Splunk SIEM Specialist

5 - 8 years

13 - 22 Lacs

Posted:4 days ago| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Job Title: Splunk SIEM Specialist

Position Overview

Splunk SIEM Specialist

Key Responsibilities

  • Lead and execute

    SIEM migrations and implementations

    , including planning, deployment, and validation.
  • Onboard and normalize diverse

    log sources

    into Splunk, ensuring CIM (Common Information Model) compliance.
  • Develop and optimize

    detection content

    such as correlation rules, dashboards, alerts, and reports.
  • Troubleshoot and resolve issues related to

    log ingestion, parsing, and Splunk platform performance

    .
  • Perform regular

    platform administration and optimization

    including indexing, storage, and search tuning.
  • Manage Splunk components (

    indexers, search heads, forwarders

    ) and oversee upgrades and patches.
  • Deploy and configure Splunk SIEM solutions across

    on-premises and cloud environments

    .
  • Conduct

    gap analysis

    of log sources and use cases; develop new use cases aligned with emerging threats.
  • Collaborate with stakeholders and security teams to deliver actionable monitoring and threat detection solutions.

Required Skills & Qualifications

  • Minimum

    3 years of hands-on experience with Splunk SIEM

    (Enterprise Security preferred).
  • Strong understanding of

    SIEM concepts, log management, and SOC operations

    .
  • Proven experience in

    log source onboarding, parsing, and CIM compliance

    .
  • Expertise in

    detection content creation

    (correlation rules, dashboards, alerts) and tuning.
  • Solid troubleshooting skills for both

    Splunk platform and security content

    .
  • Experience in

    Splunk deployment, administration, and health monitoring

    .
  • Ability to conduct

    gap analysis

    and provide actionable recommendations.
  • Strong

    communication and documentation

    skills.
  • Relevant certifications (e.g.,

    Splunk Certified Admin, Splunk Enterprise Admin, Splunk Certified Architect

    ) are an advantage.

Preferred Experience

  • Strong knowledge of

    security fundamentals and threat detection

    .
  • Hands-on experience with

    cloud SIEM deployments

    (AWS, Azure, GCP).
  • Familiarity with

    scripting languages (Python, Bash)

    for automation.
  • Exposure to other SIEM platforms (

    QRadar, Sentinel, XSIAM, SecOps

    ) is beneficial.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Kiya.ai logo
Kiya.ai

Human Resources Technology

Vancouver

RecommendedJobs for You

mumbai, navi mumbai, mumbai (all areas)

hyderabad, pune, bengaluru

pune, bengaluru, mumbai (all areas)

hyderabad, chennai, bengaluru