Splunk Engineer

9 - 12 years

15 - 30 Lacs

Posted:1 day ago| Platform: Naukri logo

Apply

Work Mode

Hybrid

Job Type

Full Time

Job Description

Role & responsibilities

Role Overview:
The Splunk Engineer / Administrator will be responsible for designing, implementing, and maintaining Splunk environments, including SIEM, SOAR, and UEBA components. This role supports security operations by enabling advanced analytics, automation, and incident response capabilities.

Key Responsibilities:
SIEM (Splunk Enterprise Security): • Administer and optimize Splunk Enterprise Security (ES) for log management, ingestion, normalization, and correlation. • Develop and maintain dashboards, alerts, saved searches, and reports. • Onboard data sources and ensure CIM compliance. • Implement risk scoring models to identify suspicious access events and reduce false positives. SOAR (Security Orchestration, Automation, and Response): • Administer Splunk SOAR (formerly Phantom), including cluster and PostgresDB environments. • Develop and maintain playbooks for automated incident response. • Create Python-based custom functions to enhance playbook capabilities. • Integrate AI models to improve alerting and operational efficiency. UEBA (User and Entity Behavior Analytics): • Develop use cases and dashboards for behavior analytics. • Integrate UEBA models with Splunk ES and SOAR for enhanced threat detection. General Splunk Administration: • Install, configure, and troubleshoot Splunk components (indexers, search heads, forwarders). • Develop custom Splunk apps and add-ons using SPL, Python, SimpleXML, JavaScript, or Bash. • Monitor and troubleshoot performance issues. • Ensure compliance with ISO27001, ITIL, and internal security standards.

Required Skills & Experience:
• 5+ years of experience in Splunk administration and engineering. • Strong knowledge of Splunk architecture, SPL, and data modeling. • Experience with Python, Bash, and web technologies (JavaScript, CSS). • Familiarity with SIEM, SOAR, and UEBA concepts and tools. • Experience in a Cyber Security Operations Center (CSOC) is a plus.

Certifications:
• Splunk Enterprise Certified Architect (Required) • Splunk ES Administration Certification (Required) • Splunk SOAR Administration Certification (Required) • Splunk UEBA Administration Certification (Required) • Splunk Core Certified Consultant (Preferred)

Education:
• Bachelors degree in Computer Science, Information Technology

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Capgemini logo
Capgemini

IT Services and IT Consulting

Paris France

RecommendedJobs for You

pune, chennai, bengaluru

chennai, tamil nadu, india