About this role
<div style="font-family:Arial;font-size:1.0em"> <p>At EY, we’re all in to shape your future with confidence. </p> <p>We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. </p> <p>Join EY and help to build a better working world. </p> </div> <div style="font-family:Arial;font-size:1.0em"> </div><p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><strong>Staff (CTM – Threat Detection & Response)</strong></span></p> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><strong> </strong></span></p> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><strong>KEY Capabilities:</strong></span></p> <p> </p> <ul> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Experience in working with Splunk Enterprise, Splunk Enterprise Security & Splunk UEBA</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Minimum of Splunk Power User Certification</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Good knowledge in programming or Scripting languages such as Python (preferred), JavaScript (preferred), Bash, PowerShell, Bash, etc.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Assist in remote and on-site gap assessment of the SIEM solution.</span> <ul style="list-style-type:circle"> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Work on defined evaluation criteria & approach based on the Client requirement & scope factoring industry best practices & regulations</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Assist in interview with stakeholders, review documents (SOPs, Architecture diagrams etc.)</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Asist in evaluating SIEM based on the defined criteria and prepare audit reports</span></li> </ul> </li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Good experience in providing consulting to customers during the testing, evaluation, pilot, production and training phases to ensure a successful deployment.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Experience in onboarding data into Splunk from various sources including unsupported (in-house built) by creating custom parsers</span></li> <li style="list-style:none;font-size:10.0pt;font-family:arial, helvetica, sans-serif"> <ul style="list-style-type:circle"> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Verification of data of log sources in the SIEM, following the Common Information Model (CIM)</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Experience in parsing and masking of data prior to ingestion in SIEM</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Provide support for the data collection, processing, analysis and operational reporting systems including planning, installation, configuration, testing, troubleshooting and problem resolution</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Assist clients to fully optimize the SIEM system capabilities as well as the audit and logging features of the event log sources</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Assist client with technical guidance to configure their log sources (in-scope) to be integrated to the SIEM</span></li> </ul> </li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Experience in SIEM content development which includes :</span></li> <li style="list-style:none;font-size:10.0pt;font-family:arial, helvetica, sans-serif"> <ul style="list-style-type:circle"> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Hands-on experience in development and customization of Splunk Apps & Add-Ons</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Builds advanced visualizations (Interactive Drilldown, Glass tables etc.)</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Build and integrate contextual data into notable events</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Experience in creating use cases under Cyber kill chain and MITRE attack framework</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Capability in developing advanced dashboards (with CSS, JavaScript, HTML, XML) and reports that can provide near real time visibility into the performance of client applications.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Sound knowledge in configuration of Alerts and Reports.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Good exposure in automatic lookup, data models and creating complex SPL queries.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Create, modify and tune the SIEM rules to adjust the specifications of alerts and incidents to meet client requirement</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Experience in creating custom commands, custom alert action, adaptive response actions etc.</span></li> </ul> </li> </ul> <p> </p> <p> </p> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><strong>Qualification & experience:</strong></span></p> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><strong> </strong></span></p> <ul> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Minimum of 3 years’ experience in Splunk and 3 to 5 years of overall experience with knowledge in Operating System and basic network technologies</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Experience in SOC as L1/L2 Analyst will be an added advantage</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Strong oral, written and listening skills are an essential component to effective consulting.</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Good to have knowledge of Vulnerability Management, Windows Domains, trusts, GPOs, server roles, Windows security policies, user administration, Linux security and troubleshooting</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Certification in any other SIEM Solution such as IBM QRadar, Exabeam, Securonix will be an added advantage</span></li> <li style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Certifications in a core security related discipline (CEH, Security+, etc.) will be an added advantage.</span></li> </ul> <p> </p><div style="font-family:Arial;font-size:1.0em"> <p><b>EY | Building a better working world </b></p> <p>EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.</p> <p>Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.</p> <p>EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.</p> </div>