Splunk SME

Overview

Remote
Accepts corp to corp applications
Contract - Independent
Contract - W2
Contract - Longterm

Skills

EC2
RDS
ELB
Guardduty
Config
Inspector
Security Hub

Job Details

Greetings from Canopy One Solutions,
Hope your day is Treating you well!

We are immediately hiring for the below given position, if you think you are right suitable resources for this opportunity based on your skills and expertise, please do share your updated resume along with contact details we will be happy to discuss in detail about this role.
Project Details:
Role: Splunk SME
Location: Remote
Duration:12+ Months Contract with Extension
Employment Type: C2C/C2H/W2
Interview Criteria: MS teams Video


Job Description:

Atleast 5+ years of experience in the IT industry with strong technical knowledge on AWS Infrastructure & security services (EC2, ELB, Guardduty, Config, Inspector, Security Hub, RDS, Route53, S3, vpc, vpn, tgw, cloudwatch, cloudtrail, eventbridge, etc.)

Hands on experience in terraform IaC deployments and ability to implement security automation.

Strong experience working on enterprise security solutions such as WAF, IPS, DDOS, and SIEM.

Good technical experience managing products like Splunk enterprise security, Tenable Nessus, PaloAlto firewall, Cortex XSOAR.

Good understanding of security controls related to regulatory requirements, such as NIST, PCI, ISO 27001, HIPAA compliance etc

Architecture certification (Google, Amazon, Azure) from a major cloud platform.

Information Security Certification is a plus: ISO 27001, CISSP or CISM or other equivalent.

Experience working on FedRamp compliant projects is a plus.

Splunk skillset Requirements:-

Strong hands-on working experience in Splunk Installation and UNIX management, Splunk architecture and components including search heads, indexers and forwarders.

Installed, configured, and maintained Splunk Add ons and Apps such as but not limited to: Splunk Add-On for AWS, Splunk Add-On for Windows, and Google Workspace for Splunk.

Creation of new dashboards, reports or analytics

Managed a clustered environment with multiple indexers and search heads.

Administered both Splunk Enterprise and Splunk Enterprise Security.

Worked closely with various Security and Platform Engineering teams to onboard new data from various sources.

Creation of new alerts, custom rules.

Maintaining the security of splunk and its related components and indexes

Maintaining current patch levels for all splunk components including the Linux host OS patching and upgrading

Performing major version upgrades including the Linux host OS, Splunk components as necessary

Troubleshooting and resolving splunk issues as necessary Candidates with Splunk Enterprise Security Certified Admin or Splunk Certified Cybersecurity Defense Analyst certification will be preferred.

XSOAR skillset Requirements: - Experience in XSOAR with ability to configure existing and/or create new Incident Types, Incident Fields, Classifications & Mappings Ability to build new or modify existing Playbooks, including implementation of Generic Polling and similar tasks Ability to configure and manage Threat Intelligence Management (TIM) features in XSOAR Palo Certified Security Automation Engineer (PCSAE) preferred.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.