Senior Cybersecurity Specialist (Splunk Engineer)
الوصف الوظيفي
About The Role
GreenZone is seeking a highly skilled and experienced Senior Cybersecurity Specialist (Splunk Engineer) to join our Cyber Engineering team in Riyadh, Saudi Arabia. In this critical role, you will be responsible for designing, implementing, and maintaining robust security systems across both internal and client environments. The ideal candidate will collaborate closely with leadership, Security Operations Center (SOC) analysts, threat analysts, solution architects, fellow security engineers, and clients to deliver high-impact, mission-critical managed security services (MSS) to our valued customers.
This position is based in Riyadh, Saudi Arabia, within the Cyber Engineering department. Your primary focus will be the administration, maintenance, and integration of SOC technologies, including SIEM, EDR, NDR, Vulnerability Assessment (VA), SOAR, and other cutting-edge cybersecurity platforms. Your expertise will play a pivotal role in enhancing our security posture and ensuring the resilience of our clients’ digital assets.
Key Responsibilities
- Splunk Administration and Development: Administer and configure Splunk and Splunk Apps, extending their functionality to meet specialized requirements. Integrate Splunk with diverse legacy data sources to enhance data visibility and analysis.
- Microsoft Security Integration: Design, implement, and support Microsoft security technologies, including Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, Microsoft Sentinel, and related integrations to strengthen our security framework.
- Vulnerability Management: Lead the implementation, deployment, and support of vulnerability scanning engines in coordination with Engineering, SOC, and Incident Response teams. Document vulnerabilities, assess risks, and support remediation activities in alignment with agreed service level agreements (SLAs).
- EDR Management: Oversee the deployment, operation, maintenance, and administration of EDR sensors, including updates, upgrades, and patching to ensure optimal performance and security.
- Threat Detection and Response: Develop advanced correlation searches, lookups, watchlists, dashboards, and alerts to identify Indicators of Compromise (IoCs), suspicious behavior, and emerging threats. Continuously refine detection mechanisms to minimize false positives and enhance accuracy.
- Client-Centric Solutions: Assess customer needs and expectations, design tailored security solutions, and implement them to meet those requirements. Act as a primary responder for Managed Security customer systems, taking ownership of client configuration issues and driving them to resolution.
- Collaboration and Process Enhancement: Work closely with SOC team members to execute operational tasks and initiatives aimed at improving service quality. Proactively contribute to fine-tuning processes and enhancing the overall effectiveness of our MSS offerings.
- Content Development: Create and maintain SOC technology content, such as use cases for Splunk, in collaboration with SOC analysts to ensure robust threat detection and response capabilities.
Qualifications & Skills
- Technical Expertise: Minimum of 3 years of professional experience supporting and maintaining Splunk SIEM and Enterprise Security. Additional experience with platforms such as Fortinet (SIEM, SOAR, XDR), Google Security Operations, Symantec (ASG, DLP, SMG, CASB), Netskope, Palo Alto, or Tenable is highly advantageous.
- Advanced Splunk Proficiency: 3-5 years of hands-on experience with advanced tuning of Splunk SIEM content, including the development of custom dashboards, alerts, and correlation rules.
- Network and Security Knowledge: Professional experience working with networks and network architecture, coupled with a strong understanding of information security principles. Familiarity with EDR solutions such as Carbon Black, Vectra, and Microsoft Azure is essential.
- Certifications and Education: Bachelor’s degree or equivalent training in a relevant field, along with professional experience in a Security Operations Center, Managed Security, or client network environment. Certifications such as Splunk Admin, Splunk Architect, or Splunk Consultant are highly desirable.
- Operating Systems Proficiency: In-depth knowledge of Linux and Windows operating systems to support diverse security environments.
- Additional SIEM Experience: Experience with other SIEM solutions, such as QRadar or LogRhythm, is preferred.
- Client-Facing Experience: Proven track record of working with clients in a service delivery capacity, demonstrating strong communication and problem-solving skills.
- Flexibility and Support: Willingness to work flexible shifts, including after-hours support, to ensure the continuous protection of our clients’ environments.
If you are a dedicated cybersecurity professional with a passion for Splunk and a commitment to delivering exceptional security services, we invite you to apply and become an integral part of our dynamic team.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.