Назад
Company hidden
4 дня назад

Security Operations Center Engineer (Splunk)

Формат работы
remote (только Europe)/onsite
Тип работы
fulltime
Грейд
middle
Английский
b1
Страна
Ukraine/Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Operations Center Engineer (Splunk): Strengthening enterprise security monitoring and detection capabilities through Splunk and Splunk Enterprise Security with an accent on detection engineering, SIEM data quality, and complex incident investigations. Focus on tuning correlation searches, expanding threat coverage, integrating security platforms, and applying automation, SOAR, and AI-enabled technologies.

Location: Poland or Ukraine; remote/office work

Company

hirify.global provides engineering and technology services, including cybersecurity operations and enterprise security solutions.

What you will do

  • Develop, configure, and maintain Splunk and Splunk Enterprise Security content, including correlation searches, dashboards, reports, data models, and knowledge objects.
  • Create, tune, and optimize SIEM detections to improve alert fidelity, expand threat coverage, and reduce false positives.
  • Onboard, normalize, and validate security data sources, including field extraction, data quality, and Splunk CIM compliance.
  • Investigate complex security alerts and incidents as an L2 escalation point and support L1 analysts during investigations.
  • Build monitoring, incident response, performance tracking, and detection engineering dashboards and reports.
  • Implement security platform integrations and use scripting, automation, SOAR, and AI-enabled technologies to improve operational workflows.

Requirements

  • At least 2 years of hands-on experience in security operations, SOC/CSOC analysis, SIEM engineering, detection engineering, security engineering, or a related cybersecurity role.
  • Strong practical experience with Splunk, Splunk Enterprise Security, and Splunk Search Processing Language.
  • Experience creating and tuning correlation searches, alerts, dashboards, reports, notable events, and SIEM detection content.
  • Knowledge of security data onboarding, normalization, field extraction, log-source coverage, data quality management, and Splunk CIM.
  • Understanding of incident investigation, alert triage, Windows and Linux environments, EDR, IDS/IPS, firewalls, email security, identity services, MITRE ATT&CK, NIST CSF, and ISO 27001.
  • Experience with Python, PowerShell, SOAR, automation technologies, and AI-enabled tools; English proficiency at B1/B2 level or higher.

Nice to have

  • Bachelor’s degree in information technology, computer science, cybersecurity, management information systems, or a related field.
  • Relevant security or Splunk certifications.

Culture & Benefits

  • Work in a Cyber Security Operations Center supporting enterprise-wide security monitoring.
  • Collaborate with Information Security, IT, Delivery teams, CSOC analysts, and platform support teams.
  • Contribute to continuous improvement, security automation, operational documentation, and threat visibility initiatives.
  • Equal opportunity employment regardless of legally protected characteristics.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →