Job 1000 van 1000


Report this listing

Solliciteren



Splunk Developer (Threat Detection Consultant)


Splunk Developer (Threat Detection Consultant) – Brussels / London / Paris / Amsterdam – Banking Client Duration: 1 year - Freelance ContractorRate: 500 – 800 per dayHybrid: 2 days onsite per week (London, Paris, Brussels or Amsterdam)Role:Interact with the different customers to capture and define requirements for the development and testing of the threat detection capabilitiesCooperate with log source onboarding team to assure correct log source onboarding and log mapping to data models according to Splunk standard processesThe development and tuning and continuous improvement of correlation rulesDevelop and maintain dashboards, reports, and alertsCreate Splunk Knowledge Objects to address customers needs in context of using Splunk as security toolPrepare correlation search tests, conduct tests, and document evidence from test that shows correlation search addresses scenario described in use caseResponsible for the creation of procedures, high-level/low-level documentation, implementation of processes and development of staff in relation to SIEM detection logicCoach a team (from a technical perspective); review work outputs and provide quality assuranceAnalyses and identifies areas of improvement with existing processes, procedures, and documentationDemonstrates how to use SIEM Enterprise Security products to both technical/non-technical personnelProvides expert technical advice and counsel in the design, monitoring and improvement of SIEM security systemsPrioritize and coordinate backlog of threat detection requests, making sure we have a healthy balance between defect resolution and new featuresQualifications:Technical Skills:In depth experience in development and maintenance of SIEM use casesFluent in Splunk’s search processing language (SPL)Excellent knowledge of Splunk Enterprise and Splunk Enterprise SecuritySound knowledge about Splunk Common Information Model and log normalization using Data ModelsSolid understanding of cybersecurity technologies, protocols, and applicationsExcellent English communication skills (written and oral)!Nice to have:Splunk Core Certified (Advanced) Power User (crucial)Splunk Certified Developer (nice to have)Splunk Enterprise Certified Admin (nice to have)Splunk Enterprise Security Certified Admin (nice to have)Any other Security Certifications (e.g. CEH, GIAC, CISSP, OSCP ...)Soft Skills:Strong analytical skills to evaluate sophisticated multivariate problems and find a systematic approach to gain a quick resolution, often under stressStrong problem solving, documentation, process execution, time management and organizational skills.Ability to communicate sophisticated information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual meansFast and independent learner, with ambition to self-improveAt ease in a fast-changing environment, flexible and pragmatic, open-mindedAccurate, acting with attention to detailsClient focus and delivery orientedA team-focused mentality with ability to work collaborate effectively in a team environmentGood leadership and communication skills, whether on the field, in the team or with management: you are a keen standout colleague and coordinate work among people from different areas or divisions. A good relationship builder with strong diplomacy skillsAbility to work autonomouslyRemote working:A minimum office presence of eight days per month is required.Please do send across to me the most up to date CV to eobiechefu@welovesalt.com

Solliciteren

Meer banen van je zoekopdracht