What are the responsibilities and job description for the Cyber Defense Manager position at Deloitte?
Work you'll do
As the Cyber Defense Manager, you will be tasked with the following:
- Serves as Splunk developer responsible for creating Security Information and Event Management (SIEM) content to monitor security events and detect potential security incidents across the enterprise. Responsible for SIEM content management, content creation, rule tuning, reporting and alert creation
- Provide knowledge of recognizing and onboarding new data sources into Splunk, analyzing the data for parsing purposes to make it CIM compliant, then building dashboards to fulfill stakeholder requirements
- Provide skillful knowledge within a Linux environment, editing and maintaining Splunk configuration files and apps
- Work with other Cybersecurity Engineering team members and interact with end users to gather requirements, perform troubleshooting, and aid with the creation of Splunk search queries and dashboards as required
- Interact with senior management, as necessary
- Troubleshoot performance alerts from the Splunk infrastructure or Splunk agents
- Assist in the testing of vendor patches for all security applications the Engineering team supports
- Maintain the Cybersecurity Engineering group in ServiceNow and ensure all request and incident SLA's are met as required by our stakeholders
- Document and update the Team's process and Data Ingestion procedures
- Actively seek to improve and develop new content based upon observed security activity
- Provide excellent customer service
The team
Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
Qualifications
- Bachelor's degree in Computer Science or Business Administration, or relevant educational or professional experience
- 8 years of related experience including at least 5 years experience with Splunk Administration
- Working Knowledge of the Splunk Platform
- Ability to troubleshoot performance and issues, as well as installation and Splunk upgrades
- Experience in analyzing, troubleshooting and providing solutions for technical issues
- Experience with Splunk Enterprise Security
- Experience in Syslog, Splunk HTTP Event collection (HEC)
- Experience in ingesting logs from DB Connect app
- Experience creating Alerts, Dashboards and reports in Splunk Tool
- Experience in requirement gathering and documentation
- Experience in Log parsing, lookups, calculated fields extractions using regular expression(regex)
- Experience in Developing Splunk Dashboards, Report, Alerts, Visualizations and Optimize searches
- Hands-on Experience in Splunk Content Development
Our culture
At Deloitte Global people are valued and respected for who they are - with opportunities to bring their unique perspectives, talents and passions to business challenges. Our global workspace creates room for individuality and collaboration. Ours is an inclusive, supportive, connected culture with a focus on development, flexibility, and well-being. This culture makes Deloitte Global one of the most rewarding places to work, and to transform your career.
Professional development
From entry-level employees to senior leaders, we believe in investing in you, helping you identify and hone your unique strengths at every step of your career. We offer opportunities to build new skills, take on leadership opportunities, and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.
Benefits
At Deloitte, we value our people and offer employees a broad range of benefits. Our Total Rewards program reflects our continued commitment to lead from the front in everything we do-that's why we take pride in offering a comprehensive variety of programs and resources to support your health and well-being.
#LI-Hybrid Hybrid work, remote may be an option