Looking for someone available locally.
- Hands-on experience in Security Operations Center (SOC) with strong expertise in Splunk SIEM for security monitoring, log analysis, correlation, and incident investigation.
- Monitor, detect, analyze, and respond to security incidents across IT, ICS/OT, endpoint, and email security environments.
- Investigate security alerts, perform threat hunting, root cause analysis, and coordinate incident containment and remediation.
- Manage and fine-tune Splunk dashboards, correlation rules, alerts, and use cases to improve detection capabilities.
- Work with security tools such as EDR/XDR, Email Security Gateways, IDS/IPS, Firewalls, and ICS/OT security solutions.
- Collaborate with infrastructure and security teams to strengthen security posture, ensure compliance, and support vulnerability management activities.
Required Skills:
- Splunk Enterprise SIEM
- Incident Response & Threat Analysis
- ICS/OT Security
- Endpoint Security (Microsoft Defender, CrowdStrike, SentinelOne, etc.)
- Email Security (Microsoft Defender for Office 365, Proofpoint, Mimecast, etc.)
- SIEM Use Case Development & Log Analysis
- MITRE ATT&CK, IOC Analysis, Threat Hunting
- Strong understanding of TCP/IP, Windows/Linux security, and cybersecurity best practices.