Splunk Engineer (New South Wales)

Splunk Engineer (New South Wales)

21 Aug
|
Avance Consulting
|
New South Wales

21 Aug

Avance Consulting

New South Wales

Job Description
Administer and maintain Splunk Enterprise Security (ES) setting.
Manage index lifecycle, retention policies, and storage optimization
Develop, optimize, and maintain correlation searches and use cases
Align detections with frameworks like MITRE ATT&CK;
Create and enhance Splunk dashboards, reports, and alerts
Integrate new log sources and data inputs (cloud, network, endpoint, apps)
Normalize and onboard logs using CIM (Common Information Model)
Tune Data Models, tags, event types
Provide advanced support for incident investigations escalated from L1/L2
Conduct deep forensic analysis using Splunk data
Support incident response activities and root cause analysis
Work closely with SOC analysts to improve detection and response workflows
Integrate Splunk with SOAR platforms
Support API integrations with external security tools
Investigate issues with DataIngestion/latency/inputs
Optimize queries and reduce search execution time
Maintain Splunk architecture documentation and SOPs
Support audits and reporting requirements
Conduct knowledge sharing and training for L1/L2 analysts
#J-*****-Ljbffr

📌 Splunk Engineer (New South Wales)
🏢 Avance Consulting
📍 New South Wales

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: splunk engineer (new south wales) / new south wales

Subscribe to this job alert:

Get the latest job offers by email for: splunk engineer (new south wales) / new south wales