Internal Firm Services
Industry/Sector
Management Level
Associate
At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies
They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to safeguard sensitive data Those in application security at PwC will be responsible for providing security services to development teams including code scanning, readiness testing, and penetration testing to enable application teams to build and deploy secure applications in Production You will utilise a riskbased methodology and shiftleft approach to engage early in the software development lifecycle
At PwC, you will be part of a vibrant community of solvers that leads with trust and creates distinctive outcomes for our clients and communities
This purposeled and valuesdriven work, powered by technology in an environment that drives innovation, will enable you to make a tangible impact in the real world We reward your contributions, support your wellbeing, and offer inclusive benefits, flexibility programmes and mentorship that will help you thrive in work and life Together, we grow, learn, care, collaborate, and create a future of infinite experiences for each other Learn more about us
At PwC, we believe in providing equal employment opportunities, without any discrimination on the grounds of gender, ethnic background, age, disability, marital status, sexual orientation, pregcy, gender identity or expression, religion or other beliefs, perceived differences and status protected by law
We strive to create an environment where each one of our people can bring their true selves and contribute to their personal growth and the firm s growth To enable this, we have zero tolerance for any discrimination and harassment based on the above considerations
& Summary
Join our Global Cyber Logging Platform Operation team as a pivotal player in managing the centralized data management and analytics platform using Splunk
Your role is crucial in ensuring the integrity, security, and performance of our logging infrastructure, while driving continual improvement and innovation Applicants should have at least 1 year experience in Splunk Enterprise / SIEM administration & management, and a good understanding of networking & Linux
SIEM Platform Management & Administration
o Monitoring, administration, and optimization of the Splunk Enterprise platform to ensure efficient
log management and effective security information and event management (SIEM)
o Conduct regular Splunk Infra & Ingestion health checks and monitoring to keep the environment
robust and healthy for our stakeholders
o Monitor & Keep the Splunk Enterprise instances in good health to serve our customers by keeping platform up & running 24/7
Troubleshooting & Problem Solving
o Actively identify issues using Monitoring , investigate the rootcause, troubleshoot and fix the Splunk
platform issues & problems related to log source outages, parsing errors, time discrepancies, user
problems and more
o Conduct Root Cause Analysis (RCA) to systematically address recurring issues and streamline
problem mitigation
SIEM Configuration Management & Enduser Support
o Support the deployment and configuration of Splunk solutions at enterprise level, ensuring seamless
log integration and issue resolution
o Manage enduser service requests, oversee Splunk access control, and enforce access restrictions to
maintain secure and efficient user management
o Ensure optimal platform performance through regular consolidation, cleanup, and configuration
adjustments
Innovation, Analytics, & Continuous Improvement
o Enhance Splunk operations by implementing innovative solutions that improve efficiencies and automate processes, while integrating emerging technologies to optimize performance
Leverage machine learning and AI to deliver advanced analytics insights, predictive models, and strategic datadriven visualizations for informed decisionmaking Migration & Collaborations o Handle SIEM server offboarding and migration, managing Cloud/Onprem Splunk forwarders (UF/HF) and log source migration projects o Foster collaboration with multiple global teams like cybersecurity, IT, and business units, while streamlining processes and documentation to boost efficiency & platform stability
Mandatory skill sets
- Splunk admin, splunk developer, SIEM
Preferred skill sets
Linux, splunk
SIEM & Data Analytics Expertise Demonstrated knowledge in SIEM solutions and data analytics tools, particularly SPLUNK
o Networking Fundamentals Good understanding of networking principles, traffic analysis, and operating systems (Windows & Unix/Linux) TCP/IP and DNS resolution Proficient with traffic analysis & Tshoot tools Wireshark, TCPdump, Name lookup etc o Linux/UNIX Proficiency Competence in Linux/UNIX environments, including scripting skills with Regular Expressions o SIEM Practical Experience Handson experience in deploying and operating Splunk / other SIEM solutions is crucial Splunk certifications are highly desirable o Security Domain Knowledge Understanding of security domain applications and their integration within SIEM frameworks to support robust cybersecurity operations o Communication Strong written and verbal communication skills in English
Years of experience required
1+ yrs
Education qualification
Any Ug/Pg
Education
Degrees/Field of Study required Bachelor of Technology, Master of Engineering
Degrees/Field of Study preferred
Required Skills
Firewalls, Linux, Networking Support, Splunk (Inactive)
Splunk Administration
No