Job Description
n
Administer and maintain Splunk Enterprise Security (ES) workplace.
n
Manage index lifecycle, retention policies, and storage optimization
n
Develop, optimize, and maintain correlation searches and use cases
n
Align detections with frameworks like MITRE ATT&CK;
n
Create and enhance Splunk dashboards, reports, and alerts
n
Integrate new log sources and data inputs (cloud, network, endpoint, apps)
n
Normalize and onboard logs using CIM (Common Information Model)
n
Tune Data Models, tags, event types
n
Provide advanced support for incident investigations escalated from L1/L2
n
Conduct deep forensic analysis using Splunk data
n
Support incident response activities and root cause analysis
n
Work closely with SOC analysts to improve detection and response workflows
n
Integrate Splunk with SOAR platforms
n
Support API integrations with external security tools
n
Investigate issues with Data
Ingestion/latency/inputs
n
Optimize queries and reduce search execution time
n
Maintain Splunk architecture documentation and SOPs
n
Support audits and reporting requirements
n
Conduct knowledge sharing and training for L1/L2 analysts
n
#J-*****-Ljbffr
📌 Splunk Engineer (New South Wales)
🏢 Avance Consulting
📍 New South Wales
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.