Sr SIEM - Splunk SME

Hybrid - Bangalore, India

Full-time

About the Role

Abnormal Security is looking for a Sr. SIEM/Detection Engineer to join the Security & Privacy team. As a leading cybersecurity company, it is imperative we find, analyze, and respond to threat actor’s attacks and leverage the lessons learned to enhance and improve our detection capabilities to catch new and novel attacks. In this role, you will play a crucial role in designing, developing, and implementing automated solutions within Splunk to enhance incident response, threat detection, and remediation processes. You will collaborate with cross-functional teams to optimize incident response workflows, develop custom dashboards and visualizations, and ensure the smooth operation of our SIEM infrastructure. Additionally, you will be responsible for maturing Splunk data models and refining detection lifecycle processes to improve threat detection capabilities.

What you will do 

  • Mission Control Automation Development: Design, develop, and implement automated solutions within Splunk Mission Control to streamline incident response, threat detection, and remediation processes.
  • Custom Dashboard Creation: Build custom dashboards and visualizations within Splunk to provide actionable insights for incident analysis and monitoring. Build capabilities to present analyst performance data to measure detection efficacy and response times.
  • Incident Response Optimization: Collaborate with cross-functional teams to identify opportunities for improving incident response workflows and develop automated solutions to enhance efficiency.
  • Continuous Monitoring and Maintenance: Monitor the performance and health of the SIEM infrastructure, troubleshoot issues, and implement necessary optimizations to ensure smooth operation.
  • Documentation and Training: Document automated workflows, best practices, and standard operating procedures for Cyber Defense analysts. Provide training and support to enable team members to effectively utilize automated solutions.
  • Detection Lifecycle Processes: Develop and implement detection lifecycle processes, including tuning and refinement of detection rules, to improve the accuracy and efficacy of threat detection capabilities.
  • Splunk Data Model Maturation: Collaborate with stakeholders to enhance and mature Splunk data models to align with evolving business requirements and improve data analysis capabilities.

Must Haves 

  • Bachelor’s Degree in Information Security, Computer Science, Digital Forensics, Cyber Security, or equivalent years of professional experience to meet job requirements and expectations.
  • 5+ years of experience in the security domain, including both a detailed understanding of attacker techniques and tracking the threat actors behind specific campaigns.
  • Demonstrated experience with Splunk Enterprise and Mission Control, including the ability to develop complex searches, dashboards, and reports.
  • Strong scripting skills (e.g., Python, PowerShell) with experience in automating tasks and processes within Splunk Mission Control.
  • Deep understanding of incident response methodologies and best practices, with the ability to translate these into automated workflows within SIEM and SOAR solutions.
  • Excellent problem-solving skills with a proactive approach to identifying and resolving technical challenges.
  • Strong interpersonal skills with the ability to effectively communicate technical concepts to both technical and non-technical stakeholders. Proven ability to collaborate with cross-functional teams.

Nice to Have 

  • Advanced degree in Computer Science, Engineering, or Cybersecurity.
  • OSCP, OSCE, or GPEN, GCIH, GCPN, GWAPT certifications.
  • Splunk certifications such as Splunk Certified Power User or Splunk Certified Admin would be advantageous.
  • Familiarity with other security tools and technologies such as IDS/IPS, EDR solutions, etc., to integrate with Splunk Mission Control.
  • Experience working with cloud platforms (e.g., AWS, Azure, GCP) and integrating Splunk Mission Control with cloud-based services.
  • Understanding of machine learning and artificial intelligence concepts, with the ability to leverage these technologies to enhance automated processes within Splunk.
  • Knowledge of DevOps practices and tools for automation, continuous integration, and continuous deployment (CI/CD) pipelines.

LI - #AB2

As part of Abnormal Security's secure hiring practices, we conduct video interviews and validate applicant identity at various stages through our recruitment process. Further, if your application is successful and Abnormal Security makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal Security's policies relevant to our security and privacy standards. Abnormal Security is committed to protecting your privacy. Please review our Applicant Privacy Policy for full information about how Abnormal Security uses your personal information.

About Abnormal Security

We're one of the world's fastest growing cybersecurity companies, on a mission to protect the modern workplace from the most pressing threats. Our AI-native technology was built from the ground up to tackle forward-looking security challenges, and our team works with bleeding-edge technology to keep our customers and their people safe as attacks grow ever more sophisticated. Our team is what makes us successful, which is why we're committed to a culture of learning, ownership, and high performance, where you'll have the opportunity to accelerate your growth and unlock excellence with the support of talented colleagues.

Meet the Team

Chau Nguyen
Software Engineer
Read More
Christy Min
Sales Development Representative
Read More
Mick Leach
Field CISO
Read More
Edwin Maljames
India Site Manager
Read More

Our Benefits

Taking care of our team goes beyond the office. Our compensation and benefits philosophy is designed to put attract, motivate, and retain top talent: Competitive Compensation We pay competitively to attract, reward, and retain top talent in the market
Equity is an important part of our total comp strategy
When the company does well, we all do well. Equity is an important and exciting part of our total compensation strategy as a pre-IPO startup. We’re guided by the belief our team members should share in the financial success of our company and grant equity accordingly.
Flexible PTO
All regular salaried team members enjoy flexible PTO. We want team members to grow with us, and a big part of that is making sure our team has the opportunity to rest and recharge. We also observe 12 paid holidays every year.
Generous Healthcare Coverage for You and Your Family
Taking care of our team goes beyond the office. In the US, we cover 100% of employee health care premium costs, and up to 100% for dependents, depending on the plan. Internationally, we offer similarly generous coverage, customized to each country in which we operate.
Fully Distributed Workforce
Operating as a globally-distributed, majority remote company means we get to work with talented folks, no matter where they live. We prioritize a balance of deep focus time with Zoom meetings, and regular in-person events. As a fast growing startup, we continuously review, improve, and personalize our benefits offerings based on the team’s input. Don’t see something that’s important to you? Let us know!

Our Interview Process

We value transparency at Abnormal, and our interview process is no exception.

Inclusion Matters

Abnormal Security is committed to creating a diverse work environment. All qualified applicants will receive consideration without regard to race, religion, gender, gender identity, sexual orientation, national origin, genetics, disability, age, or veteran status.

Privacy Policy

Learn more about Abnormal's Privacy Policy here.

Recruiting Imposter Alert

We have been made aware that there are potential scammers posing as Abnormal Security recruiters. Please ensure that any communication you have with our recruitment team comes from an official Abnormal Security email domain (e.g., @abnormalsecurity.com). Your safety and privacy are important to us, and we will never request sensitive personal information outside of our secure application process. Thank you for helping us maintain a secure and trustworthy application experience. Should you encounter what you believe to be a scamming attempt at any time in your recruiting process, please let us know at security@abnormalsecurity.com