Brampton, Ontario
Job Summary
Job Description – Splunk SIEM Engineer Position: Splunk SIEM Engineer (L2-L3) Experience 5–8 Years Location US\India (Supporting US Operations) Shift 24x7 Rotational Support (as applicable) Job Summary We are looking for a highly motivated Splunk SIEM Engineer to support Infrastructure services for a global media organization. The candidate will be responsible for Splunk platform administration, security monitoring, threat detection, incident investigation, use-case development, and SIEM optimization. The ideal candidate should possess strong expertise in Splunk Cloud, Security Information and Event Management (SIEM), cybersecurity operations, along with some hands-on on AWS, DNS knowhow and DevOps experience. Key Responsibilities Splunk Platform Administration Manage and support Splunk Cloud environment. Monitor SIEM platform health, performance, and log ingestion. Troubleshoot indexing, search, data parsing, and log collection issues. Manage data onboarding, field extraction, data models, lookups, and dashboards. Ensure availability and performance of Splunk services. SIEM Content Development Develop and maintain correlation rules and detection use cases. Create and tune alerts to reduce false positives. Design dashboards and operational reports. Support onboarding of new log sources and integrations. Develop up to 10 new detection use cases annually aligned to business requirements. Security Monitoring & Incident Response Perform security event monitoring and alert triage. Analyze and investigate security alerts. Classify incidents by severity and business impact. Create and track incidents in ITSM systems. Support critical incident investigations and root cause analysis. Collaborate with SOC, IR, and platform teams during major security incidents. Reporting & Governance Generate weekly and monthly Splunk reports. Present findings and recommendations to stakeholders. Maintain documentation, SOPs, runbooks, and operational procedures. Required Technical Skills Splunk Splunk Enterprise / Splunk Cloud Splunk Enterprise Security (ES) SPL (Search Processing Language) Correlation Searches Data Models CIM (Common Inf
Key Responsibilities
1. Analyze Escalated Security Incidents By Implementing Siem And Soar Tools To Ensure On-Time Resolution And Compliance With Sla And Quality Standards.
2. Mentor Team Members And Administrators By Sharing Expertise In Security Event Analysis, Creating Sops, And Maintaining Comprehensive Documentation To Improve Team Performance.
3. Validate And Review Change Order Implementation Plans And Compliance With Human Error Protocols, Contributing To Capacity Planning And Operational Readiness.
4. Engage With Customers During Meetings To Understand Their Challenges And Ensure Positive Feedback By Addressing Their Concerns Proactively.
5. Conduct Thorough Analyses, Including Root Cause Analysis And Trend Analysis, To Produce Actionable Reports That Inform Key Business Stakeholders About Performance Metrics And Improvement Strategies.
Skill Requirements
1. Proficient In Security Event Analysis Using Siem Tools.
2. Expertise In Implementing Technical Solutions For Security Operations.
3. Strong Analytical And Problem-Solving Skills.
4. Excellent Communication And Presentation Abilities.
5. Familiarity With Capacity Planning And Compliance Validation Processes.
Other Requirements
1. Certifications Such As Certified Information Systems Security Professional (Cissp) Or Security+ Are Optional But Valuable
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-