ESSENTIAL DUTIES AND RESPONSIBILITIES
Essential duties and responsibilities include the following. Other duties may be assigned.
Responsible for the integration of CNI Core Competencies into daily functions, including: commitment to integrity, knowledge/quality of work, supporting financial goals of the company, initiative/motivation, cooperation/relationships, problem analysis/discretion, accomplishing goals through organization, positive oral/written communication skills, leadership abilities, commitment to Affirmative Action, reliability/dependability, flexibility and ownership/accountability of actions taken.
Implements, optimizes and maintains the SIEM infrastructure (Splunk), and deploys products, apps, reports, alerts and dashboards utilizing system development life cycle (SDLC) methodologies and business best practices.
Increases the efficiency of the infrastructure to connect more enterprise data sources to Splunk Enterprise.
Develops change management plans to be adaptable to the changing needs of the program. Leads prototyping and testing of new features and solutions.
Manages and monitors Linux based on-prem server infrastructure for configuration and software upgrades.
Develops, maintains and optimizes installation of internal and external SIEM components.
Oversees the optimization, operation and health of Splunk components and connections to data sources. (Query scheduling, Performance tuning, Apps, Dashboards, Saved Searches, Scheduled Searches, Alerts, etc.).
Provides mentoring to Tier II technicians for problem resolution and lead technical discussions with technical engineers of SIEM and SIEM data connections.
Shares and provides knowledge to junior security architects and engineers and recommends training as needed.
Brings industry best practices and innovative ideas leading to continuous improvement of the Splunk environment.