Splunk Developer
Posted 2 days 2 hours ago by ThoughtLabs Belgium
Permanent
Not Specified
Other
Brussel, Belgium
Job Description
Role:
- Interact with the different customers to capture and define requirements for the development and testing of the threat detection capabilities
- Cooperate with log source onboarding team to assure correct log source onboarding and log mapping to data models according to Splunk standard processes
- The development and tuning and continuous improvement of correlation rules
- Develop and maintain dashboards, reports, and alerts
- Create Splunk Knowledge Objects to address customers needs in context of using Splunk as security tool
- Prepare correlation search tests, conduct tests, and document evidence from test that shows correlation search addresses scenario described in use case
- Responsible for the creation of procedures, high-level/low-level documentation, implementation of processes and development of staff in relation to SIEM detection logic
- Coach a team (from a technical perspective); review work outputs and provide quality assurance
- Analyses and identifies areas of improvement with existing processes, procedures, and documentation
- Demonstrates how to use SIEM & Enterprise Security products to both technical/non-technical personnel
- Provides expert technical advice and counsel in the design, monitoring and improvement of SIEM security systems
- Prioritize and coordinate backlog of threat detection requests, making sure we have a healthy balance between defect resolution and new features
Qualifications:
Technical Skills:
- In depth experience in development and maintenance of SIEM use cases
- Fluent in Splunk's search processing language (SPL)
- Excellent knowledge of Splunk Enterprise and Splunk Enterprise Security
- Sound knowledge about Splunk Common Information Model and log normalization using Data Models
- Solid understanding of cybersecurity technologies, protocols, and applications
- Excellent English communication skills (written and oral)!