (NY) or New Jersey (NJ).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · WWC 2022

Videos

See all

Related articles

See all