Splunk Enterprise Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Splunk Enterprise Security Engineer: Managing and optimizing the Splunk ES platform for enterprise-scale security operations with an accent on detection engineering, data normalization, and platform stability. Focus on implementing Risk-Based Alerting (RBA), tuning correlation searches, and enabling SOC teams to effectively detect and respond to complex security threats.
Location: Must be based in Cyberjaya, Selangor, Malaysia (Hybrid role)
Company
A global leader in business and technology services, specializing in SAP solutions and AI-driven innovation with a presence in over 70 countries.
What you will do
- Own and manage the Splunk Enterprise Security platform, ensuring high availability, performance, and scalability.
- Lead the onboarding of security-relevant data sources while ensuring CIM compliance and data quality.
- Develop, customize, and tune detection use cases to align with SOC requirements and reduce alert fatigue.
- Implement and mature Risk-Based Alerting (RBA) to improve signal-to-noise ratios.
- Collaborate with SOC analysts to support alert triage, investigations, and incident response workflows.
- Build and maintain dashboards for SOC performance metrics, detection coverage, and risk trends.
Requirements
- Minimum 3 years of hands-on experience with Splunk Enterprise including administration and troubleshooting.
- Minimum 2 years of hands-on experience with Splunk Enterprise Security (ES).
- Strong expertise in SPL, data models, CIM, and knowledge objects.
- Proven experience in detection engineering and SIEM content development.
- Must be willing to work in Cyberjaya, Selangor.
- Strong analytical and problem-solving skills with the ability to communicate technical concepts to non-technical stakeholders.
Nice to have
- Splunk certifications (e.g., Core Certified Power User, Enterprise Security Certified Admin).
- Experience with SOAR platforms and security automation.
- Knowledge of MITRE ATT&CK framework and threat modelling.
- Experience operating SIEM in regulated or large enterprise environments.
Culture & Benefits
- Team-oriented corporate culture with steady knowledge transfer.
- Commitment to Diversity & Inclusion initiatives.
- Flexible working hours with hybrid work arrangements.
- Access to Inhouse Academy, SAP Learning Hub, and certification opportunities.
- Comprehensive company health benefits including medical, dental, and optical coverage.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →