← Back to jobs
Richmond, VA, USA
No related jobs found
Key Responsibilities
·Threat Detection & Monitoring: Continuously monitor network traffic, endpoint logs, and cloud security events for anomalous behavior and potential security incidents.
·Splunk Management: Create, maintain, and tune Splunk correlation searches, alerts, and dashboards to minimize false positives and improve detection capabilities.
·Incident Response: Investigate potential security incidents, follow forensic evidence, and collaborate with IT and network teams to remediate threats.
·Use Case Development: Develop and refine detection and response playbooks based on threat intelligence and frameworks like MITRE ATT&CK.
·Log Integration: Work with infrastructure teams to onboard new data sources, ensuring log integrity, parsing, and normalization across the SIEM platform.
Compliance & Reporting: Support audit readiness by collecting SIEM control evidence and generating compliance reports aligned with internal policies and standards
Bachelor's degree
No related jobs found
← Back to jobs