7 дней назад
SIEM Engineer – Splunk & Splunk Cloud
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SIEM Engineer – Splunk & Splunk Cloud (Cybersecurity): Engineering and supporting enterprise Splunk environments, onboarding security data sources, and improving detection capabilities with an accent on Splunk Cloud, SPL searches, and platform reliability. Focus on integrating Microsoft 365, Azure, AWS, EDR, and identity data, troubleshooting ingestion and performance issues, and supporting SOC investigations.
Location: Macquarie Park, New South Wales, Australia; in-person collaboration is prioritized.
Company
delivers enterprise technology, software, managed infrastructure, application modernisation, and industry-specific solutions for global enterprises and public sector organisations.
What you will do
- Engineer and support Splunk Enterprise and Splunk Cloud environments.
- Manage indexers, search heads, forwarders, apps, and add-ons.
- Onboard and troubleshoot security log sources across Microsoft 365, Azure, AWS, EDR, and identity platforms.
- Develop and tune SPL searches, alerts, and dashboards to improve threat detection.
- Support SOC teams with detection and investigation requirements.
- Resolve ingestion, search, and platform performance issues while maintaining technical documentation and procedures.
Requirements
- Strong experience with Splunk Enterprise and/or Splunk Cloud, SPL, SIEM, Splunk CIM, apps/add-ons, and forwarders.
- Experience onboarding security logs across multiple platforms and understanding SIEM, SOC operations, and threat detection.
- Experience with syslog, APIs, JSON, XML, and regular expressions.
- Strong troubleshooting skills across Linux, Windows, and cloud environments.
- Strong communication and stakeholder management skills.
- Ability to obtain an Australian Government Security Clearance.
Nice to have
- Google SecOps and YARA-L, Microsoft Sentinel and KQL, or Sumo Logic and Cloud SIEM experience.
- Experience with Microsoft Defender, Azure Security, AWS Security, Palo Alto, CrowdStrike, or SOAR platforms.
- Automation, scripting, Git, or Infrastructure as Code experience.
- Splunk, Microsoft, or cybersecurity certifications.
Culture & Benefits
- Full-time employment with competitive remuneration and benefits.
- Training and career development opportunities.
- Inclusive culture focused on belonging, wellbeing, and corporate citizenship.
- In-person collaboration with flexibility for individual work styles and life circumstances.
- Participation in an on-call roster, typically one to two weeks per month.
Hiring process
- Submit a resume through the application process.
- Hiring is described as thorough and fair.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
10 часов назад
Security Operations Centre Specialist (Cybersecurity)
1 день назад
SOC Incident Responder (Cybersecurity)
4 дня назад
Senior Security Platform Engineer (SIEM and SOAR)
7 дней назад
SOC Analyst (Cybersecurity)
Airwallex
6 дней назад
Staff Product Security Engineer (Cybersecurity)
3 дня назад