Job details
Your potential, unleashed. India’s impact on the global economy has increased at an exponential rate and Deloitte presents an opportunity to unleash and realise your potential amongst cutting edge leaders, and organisations shaping the future of the region, and indeed, the world beyond. At Deloitte, your whole self to work, every day. Combine that with our drive to propel with purpose and you have the perfect playground to collaborate, innovate, grow, and make an impact that matters. The team : Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risk Your work profile : As Deputy Manag er in our Cyber Team you’ll build and nurture positive working relationships with teams and clients with the intention to exceed client expectations: Splunk Engineer role is to Administering customer’s Splunk Enterprise Security (SIEM) end to end environment. This includes use case development, log source onboarding, custom parser creation, troubleshoot Splunk issues, upgrading the Splunk environment. Preferred Knowledge: Demonstrates proven expertise as in administering Splunk Enterprise Security (SIEM) environment. Should have the following skills: • Splunk Certified professional having at least Splunk Admin user certification level preferrable. • Good experience in Splunk administration and troubleshooting • Experience in integration of Splunk with log sources of different types including but not limited to security devices, network devices, web applications, custom applications and so on. • Experience in tuning and troubleshooting Splunk premium apps like Enterprise Security, Phantom and UBA. • Comfortable in writing regular expression to extract fields from custom log sources. • Expertise in developing custom use cases using Splunk search language to correlate and alert on logs from multiple sources. • Hands-on experience in creating dashboard and reports using SPL queries and XML. • Good knowledge of information security and IT operations domain. • Proficiency in client and server operating systems including Linux and Windows • General networking and system troubleshooting skills (firewalls, routing, NAT, etc.)• Ability to autonomously prioritize and successfully deliver across a portfolio of projects • Good consulting skills with ability to manage client expectations. Required Qualification:
- Overall experience of at least 5+ years as SIEM Splunk Enterprise Security administrator.
- Hands-on experience with Splunk enterprise security (SIEM), security tools and devices, operating systems, and/or networking devices desired.
- Proven skills and experience in Use case development, Log source integration, log source parsing.
- Experience working across diverse teams to facilitate solutions
- Bachelor’s Degree in Engg or equivalent.
- Bachelor’s/Master’s Degree
- Certifications like Splunk Power User, Splunk ES Admin is preferred
Apply safely
To stay safe in your job search, information on common scams and to get free expert advice, we recommend that you visit SAFERjobs, a non-profit, joint industry and law enforcement organization working to combat job scams.