Posted:2 days ago| Platform: Linkedin logo

Apply

Work Mode

On-site

Job Type

Full Time

Job Description

Role: Splunk SME

Experience: 10+ years

Location: Hyderabad

Must-Have: log management and SIEM concepts. Experience with Splunk administration, deployment, and health monitoring. Experience in content development (correlation rules, dashboards, alerts) and tuning.

Good-to-Have: Splunk Certified Admin, Splunk Certified Architect) are a plus.

Roles & Responsibilities:

Implement and configure Splunk SIEM solutions tailored to organizational security requirements. Onboard diverse log sources into Splunk, ensuring data is parsed and normalized according to the Common Information Model (CIM). Develop and maintain data models, field extractions, and event parsing logic. Design, develop, and tune detection rules, correlation searches, dashboards, and alerts. Continuously optimize content to reduce false positives and improve detection accuracy. Monitor and maintain the health, availability, and scalability of the Splunk environment. Perform regular platform optimization, including indexing, storage management, and search performance tuning. Administer Splunk components (indexers, search heads, forwarders, etc.) and manage upgrades/patches. Collaborate with stakeholders to ensure successful delivery of security monitoring capabilities. Conduct log source and use case gap analysis to identify coverage gaps and recommend enhancements. Work with security teams to develop new use cases aligned with evolving threat landscapes.

Required Skills:

Strong understanding of log management and SIEM concepts. Proficiency in log source onboarding, parsing, and CIM compliance. Experience in content development (correlation rules, dashboards, alerts) and tuning. Solid troubleshooting skills for both Splunk platform and security content. Experience with Splunk administration, deployment, and health monitoring. Familiarity with SIEM optimization techniques and best practices. Ability to conduct gap analysis and develop actionable recommendations.

Excellent communication and documentation skills. Relevant certifications (e.g., Splunk Certified Admin, Splunk Certified Architect) are a plus.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Tata Consultancy Services logo
Tata Consultancy Services

Information Technology and Consulting

Thane

RecommendedJobs for You