Security Consultant -Splunk Implementation & Integration Specialist

5 - 8 years

15 - 20 Lacs

Posted:None| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

About the Role:

Security Consultant-Splunk

deployment and configuration of Cribl

Key Responsibilities:

1. SIEM Design & Implementation

  • Architect and deploy Splunk environments (single/multi-site, indexer/search head clustering).

  • Define and implement data ingestion strategies.

  • Configure Splunk components: UF/HF, indexers, deployment servers, apps, etc.

  • Cribl

2. Log Source Onboarding

  • Identify and prioritize IT, cloud, network, and application log sources.

  • Develop onboarding playbooks and custom parsing logic.

  • Configure props.conf, transforms.conf, and onboard into CIM-compliant structure.

3. Use Case Development & Configuration

  • Collaborate with SOC to translate detection requirements into correlation rules and alerts.

  • Splunk Enterprise Security (ES)

  • Optimize SPL queries and tune alerts to reduce noise and false positives.

4. Tool Integration

  • Integrate Splunk with platforms including:

    • SOAR solutions: Splunk SOAR, Palo Alto XSOAR

    • TIPs: Anomali, open-source feeds

    • Ticketing tools: ServiceNow, JIRA

    • EDR/NDR solutions: CrowdStrike, Fortinet, Cisco, etc.

  • Develop and manage APIs and automation scripts for bi-directional integration.

5. Documentation & Knowledge Transfer

  • Prepare HLDs/LLDs, operational SOPs, and architecture diagrams.

  • Create runbooks and ensure configuration backups.

  • Conduct KT sessions and operational training for SOC teams.

Required Skills & Experience:

  • 5+ years in SIEM implementation (3+ years focused on Splunk)

  • Splunk SIEM, Splunk SOAR, and Cribl deployment/configuration

  • Skilled in SPL (Search Processing Language), CIM compliance, and log enrichment

  • Hands-on with onboarding data from varied sources and environments

  • Experience integrating tools and building automation with Python, Bash, etc.

Preferred Certifications:

  • Splunk Core Certified Power User

  • Splunk Certified Admin / Architect

  • Splunk Enterprise Security Certified Admin (preferred)

  • CompTIA Security+, GCIA, or CISSP (nice to have)

 

Mock Interview

Practice Video Interview with JobPe AI

Start Python Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Python Skills

Practice Python coding challenges to boost your skills

Start Practicing Python Now

RecommendedJobs for You