Splunk Engineer (RBA) (R-00101) at True Zero Technologies | Torre

Splunk Engineer (RBA) (R-00101)

You'll build adaptive cybersecurity, securing critical futures.
Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Full-time

Legal agreement: Employment

Provide your expected compensation while applying
location_on
Remote (anywhere)
skeleton-gauges
You have opted out of job matches in .
To undo this, go to the 'Skills and Interests' section of your preferences.
Review preferences
Posted 5 months ago

Requirements and responsibilities


Job ResponsibilitiesImplement RBA: Develop and implement RBA strategies within Splunk ES to reduce alert noise and focus on high-fidelity alerts.Develop RBA components: Build and implement actionable alerts, workflow actions, risk incident rules, and risk scores.Create dashboards and reports: Design custom dashboards to visualize risk scores and provide context for analysts.Correlate data: Use Splunk's capabilities to correlate disparate events to identify patterns of risky behavior.Build custom solutions: Develop custom machine learning (ML) models to augment alerting and create automated workflows to improve efficiency.Content Development: Develop advanced security content, including dashboards, reports, and alerts, to highlight risk details, health analysis, and risk suppression specific to RBA environments.Data: Collaborate with application and system owners to onboard new data sources (e.g., from Windows, Linux, cloud services like AWS/Azure) and ensure proper parsing and enrichment for effective analysis within RBA.Correlate various data sources, such as logs from operating systems, applications, and cloud providers, into Splunk to feed RBA models.Preferred QualificationsTechnical Expertise: Deep technical expertise in Splunk administration, architecture, and Search Processing Language (SPL).Security Knowledge: Strong understanding of security operations, threat detection, incident response, and security frameworks (e.g., NIST RMF).Relevant Splunk certifications such as:Splunk Core Certified Power UserSplunk Enterprise Certified AdminSplunk Enterprise Certified ArchitectSplunk ESScripting: Proficiency in scripting languages like Python, PowerShell, or Bash for automation and data analysis.Willingness to collaborate within an agile environmentWhat we offerWe’re actively searching for talented security and technology practitioners who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy:Competitive salary, paid twice per monthBest in class medical coverage100% of medical premiums covered by True ZeroCompany wide new business incentive programsContribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)3 weeks of PTO starting + 11 Paid Holidays Annually401k Program with 100% company match on the first 4%Monthly reimbursement of Cell Phone and Home Internet costsPaternity/Maternity LeaveInvestment in training and certifications to broaden and deepen your technical skillsAI DisclaimerWe may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Optionally, you can add more information later (benefits, pre-screening questions, etc.)
check_circle

Payment confirmed

A member of the Torre team will contact you shortly

In the meantime, continue adding information to your job opening.