Scope of Work
The consultant will provide engineering, operational, and administrative support across cybersecurity environment, including SIEM (Splunk), endpoint security, scripting, automation, and security operations.
1. SIEM Engineering & Security Monitoring (Splunk) The consultant will:
• Provide engineering and administration support for Splunk environment (cloud and/or hybrid).
• Support search heads, indexers, deployers, deployment servers, heavy/universal forwarders, and Splunk applications.
• Onboard and normalize new log sources (application, database, network, cloud, endpoint).
• Develop and maintain complex Splunk queries, dashboards, reports, and alerts for both technical and executive audiences.
• Analyze log data for anomalies, suspicious trends, and potential security incidents.
• Design dashboards highlighting key security, operational, and performance metrics.
• Support log correlation and threat detection use cases aligned with SOC requirements.
• Assist with tuning alerts to reduce false positives and improve detection efficiency.
• Work with stakeholders to gather requirements and deliver reporting solutions.
2. Security Operations & Incident Support
The consultant will:
• Support day-to-day security monitoring activities in coordination with NYC SOC and internal teams.
• Assist in triage and analysis of security alerts and incidents.
• Support incident investigations by leveraging logs, endpoint data, and network telemetry.
• Assist with containment, eradication, and recovery actions when required.
• Support development and refinement of detection use cases.
• Contribute to incident response documentation and playbooks.
3. Scripting & Automation
The consultant will:
• Develop and maintain automation scripts (e.g., PowerShell, Python, Bash) to improve operational efficiency.
• Automate repetitive security tasks such as log ingestion validation, alert validation, reporting, and compliance checks.
• Support automation of endpoint configuration validation and security control verification.
• Assist in developing integrations between security tools where feasible.
• Improve dashboard automation and scheduled reporting capabilities.
4. Endpoint Security & Operational IT Support
The consultant will provide operational support in the following areas:
• Assist in monitoring and managing endpoint security tools (e.g., EDR, antivirus, host-based monitoring tools).
• Support endpoint hardening initiatives and security configuration validation.
• Assist with vulnerability remediation coordination and tracking.
• Support security patch validation and compliance reporting.
• Analyze endpoint telemetry for suspicious behavior patterns.
• Support implementation of endpoint-related security improvements.
5. Operational IT Security Tasks
The consultant will also support broader day-to-day IT security operational needs, including:
• Reviewing system logs for infrastructure components.
• Supporting firewall and network security log monitoring in coordination with OTI.
• Assisting with user access review processes and audit support.
• Supporting documentation of security configurations and architecture diagrams.
• Contributing to POAM tracking and remediation validation where required.
• Supporting compliance reporting and audit evidence preparation.
Qualifications and Desired Skills
• Strong hands-on experience with Splunk Enterprise and/or Splunk Cloud.
• Experience with onboarding log sources and building detection logic.
• Knowledge of enterprise logging (application, web, database, security, endpoint).
• Experience with scripting languages (PowerShell, Python, Bash).
• Familiarity with endpoint detection and response (EDR) tools.
• Knowledge of incident response procedures.
• Understanding of log correlation and threat detection techniques.
• Experience with IDS/IPS and host-based security tools.
• Strong analytical and problem-solving skills.
• Ability to work independently and manage assigned tasks.
• Strong verbal and written communication skills.
Preferred Certifications:
• Splunk Enterprise Certified Admin / Architect
• CISSP, CEH, GCIH, Security+, or equivalent certifications