PwC India
Associate
PwC IndiaIndia1 day ago
Full-timeInformation Technology

Job Description & Summary:

Associate II Splunk II Bangalore/Pune/ Kolkata


Join our "Global Cyber Logging - Platform Operation" team as a pivotal player in managing the centralized data management and analytics platform using Splunk. Your role is crucial in ensuring the integrity, security, and performance of our logging infrastructure, while driving continual improvement and innovation. Applicants should have at least 1 year experience in Splunk Enterprise / SIEM administration & management, and a good understanding of networking & Linux.



Responsibilities:


· SIEM Platform Management & Administration:


o Monitoring, administration, and optimization of the Splunk Enterprise platform to ensure efficient log management and effective security information and event management (SIEM).

o Conduct regular Splunk Infra & Ingestion health checks and monitoring to keep the environment robust and healthy for our stakeholders.

o Monitor & Keep the Splunk Enterprise instances in good health to serve our customers by keeping platform up & running 24/7.


· Troubleshooting & Problem Solving:


o Actively identify issues using “Monitoring”, investigate the rootcause, troubleshoot and fix the Splunk platform issues & problems related to log source outages, parsing errors, time discrepancies, user problems and more.

o Conduct Root Cause Analysis (RCA) to systematically address recurring issues and streamline

problem mitigation.


· SIEM Configuration Management & End-user Support:


o Support the deployment and configuration of Splunk solutions at enterprise level, ensuring seamless log integration and issue resolution.

o Manage end-user service requests, oversee Splunk access control, and enforce access restrictions to maintain secure and efficient user management.

o Ensure optimal platform performance through regular consolidation, cleanup, and configuration

adjustments. Innovation, Analytics, & Continuous Improvement:

o Enhance Splunk operations by implementing innovative solutions that improve efficiencies and automate processes, while integrating emerging technologies to optimize performance. Leverage machine learning and AI to deliver advanced analytics insights, predictive models, and strategic data-driven visualizations for informed decision-making. · Migration & Collaborations: o Handle SIEM server offboarding and migration, managing Cloud/On-prem Splunk forwarders (UF/HF) and log source migration projects. o Foster collaboration with multiple global teams like cybersecurity, IT, and business units, while streamlining processes and documentation to boost efficiency & platform stability.


Mandatory skill sets:


Splunk admin, splunk developer, SIEM, Linux


Preferred skill sets:

Linux, splunk

SIEM & Data Analytics Expertise: Demonstrated knowledge in SIEM solutions and data analytics tools, particularly SPLUNK. o Networking Fundamentals: Good understanding of networking principles, traffic analysis, and operating systems (Windows & Unix/Linux). TCP/IP and DNS resolution. Proficient with traffic analysis & Tshoot tools – Wireshark, TCPdump, Name lookup...etc o Linux/UNIX Proficiency: Competence in Linux/UNIX environments, including scripting skills with Regular Expressions. o SIEM Practical Experience: Hands-on experience in deploying and operating Splunk / other SIEM solutions is crucial. Splunk certifications are highly desirable. o Security Domain Knowledge: Understanding of security domain applications and their integration within SIEM frameworks to support robust cybersecurity operations. o Communication: Strong written and verbal communication skills in English.


Shift- 24*7 rotational shifts


Years of experience required:


1+ yrs

Education qualification:


Any Ug/Pg

Key Skills

Ranked by relevance