Social network you want to login/join with:
Create HLD/LLD and solution documents for Splunk deployment across enterprise.
1. Lead the deployment and management of Splunk Cloud solutions, ensuring seamless integration with existing systems.
2. Configure and integrate Splunk Cloud with existing systems and data sources.
3. Perform testing and validation of the cloud deployment.
4. Identify and prioritize data sources for onboarding into Splunk.
5. Develop and implement data ingestion strategies.
6. Ensure data quality, normalization, and enrichment.
7. Perform routine administration tasks such as user management, index management, and system monitoring.
8. Optimize Splunk performance through tuning and configuration adjustments.
9. Manage Splunk licenses and upgrade processes.
10. Develop and maintain troubleshooting guides and knowledge base articles.
11. Collaborate with vendors for support and issue resolution.
12. Maintain detailed documentation of Splunk configurations, processes, and procedures.
Key responsibilities:
1. Experience in developing comprehensive Splunk architecture tailored to the organization's security requirements, compliance standards, and infrastructure.
2. Good insight of designing data collection strategies, including log sources, event types, and data normalization techniques, to ensure maximum coverage and accuracy.
3. Implementation knowledge of correlation rules, use cases, and threat intelligence feeds to enhance detection capabilities and reduce false positives.
4. Knowledge of integration with other security tools and platforms for seamless information sharing and incident response.
5. Hand-on knowledge in deployment and configuration of SIEM components, including collectors, aggregators, correlation engines, and user interfaces, based on architectural designs.
6. Develop and maintain SIEM integrations, ensuring comprehensive security monitoring and threat detection capabilities.
7. Manage the ingestion of diverse data sources into Splunk, ensuring data quality and consistency.
8. Ensure Splunk deployments adhere to security best practices and compliance requirements.
9. Identify and resolve issues related to Splunk performance, data integrity, and security.
10. Work closely with cross-functional teams, including IT, security, and operations, to align Splunk solutions with business objectives.
11. Maintain comprehensive documentation of Splunk configurations, processes, and procedures.
Key skills/knowledge/experience:
1. Knowledge of integration with other security tools and platforms for seamless information sharing and incident response.
2. Design and implement scalable Splunk architectures to meet the needs of our enterprise environment.
#J-18808-Ljbffr