Senior Technical Lead Splunk

Brak informacji o wynagrodzeniu
MidFull-time
#429619·Dodano 8 dni temu·0
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

SecurityLinuxPythonOperationsITILrelease managementPerformance optimizationPowershellSplunkCloud

Firma i stanowisko

The position is for emagine Polska supporting large enterprise environments with Splunk/SIEM platforms, specifically for Cyber Security operations and SOC environments.

Wymagania

  • 7-15 years of hands-on experience with Splunk/SIEM platforms.
  • Strong experience in Splunk Enterprise and Splunk Enterprise Security (ES) administration.
  • Deep understanding of Splunk architecture and CIM onboarding.
  • Hands-on experience with troubleshooting, log onboarding, and performance optimization.
  • Experience conducting platform migrations and managing upgrades.
  • Minimum of two Splunk certifications (e.g., Splunk Core Certified Admin).
  • Strong scripting and automation experience with Terraform and Ansible.
  • Experience administering Linux-based environments.

Nice to have:

  • Experience with Splunk SOAR administration and playbook development.
  • Cribl Stream administration experience.
  • Proficiency in Python, Bash, or PowerShell scripting.
  • Experience with cloud platforms (AWS, Azure, GCP).
  • Knowledge of MITRE ATT&CK framework.
  • ITIL Foundation certification.

Obowiązki

  • Support and administer Splunk/SIEM platforms with 7-15 years of hands-on experience.
  • Perform log onboarding, source integration, parser creation, CIM mapping, and ingestion pipeline management.
  • Deploy, configure, administer, and optimize Splunk components including index lifecycle, retention policies, and storage optimization.
  • Optimize searches, dashboards, reports, alerts, and correlation searches for performance and scalability.
  • Implement and maintain SPL-based monitoring and operational dashboards.
  • Support platform migrations and environment expansion initiatives.
  • Provide Distributed Enterprise level support for Splunk Enterprise and Splunk ES.
  • Manage Splunk upgrades, patches, and release management.
  • Conduct security patching and vulnerability remediation across enterprise Splunk environments.
  • Perform root cause analysis and complex problem resolution in mission-critical environments.

Inne informacje

Looking for immediate joiner only.

emagine

emagine

648 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz