Splunk, MS Sentinel Engineers
Number of Openings |
4 |
ECMS ID in sourcing stage |
524226 |
Assignment Duration |
1 Year |
Total Yrs. of Experience |
10+ |
Relevant Yrs. of experience |
8+ |
Detailed JD (Roles and Responsibilities) |
|
|
Resource with min. 3-4 yrs of experience in Sentinel or SIEM. |
|
Hands-on experience in onboarding log sources into Microsoft Sentinel |
|
Practical experience in developing custom connectors for custom log sources, including onboarding and event parsing |
|
Strong understanding of security frameworks and incident response methodologies |
|
Proficiency in Kusto Query Language (KQL) |
|
Experience with scripting languages such as Python or PowerShell |
|
Good to have SIEM migration experience |
|
Working experience in MSSP is added advantage |
|
Exposure and experience working in a DevOps model especially infrastructure-as-code (IaC), CI/ CD & ETL pipelines using Elastic Logstash |
|
Any experience with ASIM tables, customized Logstash/DCR rules, MSSP architecture, log optimization |
|
|
Mandatory skills |
Splunk |
|
MS Sentinel |
Desired/ Secondary skills |
SIEM |
Domain |
Client/TDR |
Max Vendor Rate in Per Day (Currency in relevance to work location) |
INR 10000/ day |
Work Location given in ECMS ID |
Chennai |
WFO/WFH/Hybrid WFO |
Hybrid WFO |
BG Check (Before OR After onboarding) |
After Onboarding |
Is there any working in shifts from standard Daylight (to avoid confusions post onboarding) YES/ NO |
No |