Orbus International
← Back to all openings

ORB-REC-0079

Splunk Enterprise Security Engineer

Permanent Onsite 7-9 years Experience 📍 Chennai, Bangalore, Hyderabad,Mumbai, Indore

Key Skills

Splunk enterprise Security MITRE ATT&CK.

Job Description

JD:  Manage and administer Splunk Enterprise Security (ES), including Data Models, Correlation Searches, Notable Events, Threat Intelligence Framework, Asset & Identity, and Content Management.  Design, develop, and tune security detection use cases aligned with the MITRE ATT&CK framework using SPL and Splunk ES correlation searches.  Implement and optimize Risk-Based Alerting (RBA), including risk rules, risk modifiers, and detection tuning to reduce false positives and improve alert fidelity.  Onboard and normalize security data sources using CIM, troubleshoot data ingestion/parsing issues, and ensure data quality for security analytics.  Collaborate with SOC & security teams to enhance detection coverage, validate use cases, and support incident investigations and continuous improvement of the Splunk security platform. Ideal Candidate Profile  Strong foundation in Splunk Platform Engineering.  Capable of independently administering Splunk Enterprise Security.  Experienced in building high-quality detections using MITRE ATT&CK.  Practical understanding of Risk-Based Alerting (RBA) and detection tuning.  Able to bridge platform operations with security detection engineering

Apply Now