← Back to jobs

VDart Logo
Security Platform Engineer

VDart

 

United States

Posted On: 30+ days ago
Experience: 5+ years
Availability: Remote
Openings: 1
Category: Platform Engineer
Tenure: Contract - Corp-to-Corp
Related Jobs

No related jobs found

Description

Key Responsibilities:

•            Design, implement, and maintain Splunk Enterprise and Splunk Enterprise Security environments.

•            Deploy, configure, and manage Cribl Stream for log routing, filtering, masking, enrichment, and optimization.

•            Develop and maintain data onboarding pipelines from various security and infrastructure sources.

•            Configure and troubleshoot log ingestion, parsing, normalization, CIM mapping, and data models.

•            Optimize Splunk searches, dashboards, reports, and correlation searches for performance and scalability.

•            Build and maintain detection use cases, alerts, and security monitoring content.

•            Develop automation workflows using SOAR platforms such as Tines, Splunk SOAR, Cortex XSOAR, or similar automation tools.

•            Integrate security tools including Microsoft Defender, CrowdStrike, Palo Alto, Zscaler, Okta, Azure, AWS, and other enterprise technologies.

•            Perform troubleshooting of ingestion issues, parsing problems, search performance, and distributed architecture.

•            Work closely with SOC analysts, security engineers, architects, and infrastructure teams.

•            Implement best practices for platform monitoring, health checks, capacity planning, and upgrades.

•            Create technical documentation, SOPs, and operational runbooks.

Required Skills

•            5+ years of hands-on experience with Splunk Enterprise.

•            Strong experience administering and supporting Splunk Enterprise Security (ES).

•            Hands-on experience with Cribl Stream administration and pipeline development.

•            Strong understanding of log onboarding, parsing, field extraction, normalization, and CIM.

•            Experience with Splunk Search Processing Language (SPL).

•            Experience with index management, forwarders, deployment server, search heads, indexers, and clustered environments.

•            Experience integrating cloud and security products with Splunk.

•            Knowledge of Linux administration and troubleshooting.

•            Experience with REST APIs and JSON.

•            Scripting experience using Python, PowerShell, or Bash.

•            Strong troubleshooting and analytical skills.

Preferred Skills

•            Experience with security automation platforms such as Tines, Splunk SOAR, Cortex XSOAR, Swimlane, or Torq.

•            Experience with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto, AWS, Azure, or GCP.

•            Knowledge of MITRE ATT&CK framework.

•            Familiarity with security operations and incident response workflows.

•            Experience with Git, CI/CD, and Infrastructure as Code.

•            Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Cribl Certified User/Admin, or security certifications such as CISSP or GIAC.

Nice to Have

•            Experience designing enterprise SIEM architectures.

•            Experience with threat detection engineering.

•            Experience implementing SOC automation and orchestration workflows.

•            Exposure to cloud-native security monitoring and observability platforms

Education

Bachelor's degree

Related Jobs

No related jobs found

← Back to jobs