Tech Stack
AnsibleCyber SecurityDNSLinuxPythonSplunkTCP/IP
About the role
- Act as one of the engineers and Subject Matter Expert (SME) for SIEM and Log Collection services within the Cyber Security Data team.
- Support in SIEM (Splunk) infrastructure management and log collection.
- Manage log collection of new data log sources in SIEM.
- Document all relevant information in Confluence.
- Detecting and reporting any service degradation.
- Following best practices for maintaining the Splunk environment in a stable and reliable state with the objective of preventing any service degradation.
- Ensure that data security systems are installed, configured, and operating correctly and in line with dependencies with others systems or applications required.
Requirements
- A good understanding of IT Security
- At least 2 years of relevant experience and strong technical skills in administering, deploying, installing, configuring and maintaining large distributed Splunk Enterprise environment.
- Good programming skills in at least one of these languages: Ansible.python or bash.
- A good understanding of networking and various protocols such as TCP/IP, HTTP(S), DNS.
- Very good knowledge and proven experience of Linux system and application administration and troubleshooting.
- Strong reporting skills to various levels of seniority.
- Fluent in English at least at a level B2.