College degree or equivalent training with experience working in a Security Operations Center, Managed Security, or client network environment.
Minimum 7 years of professional experience supporting and maintaining SPLUNK SIEM System.
5-6 years of experience with advanced tuning of Splunk SIEM content.
Experience in Cribl.
Professional experience working with networks and network architecture.
Information security knowledge in one or more areas such as EDR – Enterprise end-point security products (e.g., McAfee e-Policy Orchestrator, Virus Scan, Anti-Spyware, Host Data Loss Protection, Endpoint Encryption, etc.)
Practical hands-on experience in EDR (Carbon Black), Vectra, and Microsoft Azure.
Splunk, Azure Log analytics, or equivalent big data engine experience.
Experience with MS Azure Information Protection and technologies, including solution architecture, deployment, management, and support in a large global enterprise.
General security knowledge, certificates on Splunk Admin, Splunk Architect, Splunk Consultant is a must. Also, good to have is Azure, Managed vulnerability (Nessus/Tenable), EDR (Carbon Black) and Firewall related security certifications.
Knowledge of Linux and Windows Operating Systems.
Experience with various other SIEM security products such as: Splunk, ArcSight, Nitro, or LogRhythm and infrastructure components such as proxies, firewalls, IDS/IPS, and DLP.
Experience working with clients in a service delivery function.
Shift flexibility, including the ability to provide after-hours support when needed.
Experience working with internal and client ticketing and knowledge base systems for Incident and Problem tracking as well as procedures.