About the job
Job Title: Splunk Engineer/Architect
Job Location: New York City, NY
Duration: Contract
Job Overview: We are seeking a skilled Splunk Engineer/Architect to join our team in New York City. This role involves engineering and deploying advanced analytics and SIEM SOC solutions in a large enterprise environment. The ideal candidate will possess strong scripting skills, Linux/Unix experience, and an ability to work effectively in a team-oriented environment.
Key Responsibilities:
- Design and implement Splunk solutions for monitoring and analysis.
- Collaborate with cross-functional teams to enhance security analytics capabilities.
- Maintain and optimize Splunk infrastructure in a large-scale environment.
- Develop scripts and automation tools to streamline processes.
Qualifications:
- Proven experience as a Splunk Engineer or Architect.
- Experience with analytics and SIEM solutions in environments with more than 50 servers.
- Proficient in scripting languages such as BASH, Perl, Python, or Java, with a strong understanding of regular expressions.
- Solid experience in Linux/Unix system administration.
- Excellent interpersonal and communication skills; adaptable and self-motivated team player.
- Strong task management abilities.
- Knowledge of networking and security fundamentals (firewalls, routing, DNS, NAT, packet analysis, etc.).
- Broad exposure to diverse technologies, preferably within the finance sector.
Highly Desired Skills:
- Familiarity with Splunk Enterprise Security (ES4) and Splunk ITSI.
- Understanding of statistical modeling for anomaly detection, machine learning, and outlier detection.
- Experience in Splunk enterprise architecture, integration, and deployment.
- Familiarity with big data technologies including Kafka, NiFi, Storm, and Spark.
- Knowledge of indicators of compromise (IOC) in systems and applications.
- Familiarity with key security events across common platforms.
- Relevant industry certifications (CISSP, SANS, CEH, etc.).
- Experience with SDLC using JIRA and GIT.
- Ability to author security policies and best practice documentation.

