The Splunk Security Engineer is responsible for the architecture, deployment, and management of Splunk instances for clients. They also develop security use-cases and configure alerts while collaborating with SOC analysts to ensure effective system monitoring.
Monitor and investigate security alerts, analyze activity using the Cyber Kill Chain and MITRE ATT&CK, and follow procedures to escalate or remediate threats. Document investigations for clients, communicate throughout escalations, collaborate with SOC colleagues, and maintain current security knowledge through training and threat awareness.
The analyst will transform detection strategies, tune rules, and manage cross-functional feedback loops to improve security operations. They will also lead attack surface reduction efforts, including vulnerability management and remediation coordination.
The Account Executive will drive the acquisition of new customers by selling AI-powered security platforms and managed security services. They will collaborate with internal teams to develop solution strategies and maintain long-term relationships with clients.
The role focuses on transforming the client's detection strategy by tuning rules, reducing alert fatigue, and managing cross-functional feedback loops. It also involves leading attack surface reduction efforts, including vulnerability management and penetration test remediation.