Principal SIEM Security Engineer
UltraViolet CyberFull Time
Expert & Leadership (9+ years)
Candidates must possess a Bachelor's degree in a related field and a minimum of 3 to 5 years of hands-on professional experience as a Splunk Engineer, with heavy experience in Risk-Based Alerting (RBA) and its application. They are required to hold an Accredited Enterprise Security Administrator in Splunk certification and a Splunk Core Certified Consultant certification, along with experience supporting federal customers and ingesting logs into Splunk via Cribl. A strong understanding of network protocols, operating systems, applications, and device event telemetry is also necessary.
The Splunk Engineer will be responsible for maintaining various client Splunk instances, focusing on data onboarding, content development, reporting, and visualizations. They will develop and implement actionable alerts and workflows for Splunk as a SIEM tool, create and implement Apps and Knowledge Objects (KO) such as Dashboards, Reports, and Data Models, collaborate with Splunk Architects/Admins, assist in training CISO teams and analysts, develop automation to improve CISO workflows, assist in developing advanced security use cases, create custom dashboards specific to RBA, configure incident response workflows, develop custom machine learning (ML) models, and work with stakeholders to implement and maintain event logging from various sources.
Cybersecurity services for IT environments
True Zero Technologies specializes in cybersecurity services and solutions, utilizing technologies such as Splunk, Tanium, and Cribl to provide actionable insights into IT environments for public and private sector organizations. The company's team delivers scalable solutions, shaping large operational and security programs.