2 дня назад
SIEM Architect & Engineer (CISO)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SIEM Architect & Engineer (CISO) (Splunk/SIEM): Designing, implementing, and managing Splunk infrastructure and Security Operations Center capabilities with an accent on clustered deployments, data onboarding, security integrations, and Enterprise Security correlation. Focus on building technology add-ons and Splunk apps, integrating threat intelligence, managing security data pipelines, and improving SecOps operations.
Location: Makati City, Philippines; hybrid and flexible working
Company
is a Switzerland-founded provider of wealth management technology and services for financial institutions, serving banks and investment managers worldwide.
What you will do
- Design, implement, optimize, and manage Splunk infrastructure, including indexer clusters, search head clusters, deployment servers, and monitoring consoles.
- Onboard data sources, create indexes and data models, develop CIM-compliant mappings, and establish health monitoring and KPIs.
- Integrate Splunk with legacy sources, security tools, cloud services, REST APIs, and relational databases.
- Build Splunk technology add-ons, custom scripts, and applications for large-scale Universal Forwarder deployments.
- Design Enterprise Security correlation searches, connect asset and identity data, and onboard threat intelligence feeds.
- Support Security Analysts, transform SecOps operations, and identify technology and security gaps for continuous improvement.
Requirements
- Splunk Architect or Splunk Consultant certification, or proven Splunk Professional Services experience.
- At least five years of experience as a Splunk Architect or in a higher-level role, including experience designing and implementing a Splunk-based Security Operations Center.
- Strong knowledge of Splunk architecture, SPL, regular expressions, data pipelines, knowledge objects, role-based access control, and Enterprise Security.
- Experience with automated deployment and version control tools such as Git and Terraform.
- Knowledge of security components, cloud service providers preferably OCI, Linux and Windows administration, Kubernetes, containerized architectures, and network protocols.
- Ability to troubleshoot and resolve issues independently, communicate clearly, support infrastructure teams, and remain calm during critical events.
Nice to have
- Knowledge of SOAR platforms.
- Linux administration experience with RHEL.
Culture & Benefits
- Hybrid and flexible working options are available for most employees.
- Support for work-life balance in a global office environment.
- Inclusive and equal-opportunity workplace.
- Collaboration with financial institutions and colleagues across multiple countries.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →