Associate Principal Cyber Security
CurrentAs a Splunk Architect :* Design and architect Splunk deployments based on organizational requirements.* Plan and implement distributed and high-availability Splunk environments.* Optimize Splunk performance and scalability.* Provide guidance on best practices for data onboarding, retention, and access controls.* Collaborate with stakeholders to understand business requirements and translate them into Splunk solutions.* Stay updated on Splunk features and industry best practices.As a Splunk Admin :* Install, configure, and maintain Splunk instances.* Manage Splunk indexes, including data retention policies and index optimization.* Monitor Splunk infrastructure for performance and availability.* Troubleshoot and resolve issues related to Splunk deployment.* Implement and manage user access controls and authentication mechanisms.* Collaborate with other IT teams to integrate Splunk into existing systems.As a Splunk Developer : * Develop and maintain custom Splunk queries, reports, and dashboards.* Create and optimize search queries to extract meaningful insights from data.* Implement and manage data input and parsing configurations.* Work closely with data owners to understand data sources and requirements.* Develop and maintain custom scripts and apps for extending Splunk functionality.* Participate in the development of Splunk apps for specific use cases.Other SIEM and Security responsibilities :* Utilize tools and analytical skills to plan and execute technical changes.* Understanding of the MITRE ATT&CK Framework and/or the Cyber Kill Chain* Experience with Incident Response methodology in investigations, and the groups behind targeted attacks and tactics, techniques, and procedures (TTPs)* Design solution for syslog integration and WEC WEF logs using Cribl Data Stream.* Deploy and manage Cribl Data Stream on Security Devices.