Description : *This role sits within TEKsystems client security operations center on the threat engineering team. This team is responsible for writing detection, reviewing firewall logs, IDS / IPS, endpoint and EDR logs.Ability to build out APIs using Python.Looking at various websites to determine the newest threats, how to detect them and then write Splunk Query Language (SPL) to build detections for those threats.Will do a little work within their deception environment, the tool they use is Attivo.Take daily deep dives into Splunk, they have roughly 9-13TBs of data flowing into Splunk daily.Experience with writing detection, firewall logs, IDS / IPS, endpoint and EDR logs.Ability to write detections for hacking, malware or any type of suspicious activitySkills : *Splunk, Splunk enterprise, Siem, Python, Powershell, SQL, Scripting, Security
Splunk,Splunk enterprise,Siem,Python,Powershell,SQL,Scripting
- Additional Skills & Qualifications : *
Any Splunk certifications is a huge plus.
Expert Level
About TEKsystems :
We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.
The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.