My client, a globally recognised IT multinational, is looking for a Splunk SIEM Architect to design and implement scalable Splunk architectures, with knowledge of integration with security tools and platforms for seamless information sharing and incident response.
Role: Splunk SIEM Architect
Location: Reading
Day Rate: £600 per day (inside ir35)
Duration: 6 months initially
Responsibilities include, but are not limited to:
Create HLD/LLD and solution documents for Splunk deployment across enterprise.
Lead the deployment and management of Splunk Cloud solutions, ensuring seamless integration with existing systems.
Configure and integrate Splunk Cloud with existing systems and data sources.
Perform testing and validation of the cloud deployment.
Identify and prioritize data sources for onboarding into Splunk.
Develop and implement data ingestion strategies.
Ensure data quality, normalization, and enrichment.
Perform routine administration tasks such as user management, index management, and system monitoring.
Optimize Splunk performance through tuning and configuration adjustments.
Manage Splunk licenses and upgrade processes.
Develop and maintain troubleshooting guides and knowledge base articles.
Collaborate with vendors for support and issue resolution.
Maintain detailed documentation of Splunk configurations, processes, and procedures.
The successful candidate will have:
Experience in developing comprehensive Splunk architecture tailored to the organization's security requirements, compliance standards, and infrastructure.
Good insight of designing data collection strategies, including log sources, event types, and data normalization techniques, to ensure maximum coverage and accuracy.
Implementation knowledge of correlation rules, use cases, and threat intelligence feeds to enhance detection capabilities and reduce false positives.
Knowledge of integration with other security tools and platforms for seamless information sharing and incident response.
Hands on knowledge in deployment and configuration of SIEM components, including collectors, aggregators, correlation engines, and user interfaces, based on architectural designs.
Develop and maintain SIEM integrations, ensuring comprehensive security monitoring and threat detection capabilities.
If you are interested and have the relevant experience, please apply promptly and we will contact you to discuss further.