Назад
Company hidden
обновлено 1 час назад

Splunk Enterprise Security Engineer

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle/senior
Английский
b2
Страна
Malaysia
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Splunk Enterprise Security Engineer: Managing and optimizing the Splunk ES platform for enterprise-scale security operations with an accent on detection engineering, data normalization, and platform stability. Focus on implementing Risk-Based Alerting (RBA), tuning correlation searches, and enabling SOC teams to effectively detect and respond to complex security threats.

Location: Must be based in Cyberjaya, Selangor, Malaysia (Hybrid role)

Company

A global leader in business and technology services, specializing in SAP solutions and AI-driven innovation with a presence in over 70 countries.

What you will do

  • Own and manage the Splunk Enterprise Security platform, ensuring high availability, performance, and scalability.
  • Lead the onboarding of security-relevant data sources while ensuring CIM compliance and data quality.
  • Develop, customize, and tune detection use cases to align with SOC requirements and reduce alert fatigue.
  • Implement and mature Risk-Based Alerting (RBA) to improve signal-to-noise ratios.
  • Collaborate with SOC analysts to support alert triage, investigations, and incident response workflows.
  • Build and maintain dashboards for SOC performance metrics, detection coverage, and risk trends.

Requirements

  • Minimum 3 years of hands-on experience with Splunk Enterprise including administration and troubleshooting.
  • Minimum 2 years of hands-on experience with Splunk Enterprise Security (ES).
  • Strong expertise in SPL, data models, CIM, and knowledge objects.
  • Proven experience in detection engineering and SIEM content development.
  • Must be willing to work in Cyberjaya, Selangor.
  • Strong analytical and problem-solving skills with the ability to communicate technical concepts to non-technical stakeholders.

Nice to have

  • Splunk certifications (e.g., Core Certified Power User, Enterprise Security Certified Admin).
  • Experience with SOAR platforms and security automation.
  • Knowledge of MITRE ATT&CK framework and threat modelling.
  • Experience operating SIEM in regulated or large enterprise environments.

Culture & Benefits

  • Team-oriented corporate culture with steady knowledge transfer.
  • Commitment to Diversity & Inclusion initiatives.
  • Flexible working hours with hybrid work arrangements.
  • Access to Inhouse Academy, SAP Learning Hub, and certification opportunities.
  • Comprehensive company health benefits including medical, dental, and optical coverage.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →