T

Splunk ES

Tata Consultancy Services · Hyderabad, Telangana, India

3–10 yrs experiencefull_timePosted 5 days ago
Apply now →

Job description

Greetings from TCS!! Role; Splunk ES Experience: 6 to 12 years Location: Hyderabad/Chennai/Bangalore/indore/Mumbai Job Description: - Manage and administer **Splunk Enterprise Security (ES)** , including Data Models, Correlation Searches, Notable Events, Threat Intelligence Framework, Asset & Identity, and Content Management. - Design, develop, and tune **security detection use cases** aligned with the **MITRE ATT&CK** framework using SPL and Splunk ES correlation searches. - Implement and optimize **Risk-Based Alerting (RBA)** , including risk rules, risk modifiers, and detection tuning to reduce false positives and improve alert fidelity. - Onboard and normalize security data sources using **CIM** , troubleshoot data ingestion/parsing issues, and ensure data quality for security analytics. - Collaborate with SOC & security teams to enhance detection coverage, validate use cases, and support incident investigations and continuous improvement of the Splunk security platform. **Ideal Candidate Profile** - Strong foundation in Splunk Platform Engineering. - Capable of independently administering Splunk Enterprise Security. - Experienced in building high-quality detections using MITRE ATT&CK. - Practical understanding of Risk-Based Alerting (RBA) and detection tuning. - Able to bridge platform operations with security detection engineering while working closely with SOC teams.