drjobs Senior Splunk Engineer (Global Security)

Senior Splunk Engineer (Global Security)

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Vancouver - Canada

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Job Summary

Job Description

What is the Opportunity

RBC Defensive Threat Operations (DTO) team is seeking an experienced Splunk Engineer with demonstrated competence and thought leadership capability to contribute toward the success of our Cyber Resiliency initiatives. Under the direction of the Director of Correlation Engineering the Senior Splunk Engineer is responsible for maintaining the RBC Security Information Event Management (SIEM) platform.

What will you do

The Senior Splunk Engineer is a hands-on technologist who is an expert in the use of the technologies that comprise the RBC SIEM platform architecture and creates and tunes the SIEM rules to adjust the specifications of alerts and security incidents. The scope of this position is RBC Enterprise-wide and requires a very good understanding of the security controls RBC uses and how they provide value to the business.

The incumbent will work closely with other members of the Global Security teams in ensuring that the security posture of RBC is maintained and take a proactive approach in continually assessing the effectiveness and efficiency of the SIEM platform.

Essential Functions:

  • Serve as a Subject Matter Expert (SME) for the SIEM and Splunk platform

  • Develops and implements effective correlation rules

  • Tunes SIEM components to ensure maximum reliability and reduce false positives

  • Review security context alerts and log sources

Essential Capabilities:

  • Ability to relate to non-technical users in user-friendly language

  • Ability to understand or learn the technical implications of security threats

  • Ability to manage multiple concurrent objectives or activities and effectively make judgments in prioritizing and time allocation in a high-pressure environment

What do you need to succeed

Must-have:

  • Bachelor of Science in a technology-related discipline or 3 years of relevant experience

  • 5 years of experience in a role dedicated to the configuration maintenance and administration ofSplunk and Enterprise Security

  • Proficiency in developing and optimizing Splunk queries dashboards and alerts.

  • Significant experience with and working knowledge of Syslog

  • Experience with scripting languages (e.g. Python Bash or PowerShell) for automation and tool integration.

  • Significant experience with and expertise in creating event correlation logic and rules

  • Hands-on experience deploying and managing Splunk in cloud environments (AWS Azure GCP).

  • Possess excellent troubleshooting problem-solving and verbal/written communication skills

  • Ability to manage critical situations and maintain solid relationships with colleagues

Nice-to-have:

  • Splunk Enterprise Certified Architect (preferred).

  • Splunk Core Certified Power User or Admin (minimum).

  • Certified Information Systems Security Profession

Whats in it for you

We thrive on the challenge to be our best progressive thinking to keep growing and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other reaching our potential making a difference to our communities and achieving success that is mutual.

  • A comprehensive Total Rewards Program including bonuses and flexible benefits competitive compensation commissions and stock where applicable

  • Leaders who support your development through coaching and managing opportunities

  • Ability to make a difference and lasting impact

  • Work in a dynamic collaborative progressive and high-performing team

  • A world-class training program in financial services

  • Flexible work/life balance options

#LI-POST

#TECHCPJ

Job Skills

Decision Making Group Problem Solving Identity Access Management (IAM) Information Security Information Technology Security IT Systems Integration Negotiation Security Controls Security Information Security Information and Event Management (SIEM) SIEM Tools Software Development Software Development Life Cycle (SDLC) Strategic Objectives

Additional Job Details

Address:

410 GEORGIA ST W FLOOR 3:VANCOUVER

City:

VANCOUVER

Country:

Canada

Work hours/week:

37.5

Employment Type:

Full time

Platform:

TECHNOLOGY AND OPERATIONS

Job Type:

Regular

Pay Type:

Salaried

Posted Date:

Application Deadline:

Note: Applications will be accepted until 11:59 PM on the day prior to the application deadline date above

Inclusion and Equal Opportunity Employment

At RBC we believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best effectively collaborate drive innovation and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect belonging and opportunity for all.

Join our Talent Community

Stay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs career tips and Recruitment events that matter to you.

Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at .


Required Experience:

Exec

Employment Type

Full-Time

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.