Job Summary
Job Description – Splunk SIEM Engineer Position: Splunk SIEM Engineer (L2-L3) Experience 5–8 Years Location US\India (Supporting US Operations) Shift 24x7 Rotational Support (as applicable) Job Summary We are looking for a highly motivated Splunk SIEM Engineer to support Infrastructure services for a global media organization. The candidate will be responsible for Splunk platform administration, security monitoring, threat detection, incident investigation, use-case development, and SIEM optimization. The ideal candidate should possess strong expertise in Splunk Cloud, Security Information and Event Management (SIEM), cybersecurity operations, along with some hands-on on AWS, DNS knowhow and DevOps experience. Key Responsibilities Splunk Platform Administration Manage and support Splunk Cloud environment. Monitor SIEM platform health, performance, and log ingestion. Troubleshoot indexing, search, data parsing, and log collection issues. Manage data onboarding, field extraction, data models, lookups, and dashboards. Ensure availability and performance of Splunk services. SIEM Content Development Develop and maintain correlation rules and detection use cases. Create and tune alerts to reduce false positives. Design dashboards and operational reports. Support onboarding of new log sources and integrations. Develop up to 10 new detection use cases annually aligned to business requirements. Security Monitoring & Incident Response Perform security event monitoring and alert triage. Analyze and investigate security alerts. Classify incidents by severity and business impact. Create and track incidents in ITSM systems. Support critical incident investigations and root cause analysis. Collaborate with SOC, IR, and platform teams during major security incidents. Reporting & Governance Generate weekly and monthly Splunk reports. Present findings and recommendations to stakeholders. Maintain documentation, SOPs, runbooks, and operational procedures. Required Technical Skills Splunk Splunk Enterprise / Splunk Cloud Splunk Enterprise Security (ES) SPL (Search Processing Language) Correlation Searches Data Models CIM (Common Inf
Key Responsibilities
2. Provide Technical Support For Complex Incidents Escalated By Analysts, Conducting Thorough Root Cause Analysis And Implementing Effective Solutions For Technical And Security Challenges.
3. Lead Value-Adding Initiatives Such As Updating And Managing The Knowledge Base, Providing Training For New Team Members, And Coaching Analysts To Enhance Team Performance.
4. Resolve Complex Support Tickets Within Agreed Slas, Collaborating With Cross-Functional Teams To Ensure Seamless Operations And A Robust Security Posture.
5. Enhance Customer Experience And Csat By Achieving First Call Resolution, Minimizing Rejected Resolutions, Reducing Case Reopenings, And Proactively Mitigating Security Threats.
Skill Requirements
2. Solid Understanding Of Security Operations And Incident Management Processes.
3. Familiarity With Soar Platforms To Automate Security Workflows Effectively.
4. Strong Analytical And Problem-Solving Skills With Attention To Detail.