Your work profile.
We are seeking SIEM Engineer (Splunk) to support the ongoing
operations and optimization of our Splunk-based log management infrastructure.
These resources will play a critical role in ensuring effective log ingestion,
alerting, dashboarding, and system performance across both on-premises and
cloud environments.
Key Responsibilities (Project-Specific):
- Splunk
Infrastructure Management: Maintain and optimize Splunk environments
(on-premise and cloud).
- Ensure
consistent and reliable log ingestion from diverse systems and
applications.
- Data
Onboarding & Management: Define and implement data onboarding
processes, field extractions, and normalization.
- Collaborate
with asset-owning teams to ensure forwarder coverage and log
completeness.
- Alerting
& Dashboards: Create and maintain dashboards and custom SPL queries
for operational visibility.
- Ensure
accuracy and effectiveness of alerting mechanisms within Splunk.
- Troubleshooting
& Support: Investigate and resolve issues related to Splunk alerts
and data ingestion.
- Provide
solutions and recommendations for improving system performance.
- Automation
& Documentation: Assist in developing automation tools for efficient
Splunk management.
- Document
procedures, configurations, and architectural changes.
Education:
- Bachelor’s
degree in Information Security, Computer Science, or a related field. A
Master’s degree in Cybersecurity or Business Management is preferred.
Required Skill Set:
- Proficiency
in Splunk Query Language (SPL) for creating searches, alerts, and
dashboards.
- Experience
with Splunk data onboarding, field extractions, and log normalization.
- Familiarity
with AWS Cloud environments and integration with Splunk.
- General
scripting knowledge (Python preferred) for automation and tooling.
- Strong
troubleshooting skills and ability to resolve complex Splunk-related
issues.
- Experience
collaborating with cross-functional teams in enterprise environments.
- Strong
documentation and communication skills.
- Ability
to manage time effectively and meet operational goals.
Skills Required
- Bachelor's degree in Information Security, Computer Science, or a related field
- Proficiency in Splunk Query Language for searches, alerts, and dashboards
- Experience with Splunk data onboarding, field extractions, and log normalization
- Familiarity with AWS cloud environments and Splunk integration
- General scripting knowledge, preferably Python, for automation and tooling
- Strong troubleshooting skills for complex Splunk-related issues
- Experience collaborating with cross-functional teams in enterprise environments
- Strong documentation and communication skills
- Ability to manage time effectively and meet operational goals
- Master's degree in Cybersecurity or Business Management
What We Do
Embark is a specialized consulting and execution platform that helps global enterprises establish, operate, scale, and transform Global Capability Centres in India. Its integrated offering spans strategy, workspace, talent, human resources, legal, finance, tax, real estate, and IT. Operating as an end-to-end partner, Embark supports global companies with setup, managed services, and long-term operational integration.


.jpeg)





