atsmantra logo
Rarr Technologies Pvt Ltd logo

Splunk Content Developer(RARR Job 2796)

For International Trade And Development Company

6 - 12 Years

Full Time

Up to 15 Days

Up to 35 LPA

1 Position(s)

6 - 12 Years

Full Time

Up to 15 Days

Up to 35 LPA

1 Position(s)

no more applicationNo longer accepting applications
Discover more job opportunities that match your interests.

Job Skills

Job Description

We are looking for a content development engineer or L2 level SOC SIEM engineer with hands-on experience in developing new rules, use cases based on various log sources including Cloud Security log sources and integrating various log sources with SIEM Platform.
Roles and Responsibilities:
• Creating and implementing new threat detection content, rules and use cases to deploy in SIEM platform with different data sets like Proxy, VPN, Firewall, DLP, etc.
• Assisting with process development and process improvement for Security Operations to include creation/modification of SOPs, Playbooks, and Work instructions.
• Developing custom content based on threat intelligence and threat hunting results.
• Identifying gaps in the existing security controls and develop/propose new security controls.
• SIEM Engineering and knowledge of integrating various log sources with any SIEM platform.
• Custom parsing of logs being ingested into the SIEM Platform
Job Requirements:
• 3+ years of experience working in the field of Content development and experience in delivering and/or building content on any of the SIEM tools like Splunk/Arcsight /QRadar/Nitro ESM/etc.
• Deep understanding of MITRE ATT and ;CK Framework.
• Experience in SOC Incident analysis with an exposure to information security technologies such as Firewall, VPN, Intrusion detection tools, Malware tools, Authentication tools, endpoint technologies, EDR and cloud security tools.
• Good understanding on networking concepts.
• Experience interpreting, searching, and manipulating data within enterprise logging
solutions (e.g. SIEM, IT Service Management (ITSM) tools, workflow, and automation)
• In depth knowledge of security data logs and an ability to create new content on advanced security threats on a need basis as per Threat Intelligence.
• Ability to identify gaps in the existing security controls.
• Good experience in writing queries/rules/use cases for security analytics (ELK, Splunk or any other SIEM platform) and deployment of content.
• Experience on EDR tools like Crowdstrike and good understanding on TTPs like Process Injection.
• Excellent communication, listening and ; facilitation skills
• Ability to demonstrate an investigative mindset.
• Excellent problem-solving skills

Matching Jobs

Nilasu Consulting Services Pvt Ltd logo
SOC Analyst

For A French Mnc It Company

location icon

Capgemini Pan India, India

experience icon

8 - 12 Years ( Full Time )

skill icon

Azure Sentinel, Cyber Security, Monitaring., Security, Security Monitoring, Siem, Soc, Splunk

Not disclosed

share icon
atsMantra logo
A unified recruitment ecosystem designed to simplify hiring for companies, recruitment agencies, and job seekers alike. From powerful applicant tracking to smart job discovery, we offer intelligent tools that bring speed, clarity, and structure to every step of the recruitment journey.
atsMantra Facebook accountatsMantra Instagram accountatsMantra Twitter accountatsMantra LinkedIn accountatsMantra YouTube account