Skill diminta
AWSAnsibleAzureCommunicationDeliveryDockerGCPKubernetesLeadershipLinuxPythonTerraformTroubleshooting
Deskripsi
Tanggung Jawab
- Design, deploy, and maintain enterprise security monitoring platforms.
- Architect, implement, and optimize Splunk Enterprise environments.
- Design SIEM architecture for scalability, high availability, and disaster recovery.
- Develop dashboards, reports, alerts, correlation searches, and SPL queries.
- Optimize indexing, search performance, storage utilization, and overall platform health.
- Integrate log sources from operating systems, network devices, cloud platforms, enterprise applications, and security solutions.
Integrate enterprise security technologies including Firewalls, IDS/IPS, WAF, EDR/XDR, IAM, Vulnerability Management, and Threat Intelligence platforms.
- Administer Linux servers supporting security platforms.
- Perform platform installation, upgrades, patching, performance tuning, and troubleshooting.
- Support incident investigation, threat hunting, and security monitoring activities.
- Produce technical documentation including HLD, LLD, MOP, SOP, runbooks, and knowledge base articles.
- Lead customer workshops, deployments, and technical implementation activities.
- Mentor Security Engineers and provide technical leadership throughout project delivery.
Kualifikasi
- Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related field.
- Minimum 4 years of experience in cybersecurity engineering.
- Hands-on experience designing, deploying, and administering Splunk Enterprise.
- Strong understanding of SIEM architecture, log management, and security monitoring.
- Advanced proficiency with Splunk Search Processing Language (SPL).
- Experience with Splunk Enterprise Security (ES) and Splunk SOAR is an advantage.
- Strong Linux administration skills (RHEL, Rocky Linux, Ubuntu, or CentOS).
- Experience with Python, Bash, or PowerShell scripting.
- Experience with Docker, Kubernetes, Terraform, or Ansible is an advantage.
- Strong understanding of TCP/IP networking, Routing & Switching, VLAN, DNS, DHCP, NAT, VPN, SSL/TLS, and Load Balancers.
Experience implementing or integrating Firewalls, IDS/IPS, WAF, EDR/XDR, Active Directory, IAM, Vulnerability Management, and Threat Intelligence platforms.
- Familiarity with AWS, Azure, or Google Cloud Platform.
- Strong analytical, troubleshooting, documentation, communication, and customer-facing skills.
- Ability to lead technical projects and mentor junior engineers.
- Preferred Certifications
- Splunk Enterprise Certified Architect
- Networking Certifications
- GIAC Certifications