SIEM(Splunk) - Sr. Engineer | On-site, Bangalore




Bengaluru, India


Position summary

Experience with basic tuning of SIEM(Splunk) content.

  • College degree or equivalent training with experience working in a Security Operations Center, Managed Security, or client network environment.

  • Information security knowledge in one or more areas such as Enterprise end-point security products (i.e. McAfee e-Policy Orchestrator, Virus Scan, Anti-Spyware, Host Data Loss Protection, Endpoint Encryption, etc.) Security Information and Event Manager (SIEM), Firewall, Web Proxy, E-Mail and Web Gateway etc. to include Palo Alto / Checkpoint / Juniper / McAfee / Cisco / Blue Coat / Imperva etc.

  • Understanding of network operations a must; ideal candidate will have worked with network engineering or network security analysis.

  • Experience with SIEM(Splunk) content creation and reporting.

  • Excellent time management, reporting, and communication skills.

  • Superior IT problem-solving skills.

  • Experience with Linux OS.

  • Strong technical writing skills and the ability to explain complex problems to nontechnical teams.

  • Experience working with clients in a service delivery function.

  • Shift flexibility, including the ability to provide after-hours support when needed.

  • Ability to work greater than 40 hours per week as needed.

What we're looking for:

  • Bachelor of Science degree in Computer Science or related field is required.

  • Experience working with Internal and client Ticketing and Knowledge Base Systems for Incident and Problem tracking as well as procedures. (i.e. Service Now, Jira, Confluence, etc.).

  • General security knowledge (GIAC, CISSP, CCSE, CISA, HBSS, NSA, CEH, Cisco Security, Security +, or other security certifications).

  • Knowledge of Linux and Windows Operating Systems.

  • An understanding of a wide array of server grade applications such as: DBMS, Exchange, DNS, SMTP, IIS, Apache, SharePoint, Active Directory, Identity Management, Patch Management, LDAP, SQL, and others.

  • Experience with various SIEM security products such as: QRadar, Nitro, Splunk, Exabeam, Sentinel, ArcSight, LogRhythm and infrastructure components such as proxies, firewalls, IDS/IPS, DLP etc.

  • This role demands the exposure to SIEM (Splunk) as Development as well as Admin role.

  • This role demands the availability during US Working Hours (5PM(IST) to 3AM(IST))

  • This role is Work from Office role.

What you can expect from Optiv

  • A company committed to championing Diversity, Equality, and Inclusion through our Employee Resource Groups.

  • Work/life balance

  • Professional training resources

  • Creative problem-solving and the ability to tackle unique, complex projects

  • Volunteer Opportunities. "Optiv Chips In" encourages employees to volunteer and engage with their teams and communities.

  • The ability and technology necessary to productively work remotely/from home (where applicable)

EEO Statement

Optiv is an equal opportunity employer (EEO). All qualified applicants for employment will be considered without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, status as an individual with a disability, veteran status, or any other basis protected by federal, state, or local law. Optiv respects your privacy.

By providing your information through this page or applying for a job at Optiv, you acknowledge that Optiv will collect, use, and process your information, which may include personal information and sensitive personal information, in connection with Optiv's selection and recruitment activities. For additional details on how Optiv uses and protects your personal information in the application process, click here to view our Applicant Privacy Notice. If you sign up to receive notifications of job postings, you may unsubscribe at any time.