Security infrastructure Consultant (SIEM platforms)
Job DescriptionJob Description
Overview:
We are seeking a seasoned Security Infrastructure Consultant with deep expertise in Security Information and Event Management (SIEM) platforms, particularly Splunk and its Enterprise Security (ES) module. The ideal candidate will be responsible for the end-to-end design, implementation, and optimization of SIEM solutions, ensuring robust security monitoring and compliance across complex IT environments.
Key Responsibilities:
-
Lead the design, deployment, and configuration of Splunk environments, including the integration of the Splunk Enterprise Security module.
-
Manage and optimize log source integrations from various systems such as firewalls, Active Directory, EDR platforms, DNS servers, proxies, and other security tools.
-
Collaborate with clients to gather requirements and translate them into effective SIEM solutions that meet business, compliance, and security objectives.
-
Develop comprehensive documentation, including operational procedures and architectural designs, adhering to security best practices.
-
Identify and address security vulnerabilities, providing actionable recommendations to mitigate risks across the client's IT environment.
-
Work independently and collaboratively within a team to deliver high-quality security solutions.
Required Qualifications:
-
8–10 years of experience in IT security, with at least 6 years focused on SIEM technologies.
-
Proven expertise in installing, configuring, and managing Splunk, including the Enterprise Security module.
-
Extensive experience with integrating and managing log sources from diverse security systems.
-
Strong analytical skills with the ability to interpret complex data and provide insightful recommendations.
-
Excellent written and verbal communication skills, capable of producing clear and concise documentation and reports.
-
Demonstrated ability to work autonomously and as part of a collaborative team.
Qualifications:
-
Previous consulting experience within a professional services organization.
-
Certifications such as Splunk Core Certified Consultant, Splunk Enterprise Security Certified Admin, CISSP, CCSE, MCITP, or relevant SANS certifications (e.g., GCIA, GCIH, GREM, GPEN, CEH).
Education:
-
Bachelor's degree in Computer Science, Information Technology, or a related field.