ازکی
ازکی

Senior Cyber Defense Engineer

Tehran/Saei-Tavanir
Full Time
Saturday to Wednesday
-
Loan -Health insurance -Parking space -Game room -Occasional packages and gifts

این فرصت شغلی چقدر برای من مناسب است؟

1001 - 5000 employees
Insurance
Iranian company dealing only with Iranian entities
1395
Privately held
توضیحات بیشتر

key Requirements

3 years experience in similar position

Job Description

We are looking for a Senior Cyber Defense Engineer / Blue Team Security Engineer to design, build, and operate our security monitoring and detection capability. The core of this role is detection engineering: building real detections from raw telemetry, not administering an existing SIEM.

Key Responsibilities:
  • Manage, maintain, and optimize the Splunk SIEM environment.
  • Onboard and integrate security logs from servers, endpoints, network devices, private cloud platforms, and security tools.
  • Create and maintain Splunk dashboards, reports, alerts, and searches.
  • Monitor Splunk performance, data ingestion, indexing, and system health.
  • Develop new security detection rules and use cases.
  • Review and tune WAF rules to reduce false positives and improve coverage of web attacks.
  • Analyze security events and identify suspicious or malicious activity.
  • Support automation and integration between Splunk and other security tools.
  • Knowledge of Kubernetes security.
Requirements:
  • Hands-on experience with Splunk Enterprise and/or Splunk Enterprise Security (ES).
  • Strong knowledge of Splunk SPL.
  • Hands-on experience with WAF technologies, including log analysis, custom rule writing, and tuning.
  • Familiarity with web attacks and the OWASP Top 10, and how to detect them in WAF and web server logs.
  • Knowledge of MITRE ATT&CK.
  • Understanding of Windows, Linux, network, endpoint, and Kubernetes logs.

Job Requirements

Gender
Men / Women

ثبت مشکل و تخلف آگهی

ارسال رزومه برای ازکی