Overview
Skills
Job Details
Splunk DEVELOPER:
Key Responsibilities:? Playbook Development: o Design, develop, test, and deploy playbooks using the Splunk SOAR visual editor or Python.o Translate incident response procedures into automated workflows.o Optimize and refine existing playbooks for performance and efficiency.? Integration & App Development: o 6+ years of hands on experience with designing/development of splunk applications.o Advanced Splunk analytics and the development of custom Splunk applicationso Splunk data integrations with business-critical enterprise applications and systems.o Translating feedback from the business to Splunk technical requirement and solutions.o Develop specialized Splunk Security and Compliance applications, add-ons, data models, dashboards, o content using Python, Splunk SPL, Splunk SimpleXML (OR JavaScript, CSS), Bash.o Develop custom Splunk applications and Add-Ons for inclusion of access events per use case criteria.o Develop and configure integrations with third-party security tools (EDR, firewalls, threat intel platforms, ticketing systems, etc.).o Build custom apps or modify existing ones using REST APIs and Python to enhance SOAR capability.? Automation Strategy & Implementation: o Work with stakeholders to identify use cases for automation.o Lead end-to-end implementation of SOAR use cases from design to production.? Security Incident Handling: o Assist in real-time incident response by using SOAR to correlate, triage, and respond to alerts.o Create response templates and automated reports for incidents.? Platform Management: o Maintain and administer the Splunk Phantom platform, including upgrades, performance tuning, and health checks.o Monitor system logs and troubleshoot issues related to connectivity, app execution, or workflow failure.? Documentation & Reporting: o Document playbooks, scripts, and integrations.o Generate reports on SOAR activity, performance metrics, and automation ROI.? Collaboration & Training: o Train SOC staff and other stakeholders on SOAR usage and capabilities.o Collaborate with Splunk SIEM and threat intelligence teams for cohesive operations. ? Key Skills-o Splunk Phantom (SOAR)o Python development ? Proficiency in Python programming languageo Splunk SimpleXML or web development (JavaScript, CSS)o Splunk app & add-on developmento Splunk data modellingo Splunk Enterprise / Splunk Cloudo Python, REST APIo Jira, ServiceNow, Palo Alto, CrowdStrike, VirusTotal, MISP, etc.o Git (for version control of playbooks/scripts