What are the responsibilities and job description for the Splunk Intel Developer position at Nexwave Inc?
Job Description
Job Description
Role : Splunk Intel Developer
Duration : Long term contract
Location : Wilmington, DE (Onsite)
Rate : 60
Exp 8
We are seeking an experienced and skilled Splunk Intel Developer to join our team and play a key role in integrating threat intelligence into Cribl and Splunk platforms.
The ideal candidate will have a strong understanding of pipeline management in Cribl, experience with lookups, and a proven ability to work with large datasets, optimizing them for large retroactive queries.
This is an exciting opportunity to leverage your expertise in Splunk content development and threat intelligence while helping to enhance the security capabilities of the organization.
Key Responsibilities :
- Threat Intelligence Integration : Integrate threat intelligence feeds and external threat data into Splunk and Cribl , ensuring effective correlation and analysis within security use cases.
- Cribl Pipeline Management : Manage and optimize data pipelines in Cribl , ensuring seamless integration of various data sources while maintaining high efficiency and scalability.
- Lookup Management : Work with Splunk lookups to enrich event data, leveraging threat intelligence to enhance data quality and accuracy for analysis.
- Data Optimization : Collaborate with teams to design and implement data ingestion strategies, ensuring large datasets are optimized for fast, efficient querying, particularly for retroactive queries .
- Splunk Content Development : Develop and maintain Splunk apps , knowledge objects , search queries , and dashboards to facilitate security analysis and alerting.
- Threat Detection and Correlation : Develop and implement custom detection rules and correlation searches that leverage threat intelligence data for proactive security monitoring.
- Collaboration : Work closely with security analysts, threat hunters, and other stakeholders to ensure that the integration of threat intelligence is aligned with organizational security objectives.
- Performance Tuning : Troubleshoot and resolve performance issues in Splunk searches, queries, and dashboards, ensuring high system availability and responsiveness under large query loads.
- Documentation : Create and maintain documentation on the integration processes, pipeline management, and content development for internal knowledge sharing.
Required Skills and Qualifications :
Preferred Qualifications :