img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعجدة

وصف الوظيفة

About the Role

FNRCO is seeking a Senior Splunk SIEM Engineer Managed Services Consultant to join their team in Makkah, with work locations including Jeddah and Makkah. This full-time role requires a professional with 5-10 years of experience in Splunk Enterprise and SIEM environments, focusing on administration, security use case development, and operational support.

Key Responsibilities

  • Administer the Splunk Enterprise environment, including solution deployment, user management, license management, upgrades, patch deployment, and managing log sources.
  • Onboard new log sources and troubleshoot issues if logs are not being sent to Splunk.
  • Develop security use cases using Splunk Enterprise Security and construct SIEM content such as correlation rules, reports, and queries.
  • Manage support tickets with SIEM support as necessary.
  • Periodically review existing Splunk configurations and propose enhancements.
  • Continuously review and develop use cases, dashboards, alerts, and reports.
  • Create and add custom correlation rules for devices based on business requirements.
  • Support audits conducted by regulators in the Kingdom by providing relevant evidence from the SIEM solution.
  • Develop parsing rules for non-standard logs.
  • Configure threat feeds, IoCs, Sigma rules, and advisories from regulators and globally recognized organizations.
  • Administer the Splunk UBA environment, including ingesting CIM-compliant data, raw events, and HR data.
  • Manage UBA health using the Splunk UBA Monitoring App and perform backups/failovers.

Qualifications and Experience

  • A minimum of 5 years of experience in Splunk Enterprise administration and SIEM engineering is required, with a preference for candidates having 5-10 years of experience.
  • Demonstrated experience in the deployment, configuration, and management of Splunk Enterprise environments.
  • Proficiency in developing security use cases and SIEM content.
  • Experience with Splunk UBA administration and data ingestion.

Work Environment

This is a full-time position based in the Makkah region, with responsibilities covering both Jeddah and Makkah. The role involves working within a managed services framework, providing critical support and development for security information and event management systems.

Application Process

Candidates who meet the specified requirements are encouraged to apply. Salary details will be discussed during the interview process.


متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة