Splunk SME with Cybersecurity Automation SOAR/XSOAR Job at Net2Source Inc., Dallas, TX

cERocDJ6bi9hZUhaMHlDMkFRWVNwa2t0
  • Net2Source Inc.
  • Dallas, TX

Job Description

Title: Splunk SME / Cybersecurity Automation SOAR SME

Location: Dallas TX // Onsite-Hybrid

Term: Contract long term

Required skills:

  • At least 10+ years of experience in the IT industry with strong technical knowledge on AWS Infrastructure & security services (EC2, ELB, Guardduty, Config, Inspector, Security Hub, RDS, Route53, S3, vpc, vpn, tgw, cloudwatch, cloudtrail, eventbridge, etc.)
  • Strong security automation experience and ability to convert security use cases to automation scripts especially covering large set of AWS specific use cases.
  • Strong proficiency in XSOAR platform, including playbook development, automation scripting (Python preferred), and integration management.
  • Strong working experience in XSOAR product with the ability to design, implement, and maintain the Palo Alto XSOAR platform.
  • Ability to build new or modify existing Playbooks, develop custom playbooks, automations, and integrations with various security tools and technologies.
  • Ability to configure and manage Threat Intelligence Management (TIM) features in XSOAR
  • Identify opportunities to automate repetitive security tasks and processes using XSOAR.
  • Ability to develop/document playbooks to automate security controls and processes for AWS.
  • Collaborate with Security Operations Center (SOC) teams to streamline incident response workflows.
  • Palo Certified Security Automation Engineer (PCSAE) preferred
  • Good understanding of security controls related to regulatory requirements, such as NIST, PCI, ISO 27001, HIPAA compliance etc
  • Experience working on FedRamp compliant projects is a plus.

Splunk skillset Requirements:-

  • Strong hands-on working experience in Splunk Installation and UNIX management, Splunk architecture and components including search heads, indexers and forwarders.
  • Installed, configured, and maintained Splunk Add ons and Apps such as but not limited to: Splunk Add-On for AWS, Splunk Add-On for Windows, and Google Workspace for Splunk.
  • Creation of new dashboards, reports or analytics
  • Managed a clustered environment with multiple indexers and search heads.
  • Administered both Splunk Enterprise and Splunk Enterprise Security.
  • Worked closely with various Security and Platform Engineering teams to onboard new data from various sources.
  • Creation of new alerts, custom rules.
  • Maintaining the security of splunk and its related components and indexes
  • Maintaining current patch levels for all splunk components – including the Linux host OS patching and upgrading
  • Performing major version upgrades – including the Linux host OS, Splunk components as necessary
  • Troubleshooting and resolving splunk issues as necessary
  • Candidates with Splunk Enterprise Security Certified Admin or Splunk Certified Cybersecurity Defense Analyst certification will be preferred.

XSOAR skillset Requirements: -

  • Experience in XSOAR with ability to configure existing and/or create new Incident Types, Incident Fields, Classifications & Mappings Ability to build new or modify existing Playbooks, including implementation of Generic Polling and similar tasks Ability to configure and manage Threat Intelligence Management (TIM) features
  • XSOAR Palo Certified Security Automation Engineer (PCSAE) preferred

Job Tags

Contract work, Work experience placement,

Similar Jobs

OPI Inc

Business Management Consultant Job at OPI Inc

 ...opportunity for those few who embody an entrepreneurial spirit? Do you thrive in a fast-paced environment?Our entry-level Business Management Consultant opening is an excellent opportunity to join an industry leader and grow with us in an environment that is both... 

Trimac

CDL-A Drivers Wanted - Competitive Pay Job at Trimac

 ...~ Valid Class A Commercial Driver's License ~1-year verifiable tractor-trailer experience ~ Tanker & Hazmat Endorsements~ TWIC Card Past 7 years without: Driving violation involving the consumption of illegal or intoxicating substances A preventable rollover... 

TriShield Security & Protection Services

Armed School Security Professional Job at TriShield Security & Protection Services

 ...protecting students, staff, and school communities. If youre a retired law enforcement officer or experienced professional with a...  ...Security Officer Registration Act) certificationValid RPO (Retired Police Officer Permit to Carry) licenseDont have your certifications... 

Jobsultant Solutions

Data Entry Analyst - Part-time (Remote) Job at Jobsultant Solutions

About the job Data Entry Analyst - Part-time (Remote)We are seeking a Data Entry Analyst to support a challenging and dynamic program within the Northern Virginia area. The Analyst will analyze pre-collected intelligence analysis data and foreign travel data by leveraging... 

Headway

LCP (Remote) | Work from home Job at Headway

 ...clients you see through Headway, so that you can set the hours that work for you. Grow your caseload by providing marketing support and...  ...patients in-person or remotely via telehealth while working from home. We accept the following licenses on a state by state basis:...