Abnormal Security Logo

Abnormal Security

Sr SIEM - Splunk SME

Posted 2 Days Ago
Be an Early Applicant
Bangalore, Bengaluru, Karnataka
Senior level
Bangalore, Bengaluru, Karnataka
Senior level
As a Sr. SIEM/Detection Engineer at Abnormal Security, you will enhance incident response and threat detection capabilities by developing automated solutions within Splunk, creating custom dashboards, optimizing workflows, monitoring SIEM infrastructure, and refining detection processes. Your role involves training team members and collaborating with cross-functional teams to improve security operations.
The summary above was generated by AI

About the Role

Abnormal Security is looking for a Sr. SIEM/Detection Engineer to join the Security & Privacy team. As a leading cybersecurity company, it is imperative we find, analyze, and respond to threat actor’s attacks and leverage the lessons learned to enhance and improve our detection capabilities to catch new and novel attacks. In this role, you will play a crucial role in designing, developing, and implementing automated solutions within Splunk to enhance incident response, threat detection, and remediation processes. You will collaborate with cross-functional teams to optimize incident response workflows, develop custom dashboards and visualizations, and ensure the smooth operation of our SIEM infrastructure. Additionally, you will be responsible for maturing Splunk data models and refining detection lifecycle processes to improve threat detection capabilities.

What you will do 

  • Mission Control Automation Development: Design, develop, and implement automated solutions within Splunk Mission Control to streamline incident response, threat detection, and remediation processes.
  • Custom Dashboard Creation: Build custom dashboards and visualizations within Splunk to provide actionable insights for incident analysis and monitoring. Build capabilities to present analyst performance data to measure detection efficacy and response times.
  • Incident Response Optimization: Collaborate with cross-functional teams to identify opportunities for improving incident response workflows and develop automated solutions to enhance efficiency.
  • Continuous Monitoring and Maintenance: Monitor the performance and health of the SIEM infrastructure, troubleshoot issues, and implement necessary optimizations to ensure smooth operation.
  • Documentation and Training: Document automated workflows, best practices, and standard operating procedures for Cyber Defense analysts. Provide training and support to enable team members to effectively utilize automated solutions.
  • Detection Lifecycle Processes: Develop and implement detection lifecycle processes, including tuning and refinement of detection rules, to improve the accuracy and efficacy of threat detection capabilities.
  • Splunk Data Model Maturation: Collaborate with stakeholders to enhance and mature Splunk data models to align with evolving business requirements and improve data analysis capabilities.

Must Haves 

  • Bachelor’s Degree in Information Security, Computer Science, Digital Forensics, Cyber Security, or equivalent years of professional experience to meet job requirements and expectations.
  • 5+ years of experience in the security domain, including both a detailed understanding of attacker techniques and tracking the threat actors behind specific campaigns.
  • Demonstrated experience with Splunk Enterprise and Mission Control, including the ability to develop complex searches, dashboards, and reports.
  • Strong scripting skills (e.g., Python, PowerShell) with experience in automating tasks and processes within Splunk Mission Control.
  • Deep understanding of incident response methodologies and best practices, with the ability to translate these into automated workflows within SIEM and SOAR solutions.
  • Excellent problem-solving skills with a proactive approach to identifying and resolving technical challenges.
  • Strong interpersonal skills with the ability to effectively communicate technical concepts to both technical and non-technical stakeholders. Proven ability to collaborate with cross-functional teams.

Nice to Have 

  • Advanced degree in Computer Science, Engineering, or Cybersecurity.
  • OSCP, OSCE, or GPEN, GCIH, GCPN, GWAPT certifications.
  • Splunk certifications such as Splunk Certified Power User or Splunk Certified Admin would be advantageous.
  • Familiarity with other security tools and technologies such as IDS/IPS, EDR solutions, etc., to integrate with Splunk Mission Control.
  • Experience working with cloud platforms (e.g., AWS, Azure, GCP) and integrating Splunk Mission Control with cloud-based services.
  • Understanding of machine learning and artificial intelligence concepts, with the ability to leverage these technologies to enhance automated processes within Splunk.
  • Knowledge of DevOps practices and tools for automation, continuous integration, and continuous deployment (CI/CD) pipelines.

LI - #AB2

Top Skills

Python

Similar Jobs

8 Hours Ago
Hybrid
Bengaluru, Karnataka, IND
Senior level
Senior level
Artificial Intelligence • Big Data • Information Technology • Software
The Cloud Security Architect will enhance security for the cloud infrastructure, focusing on design, implementation, and management of security controls. Responsibilities include assessing and mitigating cloud risks, responding to security incidents, maintaining security tools, and collaborating with engineering teams to ensure secure deployment and operations.
Top Skills: AnsibleAWSCrossplaneGoJavaScriptKubernetesPythonTerraformTerragruntTypescript
8 Hours Ago
Hybrid
Bengaluru, Karnataka, IND
Senior level
Senior level
Artificial Intelligence • Big Data • Information Technology • Software
As a Senior Product Security Engineer at Nexthink, you will secure the company's multi-tenant SaaS offering and protect customer data. You will guide product teams on secure coding practices, develop analysis rules for vulnerability detection, educate developers on security best practices, and collaborate with various teams to align on security initiatives.
Top Skills: Application SecuritySecure Software DevelopmentThreat Modeling
Yesterday
Hybrid
Bengaluru, Karnataka, IND
Junior
Junior
Financial Services
This role involves troubleshooting and maintaining the operational stability and performance of production application flows in a large-scale tech environment. You will monitor for anomalies, escalate issues, and work towards improving service delivery and problem management related to applications and infrastructure.
Top Skills: PythonSQLUnix

What you need to know about the Bengaluru Tech Scene

Dubbed the "Silicon Valley of India," Bengaluru has emerged as the nation's leading hub for information technology and a go-to destination for startups. Home to tech giants like ISRO, Infosys, Wipro and HAL, the city attracts and cultivates a rich pool of tech talent, supported by numerous educational and research institutions including the Indian Institute of Science, Bangalore Institute of Technology, and the International Institute of Information Technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account