Splunk Engineer (New South Wales)

Splunk Engineer (New South Wales)

16 Aug
|
Avance Consulting
|
New South Wales

16 Aug

Avance Consulting

New South Wales

Administer and maintain Splunk Enterprise Security (ES) workplace.Manage index lifecycle, retention policies, and storage optimizationDevelop, optimize, and maintain correlation searches and use casesAlign detections with frameworks like MITRE ATT&CKCreate; and enhance Splunk dashboards, reports, and alertsIntegrate new log sources and data inputs (cloud, network, endpoint, apps)Normalize and onboard logs using CIM (Common Information Model)Tune Data Models, tags, event typesProvide advanced support for incident investigations escalated from L1/L2Conduct deep forensic analysis using Splunk dataSupport incident response activities and root cause analysisWork closely with SOC analysts to improve detection and response workflowsIntegrate Splunk with SOAR platformsSupport API integrations with external security toolsInvestigate issues with Data Ingestion/latency/inputsOptimize queries and reduce search execution timeMaintain Splunk architecture documentation and SOPsSupport audits and reporting requirementsConduct knowledge sharing and training for L1/L2 analysts
#J-*****-Ljbffr

📌 Splunk Engineer (New South Wales)
🏢 Avance Consulting
📍 New South Wales

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: splunk engineer (new south wales) / new south wales

Subscribe to this job alert:

Get the latest job offers by email for: splunk engineer (new south wales) / new south wales