Responsibilities:
Deliver Splunk SIEM management services within the SOC environment.
Collaborate with the SOC Principal Engineer, SIEM, in onboarding new log sources to the SIEM platform.
Maintain and govern SOC critical log sources, ensuring their proper functionality and integration with Splunk SIEM.
Detect log source issues, coordinate with customers to diagnose and resolve them in a timely manner.
Enhance and optimize telemetry within the Splunk environment to improve data collection, correlation, and reporting.
Perform regular system updates to ensure Splunk functionality and security are up to date.
Resolve Splunk-related issues promptly and efficiently.
Maintain the performance of the Splunk SIEM according to established best practices.
Participate in continuous process