Pride Global

Software Engineer - Splunk SIEM Specialist for Banking Sector

Pride Global

Singapore · Full Time

Be the first to apply

Experience
7+ yrs
Salary
Openings
1
Posted
2時間前
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

We seek a seasoned Splunk SIEM Engineer to join a key banking project in Singapore. The candidate must have over seven years of comprehensive experience in Splunk ecosystem administration, architecture design, engineering, and data onboarding specifically tailored to security information and event management (SIEM) within a financial services environment.

Responsibilities

  • Oversee and optimize Splunk SIEM health, including infrastructure performance monitoring, resource management (CPU, memory, storage), and security advisory application.
  • Manage and troubleshoot Indexer Clusters and Search Head Clusters, ensuring system stability and performance.
  • Handle end-to-end onboarding of logs from security and infrastructure devices, including servers (Windows/Linux), network devices, and security tech such as NAC, PAM, NBAD, IPS, DAM, DLP, and Antivirus solutions.
  • Execute data parsing, field extraction, and CIM data model mapping to maintain integrity and usefulness of ingested data.
  • Develop, refine, and optimize Splunk SIEM use cases with creation of searches, alerts, and dashboards that address security requirements.
  • Perform advanced troubleshooting on complex issues regarding search failures, data ingestion stoppages, search head optimization, and platform health validation.
  • Support migration activities during Windows/OS upgrades or infrastructure changes, ensuring all Splunk configurations and use cases function seamlessly post-migration.
  • Collaborate closely with Infrastructure, Network, Cybersecurity, and application teams to resolve intricate log routing and forwarding issues including managing Universal and Heavy Forwarders.
  • Manage restoration or ingestion of historical logs when necessary to maintain comprehensive data records.

Requirements

  • A minimum of seven years in roles emphasizing Splunk SIEM engineering with SME-level skills in administration, architecture, and engineering.
  • Hands-on experience managing Splunk components including Indexer Clusters, Search Head Clusters, and familiarity with Universal and Heavy Forwarders architecture.
  • Proficiency in log ingestion, parsing techniques, and CIM data model implementation.
  • Demonstrated ability to create and enhance SIEM use cases tailored for detecting security events.
  • Strong troubleshooting capabilities, particularly in search scheduler issues, log flow, and platform health optimization.
  • Experience overseeing Splunk migration projects, especially those related to Windows or OS upgrades.
  • Ability to work effectively alongside infrastructure and network teams in complex, highly regulated environments, ideally within banking or financial services.
  • Excellent analytic skills coupled with effective stakeholder communication and management abilities.

Additional Information

This is a full-time onsite position based in Singapore. Candidates must be prepared to engage across multiple teams and exhibit deep technical expertise in Splunk SIEM solutions. Applications can be directed to the provided contact email.

How they work

Teamwork & Collaboration Problem Solving Attention to Detail

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help