𝐒𝐏𝐋𝐔𝐍𝐊 𝐒𝐈𝐄𝐌 𝐄𝐍𝐆𝐈𝐍𝐄𝐄𝐑 / 𝐒𝐏𝐋𝐔𝐍𝐊 𝐀𝐃𝐌𝐈𝐍𝐈𝐒𝐓𝐑𝐀𝐓𝐎𝐑
الوصف الوظيفي
About Emdad Excellence
Emdad Excellence, a distinguished subsidiary of the Emdad Group, stands at the forefront of delivering innovative, compliant, and efficient human resources and workforce solutions tailored to the evolving needs of modern businesses across Saudi Arabia. With its headquarters strategically located in Riyadh, the company benefits from the robust backing of a group boasting over 10,000 employees and a substantial capital base of SAR 100 million. Emdad Excellence leverages more than two decades of industry expertise and an in-depth understanding of local regulatory frameworks to provide comprehensive, talent-centric workforce services. The company’s mission is to empower organizations through scalable, customized HR solutions that foster sustainable workforce growth and operational excellence. By joining Emdad Excellence, professionals become part of a trusted partner dedicated to delivering unparalleled quality, customer satisfaction, and long-term business success.
Role Overview
We are seeking an experienced and highly skilled Splunk SIEM Engineer / Splunk Administrator to lead the automation workflow for a leading multinational corporation (MNC) based in Jeddah, Saudi Arabia. This critical role requires a seasoned professional with extensive hands-on experience in Splunk Enterprise environments, security information and event management (SIEM), and advanced threat detection capabilities. The ideal candidate will play a pivotal role in enhancing the organization’s cybersecurity posture by optimizing Splunk deployments, ensuring seamless log ingestion, and developing robust security use cases. This position is exclusively open to candidates currently based in Saudi Arabia.
Key Responsibilities
- Splunk Enterprise Administration: Deploy, configure, and manage Splunk Enterprise environments, including user and license administration, system upgrades, patching, backup, and recovery operations.
- Log Source Management: Onboard and manage diverse log sources, troubleshoot log ingestion issues, and ensure data integrity across the SIEM platform.
- Security Use Case Development: Design, implement, and maintain Splunk Enterprise Security (ES) use cases, correlation rules, dashboards, alerts, reports, and advanced queries to enhance threat detection and response capabilities.
- Threat Intelligence Integration: Configure and manage Threat Intelligence feeds, Indicators of Compromise (IoCs), Sigma rules, and security advisories to bolster proactive threat hunting and incident response.
- Regulatory Compliance: Support SIEM audits and ensure adherence to Saudi Arabian regulatory requirements, maintaining robust documentation and compliance frameworks.
- User Behavior Analytics (UBA): Administer Splunk UBA to monitor and analyze user activities, detect anomalies, and mitigate insider threats. Configure CIM-compliant data ingestion, manage raw events, and ensure the health and performance of UBA systems, including backup and failover mechanisms.
- Troubleshooting and Support: Provide expert-level troubleshooting for Splunk-related issues, collaborate with cross-functional teams to resolve technical challenges, and optimize system performance.
Qualifications and Experience
- Technical Expertise: Minimum of 5 years of hands-on experience with Splunk SIEM and Splunk Enterprise environments.
- Security Operations: Proven experience in deploying, configuring, and managing Splunk Enterprise Security, including the development of correlation rules, dashboards, and alerts.
- Log Management: Strong background in onboarding log sources, troubleshooting ingestion issues, and developing parsing rules for non-standard log formats.
- Threat Intelligence: Experience integrating Threat Intelligence feeds, IoCs, and Sigma rules to enhance security monitoring and incident response.
- Regulatory Knowledge: Familiarity with Saudi Arabian regulatory requirements and experience supporting SIEM audits and compliance initiatives.
- UBA Administration: Hands-on experience with Splunk UBA, including configuring CIM-compliant data, managing raw events, and monitoring system health, backups, and failover activities.
- Troubleshooting Skills: Exceptional problem-solving abilities with a strong focus on resolving complex Splunk-related issues efficiently.
- Location Requirement: Candidates must be currently based in Saudi Arabia to be considered for this position.
Why Join Us?
As a valued member of our team, you will have the opportunity to work with a leading multinational corporation, contributing to the enhancement of its cybersecurity infrastructure and operational resilience. Emdad Excellence offers a dynamic and collaborative work environment, competitive compensation packages, and opportunities for professional growth. This role is ideal for a proactive and detail-oriented professional eager to make a significant impact in the field of information security.
If you meet the outlined qualifications and are currently based in Saudi Arabia, we encourage you to apply by sharing your updated CV via email at [email protected]. Kindly reference “Splunk” in your application to ensure prompt consideration.
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.
ℹ️ إخلاء مسؤولية توظيف:
موقع وظائف السعودية (ksajobshub.com) هو محرك بحث ومجمع لإعلانات الوظائف من المصادر والشركات الرسمية في المملكة العربية السعودية. نحن لا نتقاضى أي مبالغ مالية أو رسوم من الباحثين عن عمل، وتتم عمليات التقديم مباشرة عبر الانتقال للرابط الأصلي للجهة المعلنة.