Splunk SIEM Engineer / SME – Banking Project
Experience: 7+ Years
Location: Singapore
Project: Banking / Financial Services
We are looking for an experienced Splunk SIEM Engineer / SME to support a critical Banking / Financial Services environment in Singapore.
The ideal candidate will have strong hands-on expertise across Splunk SIEM administration, architecture, engineering, data onboarding, use-case development, troubleshooting and migration.
This role requires a true Splunk SME who can work beyond routine administration and operate across architecture, engineering and infrastructure, with strong understanding of how Splunk integrates with servers, network infrastructure and enterprise security technologies.
Key Focus Areas
Splunk Administration & Engineering
- SIEM health monitoring, infrastructure administration and performance optimization.
- CPU, memory, storage and platform health monitoring.
- Splunk upgrades, configuration management and security advisory implementation.
- Indexer Cluster and Search Head Cluster monitoring and troubleshooting.
Data Onboarding
- End-to-end onboarding of security and infrastructure logs.
- Integration of Windows/Linux servers, network devices and security technologies including NAC, PAM, NBAD, IPS, DAM, DLP and Antivirus.
- Data parsing, field extraction and CIM mapping.
- First-level assessment, UAT and production onboarding.
SIEM Use Cases
- Develop new Splunk SIEM use cases based on security requirements.
- Fine-tune existing detection use cases.
- Develop and optimize searches, alerts and dashboards.
Advanced Troubleshooting
- Investigate and remediate complex Splunk issues.
- Troubleshoot stopped-reporting servers and data sources.
- Search scheduler, failed search, missed search and job troubleshooting.
- Search Head tuning and optimization.
- Splunk server reconciliation and platform health validation.
Splunk Migration
- Support migration of existing Splunk environments during Windows/OS upgrades and infrastructure changes.
- Understand existing Splunk architecture, configurations and dependencies.
- Perform hands-on migration configuration and validation.
- Ensure forwarders, data ingestion, searches and SIEM use cases continue to function after migration.
Infrastructure Integration
- Work closely with Infrastructure, Network, Cybersecurity and application teams.
- Troubleshoot Universal Forwarders, Heavy Forwarders, servers and network-based log forwarding.
- Support restoration / pump-back of historical logs into Splunk when required.
- Coordinate cross-functional resolution of complex log-flow and infrastructure issues.
Key Requirements
- 7+ years of relevant experience with strong Splunk expertise.
- Proven Splunk SME-level experience across administration, engineering and architecture.
- Strong hands-on experience with Splunk SIEM, Indexers, Search Heads, Indexer Clusters and Search Head Clusters.
- Strong experience in data onboarding, parsing and CIM mapping.
- Experience developing and fine-tuning SIEM use cases.
- Strong troubleshooting and performance-tuning experience.
- Experience with Splunk migration and Windows/OS upgrade-related migration activities.
- Strong understanding of Universal Forwarders / Heavy Forwarders and log-flow architecture.
- Experience working with Infrastructure and Network teams.
- Banking / Financial Services or other highly regulated enterprise environment experience is strongly preferred.
- Strong analytical, troubleshooting and stakeholder-management skills.
Interested Candidates can apply to *************