img
Contract TypeFull-time
Workplace typeOn-site
LocationJeddah

Job Description

About the Role

Qualified Crew is seeking a dedicated Splunk / SIEM Specialist to join our team in Jeddah and Makkah, Saudi Arabia. This full-time role is central to managing and enhancing our security information and event management infrastructure. The position requires a professional with at least 5 years of experience in Splunk Enterprise administration and security operations.

Splunk Enterprise Administration

The primary responsibility of this role involves the comprehensive administration of the Splunk Enterprise environment. This includes ensuring the optimal performance and security of the platform through various operational tasks.

  • Deployment of Splunk solutions and managing user access.
  • Managing licenses, performing upgrades, and deploying patches.
  • Adding or deleting log sources and configuring the Splunk environment.
  • Implementing and managing change control processes.
  • Managing report generation and ensuring effective backup and recovery procedures.

SIEM Content Development and Operations

This role is crucial for developing and maintaining robust SIEM content to enhance security monitoring and incident response capabilities. The specialist will work with various security tools and data sources.

  • Onboarding new log sources and troubleshooting issues where logs are not being sent to Splunk.
  • Developing security use cases using Splunk Enterprise Security.
  • Constructing SIEM content, including correlation rules, reports, report templates, and queries.
  • Periodically reviewing existing Splunk configurations and proposing enhancements.
  • Continuously developing use-cases, dashboards, alerts, and reports.
  • Creating and adding custom correlation rules based on business requirements.
  • Developing parsing rules for non-standard logs.
  • Configuring threat feeds, IoCs, Sigma rules, and advisories from regulators and global organizations.

Splunk UBA Management

The specialist will also be responsible for the administration and maintenance of the Splunk User Behavior Analytics (UBA) environment, ensuring its effective operation for threat detection.

  • Administering the Splunk UBA environment.
  • Ingesting CIM-compliant data, raw events, and HR data from the Splunk Platform into Splunk UBA.
  • Managing UBA health using the Splunk UBA Monitoring App.
  • Performing backups and failovers for the Splunk UBA environment.

Regulatory Compliance and Support

A key aspect of this role involves supporting regulatory compliance efforts and managing external support interactions related to SIEM solutions.

  • Managing support tickets with SIEM support teams as necessary.
  • Supporting audits conducted by regulators in the Kingdom and providing relevant evidence from the SIEM solution.

Candidate Profile

We are looking for a professional with a strong background in cybersecurity and extensive hands-on experience with Splunk platforms. The ideal candidate will possess the technical expertise to manage complex Splunk and SIEM environments, coupled with a proactive approach to security content development and operational excellence.


Requirements

  • Requires 5-10 Years experience

Similar Jobs