Senior Security Engineer - Splunk Sentinel and Cribl

🏢 HELP INFORMATION TECHNOLOGY CONSULTANCY - SOLE PROPRIETORSHIP L.L.C
📍 Dubai, United Arab EmiratesFull-timeOn-site
📅 Posted: Yesterday🔄 Updated: Today
CV%
✨ AI Summary
This Senior Security Engineer role focuses on administering and developing Splunk solutions, integrating legacy data sources, and establishing best practices for Splunk data utilization. The position involves designing, implementing, and supporting Microsoft security technologies such as Azure Cloud Access Security Broker, Office 365 Advanced Threat Protection, and Microsoft Defender ATP. Responsibilities include managing CB sensors, creating watchlists for threat detection, and assessing customer needs to design and implement solutions. The role also requires serving as a primary responder for Managed Security customer systems, taking ownership of configuration issues through resolution. The ideal candidate must have a Bachelor's degree in Information Technology and significant experience with Splunk SIEM, Cribl, and various Microsoft security products. Strong knowledge of network architecture, EDR, and SIEM technologies is essential, along with mandatory Splunk certifications. Administering Splunk and Splunk Apps to include developing new or extending existing Apps to perform specialized functionality. Integrating Splunk with a wide variety of legacy data sources.Engaging application and infrastructure teams to establish best practices for utilizing Splunk data and visualizations.Design, implement, and support solutions with Microsoft security technologies such as Azure Cloud Access Security Broker, Office 365Advanced Threat Protection (O365 ATP), Microsoft Defender A
Required Skills
Information Technology
NISTMicrosoft SentinelAzureSIEMFirewallsIDS/IPSDLPLinux
Other
Splunk ImplementationCriblSplunk EnterpriseSplunk ESKQLMicrosoft Defender ATPMicrosoft DefenderNessusTenable Security CenterCarbon BlackVectraArcSightNitroLogRhythmproxiesIncident and Problem tracking
Productivity & Workplace Tools
Office 365
Engineering, Construction & Trades
Heating Systems
Soft Skills & Professional Competencies
Problem Solving
Nice to have:
Information Technology
API DevelopmentAI IntegrationOT SecurityEDREncryptionSolution ArchitectureModel DeploymentTechnical Documentation
Other
vulnerability scanningnetwork architectureMcAfee e-Policy OrchestratorVirus ScanAnti-SpywareHost Data Loss Protection
Soft Skills & Professional Competencies
People ManagementCommunication
Finance, Legal & Governance
Audit Support
🎁 Benefits & Perks
HELP INFORMATION TECHNOLOGY CONSULTANCY - SOLE PROPRIETORSHIP L.L.C
Requirements
  • College degree or equivalent training with experience working in a Security Operations Center, Managed Security, or client network environment.

  • Minimum 7 years of professional experience supporting and maintaining SPLUNK SIEM System.

  • 5-6 years of experience with advanced tuning of Splunk SIEM content.

  • Experience in Cribl.

  • Professional experience working with networks and network architecture.

  • Information security knowledge in one or more areas such as EDR – Enterprise end-point security products (e.g., McAfee e-Policy Orchestrator, Virus Scan, Anti-Spyware, Host Data Loss Protection, Endpoint Encryption, etc.)

  • Practical hands-on experience in EDR (Carbon Black), Vectra, and Microsoft Azure.

  • Splunk, Azure Log analytics, or equivalent big data engine experience.

  • Experience with MS Azure Information Protection and technologies, including solution architecture, deployment, management, and support in a large global enterprise.

  • General security knowledge, certificates on Splunk Admin, Splunk Architect, Splunk Consultant is a must. Also, good to have is Azure, Managed vulnerability (Nessus/Tenable), EDR (Carbon Black) and Firewall related security certifications.

  • Knowledge of Linux and Windows Operating Systems.

  • Experience with various other SIEM security products such as: Splunk, ArcSight, Nitro, or LogRhythm and infrastructure components such as proxies, firewalls, IDS/IPS, and DLP.

  • Experience working with clients in a service delivery function.

  • Shift flexibility, including the ability to provide after-hours support when needed.

  • Experience working with internal and client ticketing and knowledge base systems for Incident and Problem tracking as well as procedures.

Description
Administering Splunk and Splunk Apps to include developing new or extending existing Apps to perform specialized functionality. Integrating Splunk with a wide variety of legacy data sources.Engaging application and infrastructure teams to establish best practices for utilizing Splunk data and visualizations.Design, implement, and support solutions with Microsoft security technologies such as Azure Cloud Access Security Broker, Office 365Advanced Threat Protection (O365 ATP), Microsoft Defender ATP, and their integrations used to deliver internet-scale intelligence and managed security products.Implement & administer Microsoft Defender (ATP), Azure Cloud Access Security Broker & Azure Threat Protection security products within customer environment Manage and oversee day-to-day activities of Azure IP platform and ensure adherence to enterprise standards in project execution methodology, requirements gathering, quality assurance, and continuous improvement.Handle the implementation/deployment/support of Nessus scan engines and Tenable Security Center and peripherals with Engineering, SOC, TIU, and IR.Maintain local and network credentials, Tenable Security Center, and provisions access to vulnerability scanning systems.Integrate Nessus/TSC with other security and IT systems management tools.Document vulnerabilities and work on vulnerability mitigation with agreed SLA.Managing CB sensors including deployment, operation, management, maintenance, update, upgrade, patching, and administration.Should be able to create watchlists to detect indicators of compromise (IOCs) and malicious behavior of new threats.Hands on in writing queries in CB to search the desired events.Assess customer needs and expectations, design solutions to meet those needs, and then implement the design.Quickly build and solve a problem using a new technology to determine viability.Serve as a primary responder for Managed Security customer systems, taking ownership of client configuration issues and tracking through resolution.
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00