Splunk SME - SC Cleared
Whitehall Resources require a Splunk SME with active SC clearance to work on an initial 3 month contract.
* Inside IR35.
* This role will be largely remote with occasional UK travel.
Splunk SME - SC Cleared
Job Description:
A Splunk SME to manage and optimize log management and SIEM environment. Will configure and maintain Splunk Heavy Forwarders, Windows Event Collectors, and Syslog Aggregators to ensure efficient log collection, analysis, and correlation. The focus will be on normalizing data, configuring event sources for various devices (Cisco, Palo Alto, F5, Fortinet, HPE, VMs), and developing event correlation rules, alerts, and dashboards to support our CSOC. This role requires a strong understanding of Linux, Windows, and networking logging concepts.
Essential Skills:
. Proven experience with Splunk Heavy Forwarders on Linux platforms.
. Strong understanding of Windows Event Collector Services (WEC).
. Hands-on experience with Syslog Aggregators.
. Expertise in log management and forwarding best practices.
Desirable Skills:
. Experience implementing Splunk environments to CIS Level 1 and Level 2 standards.
. Familiarity with Red Hat Enterprise Linux Server.
. Knowledge of forwarding events to Splunk Enterprise and ServiceNow platforms.
. Experience integrating Splunk with SolarWinds.
. Understanding of Reliable Event Logging Protocol (RELP).
All of our opportunities require that applicants are eligible to work in the specified country/location, unless otherwise stated in the job description.
Whitehall Resources are an equal opportunities employer who value a diverse and inclusive working environment. All qualified applicants will receive consideration for employment without regard to race, religion, gender identity or expression, sexual orientation, national origin, pregnancy, disability, age, veteran status, or other characteristics.
17 Dec 2024
Project-based
Tehnologia informaţiei, Telecomunicaţii