Soc Admin

Valuepoint Systems Private Limited

Bengaluru, KarnatakaFull-timeMid LevelOn-site

Job Description

We are seeking an experienced Splunk Administrator responsible for deployment, configuration, optimization, and ongoing management of the Splunk environment, including SIEM use case development and automation support for SOC operations.

Key Responsibilities

  • Install, configure, and manage Splunk Enterprise / Splunk ES (Standalone, Distributed, Clustered).
  • Configure and maintain Indexers, Search Heads, Forwarders, Deployment Server, Cluster Master.
  • Onboard and integrate logs from servers, network devices, security tools, endpoints, and cloud platforms.
  • Perform use case creation, correlation rule development, and fine-tuning aligned with MITRE ATT&CK framework.
  • Optimize detection logic to reduce false positives and improve alert quality.
  • Develop and maintain dashboards, alerts, reports, and advanced SPL queries.
  • Support SOAR playbook development and automation workflows for incident response (phishing, malware, ransomware, etc.).
  • Monitor Splunk platform health, performance tuning, EPS optimization, and storage management.
  • Troubleshoot ingestion, parsing (props.conf, transforms.conf), and search performance issues.
  • Implement RBAC, data retention policies, and security hardening.
  • Support version upgrades, patching, backup, and DR setup.

Posted Today

Related Jobs

Purchase Admin

STANCO Solutions Pvt

Bhubaneswar, Odisha Today
Full-time On-site Mid Level Operations

Kafka Admin

Apptad

Bangalore, Karnataka Today
Full-time On-site Mid Level Operations

Admin

Numoo HR

Mumbai, Maharashtra Today
Full-time On-site Mid Level Operations

Related Searches