Sr. SIEM Engineer - Splunk, On-Site, Bangalore

12 Months ago • 5 Years + • Software Development & Engineering

Job Summary

Job Description

Optiv is seeking a Sr. SIEM Engineer specializing in Splunk to join their team in Bangalore. This role involves leading the Splunk team, prioritizing client work, defining processes, and mentoring junior engineers. The successful candidate will implement and configure SIEM products, develop and tune Splunk content, and provide remote consulting services. Key responsibilities include analyzing and improving existing procedures, assisting with client onboarding, and performing knowledge transfers. The role requires expert-level Splunk Enterprise Security knowledge and extensive experience with SIEM systems, network architecture, and regular expressions.
Must have:
  • Help lead the Splunk team by prioritizing client work requests, projects, and service tasks.
  • Work closely with Management, Service Delivery and Principal Engineers in defining processes and procedures for internal projects.
  • Analyze and identify areas of improvement with existing processes, procedures, and documentation.
  • Assist in team development by defining strategies and responsibilities to be successful and grow.
  • Develop internal training methods to support Managed Services and their clients.
  • Act as a point of escalation for Junior SIEM Engineers, as well as provide them with guidance and mentorship.
  • Assist with client activation and onboarding.
  • Explain and demonstrate how to use SIEM products to both technical and relatively non-technical personnel.
  • Provide remote consulting services via interactive client sessions to assist with implementation of multiple product vendors and technologies.
  • Implement and configure SIEM software and appliance-based products in Enterprise and Government environments.
  • Develop, deploy, and tune SIEM content and reporting.
  • Interact appropriately and professionally with both customers and partners, when required.
  • Perform knowledge transfers and train clients regarding security and system configuration.
  • 5+ years professional experience managing and maintaining SIEM systems.
  • 2-3 years professional experience working with networks and network architecture.
  • 1+ year professional experience writing SIEM content specifically for Splunk.
  • Ability to deal confidently with complex technical problems.
  • Expert-level knowledge of Splunk Enterprise Security.
  • Experience with building intricate searches from disparate data sources and joining them together.
  • Extensive experience using the Enterprise Security Asset & Identity and Threat Intelligence Framework within Splunk Enterprise Security.
  • Proficient with managing Unix and Linux operating systems.
  • Strong experience with writing complex regular expression (Regex) to extract fields for data that is structured and unstructured.
  • Experience with extracting fields, multi-value fields, tags, field aliases, etc.
  • Well-versed in building threat detections (correlation rules) using security logs to detect malicious activity with high fidelity.
  • In-depth knowledge of security logging for Linux, Windows, major EDRs, Firewalls, & Active Directory.
  • Experience with installing and configuring Splunk CORE and Splunk Enterprise Security.
  • Ability to aggregate and analyze logs from various deployed security devices.
  • Experience with configuring and/or working with Splunk Search Head and/or Indexer Clusters.
  • Experience with creating custom applications, dashboards, reports, and alerts (not including the default ones that come with Splunk).
  • Shift flexibility, including the ability to provide on call support when needed.
Perks:
  • A company committed to championing Diversity, Equality, and Inclusion through our Employee Resource Groups.
  • Work/life balance
  • Professional training resources
  • Creative problem-solving and the ability to tackle unique, complex projects
  • Volunteer Opportunities. “Optiv Chips In” encourages employees to volunteer and engage with their teams and communities.
  • The ability and technology necessary to productively work remotely/from home (where applicable)

Job Details

At Optiv, we’re on a mission to help our clients make their businesses more secure. We’re one of the fastest growing companies in a truly essential industry.

In your role at Optiv, you’ll be inspired by a team of the brightest business and technical minds in cyber security. We are passionate champions for our clients and know from experience that the best solutions for our clients’ needs come from working hard together. As part of our team, your voice matters, and you will do important work that has impact, on people, businesses and nations. Our industry and our company move fast, and you can be sure that you will always have room to learn and grow. We’re proud of our team and the important work we do to build confidence for a more connected world.

Our consultants are skilled technical and consultative resources expected to be strong in both technical and soft skills. A Consultant must be a proven self-starter with the ability to problem-solve, communicate, participate in diverse project teams from a technical perspective, and interface effectively with customers, vendor partners, and colleagues. Establish & maintain productive and respectful relationships with the delivery team, practice management, and client management team. In line with Optiv’s commitment to quality, you will confirm that work is of the highest quality as per Optiv’s quality standards, by reviewing the work provided by other members.

How you’ll make an impact:

  • Help lead the Splunk team by prioritizing clients work requests, projects, and service tasks.
  • Work closely with Management, Service Delivery and Principal Engineers in defining processes and procedures for internal projects.
  • Analyzes and identifies areas of improvement with existing processes, procedures, and documentation.
  • Assist in team development by defining strategies and responsibilities to be successful and grow.
  • Develop internal training methods to support Managed Services and their clients.
  • Act as a point of escalation for Junior SIEM Engineers, as well as provide them with guidance and mentorship.
  • Assist with client activation and onboarding.
  • Explain and demonstrate how to use SIEM products to both technical and relatively non-technical personnel.
  • Provide remote consulting services via interactive client sessions to assist with implementation of multiple product vendors and technologies.
  • Implement and configure SIEM software and appliance-based products in Enterprise and Government environments.
  • Develop, deploy, and tune SIEM content and reporting.
  • Interacting appropriately and professionally with both customers and partners, when required.
  • Perform knowledge transfers and train clients regarding security and system configuration
  • The Senior SIEM Engineer will have no direct reports.

What we’re looking for

  • 5+ years professional experience managing and maintaining SIEM systems.
  • 2-3 years professional experience working with networks and network architecture.
  • 1+ year professional experience writing SIEM content specifically for Splunk.
  • Ability to deal confidently with complex technical problems.
  • Expert-level knowledge of Splunk Enterprise Security
  • Experience with building intricate searches from disparate data sources and joining them together.
  • Extensive experience using the Enterprise Security Asset & Identity and Threat Intelligence Framework within Splunk Enterprise Security
  • Proficient with managing Unix and Linux operating systems
  • Strong Experience with writing complex regular expression (Regex) to extract fields for data that is structured and unstructured.
  • Experience with extracting fields, multi-value fields, tags, field aliases, etc.
  • Well-versed in building threat detections (correlation rules) using security logs to detect malicious activity with high fidelity.
  • In-depth knowledge of security logging for Linux, Windows, major EDRs, Firewalls, & Active Directory
  • Experience with installing and configuring Splunk CORE and Splunk Enterprise Security
  • The ability to aggregate and analyze logs from various deployed security devices.
  • Experience with configuring and/or working with Splunk Search Head and/or Indexer Clusters.
  • Experience with creating custom applications, dashboards, reports, and alerts (not including the default ones that come with Splunk).
  • Shift flexibility, including the ability to provide on call support when needed.

What you can expect from Optiv

  • A company committed to championing Diversity, Equality, and Inclusion through our Employee Resource Groups.
  • Work/life balance
  • Professional training resources
  • Creative problem-solving and the ability to tackle unique, complex projects
  • Volunteer Opportunities. “Optiv Chips In” encourages employees to volunteer and engage with their teams and communities.
  • The ability and technology necessary to productively work remotely/from home (where applicable)

EEO Statement

Optiv is an equal opportunity employer. All qualified applicants for employment will be considered without regard to race, color, religion, sex, gender identity or expression, sexual orientation, pregnancy, age 40 and over, marital status, genetic information, national origin, status as an individual with a disability, military or veteran status, or any other basis protected by federal, state, or local law.

Optiv respects your privacy. By providing your information through this page or applying for a job at Optiv, you acknowledge that Optiv will collect, use, and process your information, which may include personal information and sensitive personal information, in connection with Optiv’s selection and recruitment activities. For additional details on how Optiv uses and protects your personal information in the application process, click here to view our Applicant Privacy Notice. If you sign up to receive notifications of job postings, you may unsubscribe at any time.

Similar Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Skill Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Jobs in Bengaluru, Karnataka, India

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Software Development & Engineering Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

We work alongside clients to manage cyber risk and equip them with perspectives and programs to accelerate business progress. Our real-world experience, deep vertical expertise and diverse teams enable us to face any challenge with confidence. We put you at the center of our unmatched ecosystem of people, products, partners and programs to design and implement agile solutions. Our adaptive approach continually assesses risk in the context of cyber and broader objectives to secure today's business and fortify it for the future.

Tallahassee, Florida, United States (Hybrid)

St. Louis, Missouri, United States (Hybrid)

Salt Lake City, Utah, United States (Hybrid)

Bengaluru, Karnataka, India (On-Site)

Overland Park, Kansas, United States (Remote)

Boston, Massachusetts, United States (Remote)

Jacksonville, Florida, United States (Remote)

Overland Park, Kansas, United States (Remote)

Overland Park, Kansas, United States (Remote)

Bengaluru, Karnataka, India (On-Site)

View All Jobs

Get notified when new jobs are added by Optiv

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug