استخدام Security Engineer (Splunk Expert / IDS Specialist)
شرح موقعیت شغلی
Position Overview:
We are seeking an experienced and highly motivated Security Engineer with deep expertise in Splunk, strong hands-on skills in Linux, and practical knowledge in deploying and tuning Intrusion Detection Systems (IDS) such as Suricata. Familiarity with automation/configuration tools like Ansible or Puppet is also expected.
Responsibilities:
Administration and maintain Splunk And Application Like Enterprise security , ITSI , SOAR …
- Design, implement, and maintain advanced dashboards, alerts, and reports in Splunk
- Ingest and normalize log data from various sources (network, systems, applications)
- Deploy and fine-tune Suricata or other IDS tools to detect threats and suspicious behavior
- Perform security event analysis, threat hunting, and provide actionable recommendations
- Write and optimize Suricata rules to reduce false positives and enhance threat coverage
- Administer and troubleshoot Linux systems (services, scripting, system logs)
- Collaborate with DevOps and other teams to implement security automation using Ansible or Puppet
- Document configurations, processes, and findings clearly and thoroughly
Required Skills and Qualifications:
Technical:
- Expert-level experience with Splunk Enterprise
- Practical hands-on experience with Suricata (or similar IDS platforms)
- Strong understanding of SIEM, SOAR, and behavioral analytics (UEBA)
- Advanced proficiency in Linux administration (preferably RHEL, Ubuntu, Debian)
- Scripting skills (e.g., Bash, Python) for automation and log parsing
- Familiarity with configuration management tools like Ansible and/or Puppet
General:
- Solid understanding of cybersecurity concepts and threat landscapes
- Strong troubleshooting and analytical thinking in high-pressure environments
- Effective written and verbal communication for documentation and collaboration
- Ability to work independently and within cross-functional teams
Preferred Certifications:
- Splunk Certified Power User / Admin / Architect
- Linux certifications such as LPIC-1/2 or RHCSA/RHCE
- Security certifications such as Security+, CEH, Sans Sec 511 , Sans Sec 555
مهارتهای مورد نیاز
- Splunk
- Linux
- Python
حداقل سابقه کار
- سه تا شش سال
جنسیت
- مهم نیست
وضعیت نظام وظیفه
- مهم نیست