One of our large clients are looking for a Splunk Engineer and Splunk Architect to apply your expertise on a 6-month rolling contract with hybrid working.
Key Responsibilities:
Design and implement Splunk architecture to support Security Operations Centre (SOC) activities.
Develop advanced Splunk searches, dashboards, and alerts for monitoring and incident response.
Analyse log data to identify patterns, anomalies, and security threats.
Optimize Splunk performance and ensure data integrity across all systems.
Collaborate with SOC analysts to enhance threat detection and response capabilities.
Maintain compliance with security standards like ISO27001 and ITIL best practices.
Automate routine tasks using scripting languages (e.g., Python, Bash, PowerShell).
Provide training and documentation for Splunk users and administrators.
Qualifications:
Bachelor's degree in Computer Science, Information Technology, or a related field.
Certifications such as Splunk Core Certified Power User or Splunk Enterprise Certified Admin.
Experience with SIEM tools, intrusion detection systems (IDS), and intrusion prevention systems (IPS).
Knowledge of scripting languages and data formats like JSON and XML.
Familiarity with cloud environments (e.g., AWS, Azure) and containerization tools (e.g., Docker, Kubernetes).
Strong analytical skills and ability to interpret complex data.
Preferred Skills:
Experience working in a SOC or incident response team.
Knowledge of correlation searches and advanced Splunk visualizations.
Understanding of DevOps principles and CI/CD pipelines.
If you are interested, please send your CV and a good time to call about the position.