Skill diminta
AWSAzureCommunicationGCPLinuxPythonTeamworkTroubleshooting
Deskripsi
Tanggung Jawab
- Install, configure, and maintain Splunk Enterprise environments.
- Configure Universal Forwarders, Heavy Forwarders, and data inputs.
- Develop dashboards, reports, alerts, and SPL searches.
- Monitor SIEM platform health and troubleshoot data ingestion issues.
- Onboard log sources from Windows, Linux, network devices, cloud services, enterprise applications, and security products.
- Support integration of Firewalls, IDS/IPS, EDR/XDR, Active Directory, and other enterprise security solutions.
- Administer Linux servers supporting security applications.
- Perform system upgrades, patching, maintenance, and troubleshooting.
- Support security monitoring, incident investigation, and operational troubleshooting.
- Prepare implementation documents, operational runbooks, and technical documentation.
- Support customer implementation and deployment projects.
Kualifikasi
- Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related field.
- Minimum 2 years of experience in cybersecurity or infrastructure engineering.
- Experience administering Splunk Enterprise.
- Good understanding of SIEM concepts, log management, and security monitoring.
- Working knowledge of Splunk Search Processing Language (SPL).
- Experience with Splunk Enterprise Security (ES) is an advantage.
- Good Linux administration skills.
- Basic scripting knowledge using Python, Bash, or PowerShell.
- Good understanding of TCP/IP networking, Routing & Switching, VLAN, DNS, DHCP, VPN, and Syslog.
- Experience working with Firewalls, IDS/IPS, EDR/XDR, and Active Directory.
- Familiarity with AWS, Azure, or Google Cloud Platform is an advantage.
- Basic understanding of MITRE ATT&CK and Security Operations Center (SOC) practices.
- Strong analytical, troubleshooting, documentation, communication, and teamwork skills.