jobs in NTT DATA Business Solutions

Kerja Sepenuh Masa, Splunk Enterprise Security Engineer di NTT DATA Business Solutions Selangor - Maukerja

Splunk Enterprise Security Engineer

NTT DATA Business Solutions

Kongsi
Simpan

Lokasi Kerja

  • Cyberjaya Selangor Malaysia

Penerangan Kerja

Tanggungjawab

At NTT DATA Business Solutions, we drive innovation – from advisory and implementation to managed services and beyond, powered by a global team of over 18,500 experts representing over 90 nations in more than 30 countries. With SAP at our core and a powerful ecosystem of partners like Microsoft and ServiceNow, we continuously improve solutions and AI-driven technology to make them work for companies – and for their people.


We are part of NTT DATA, a $30+ billion business and technology services, AI and digital infrastructure leader. As a Global Top Employer, NTT DATA serves 75% of the Fortune Global 100 and, with experts in over 70 countries, co-innovates solutions that encourage experimentation and recognize great work.



With us, you have endless opportunities to think big, act bold and take ownership. Make this the place where you belong, learn, and build your network.


Make this the place where you grow.


What makes us special:

Team-oriented corporate culture, collaboration as equals and steady knowledge transfer

Diversity & Inclusion (e.g. various initiatives & communities)

Flexible working hours, (e.g. hybrid working)

Inhouse Academy with a variety of professional technical training, soft skills training, SAP Learning Hub and certification opportunities

Company health benefits (e.g. Medical Insurance, Health Insurance, Optical and Dental Benefits)


What We Are Looking For:


We are seeking a highly technical Splunk Enterprise Security (ES) Engineer who possesses strong hands-on expertise in both Splunk Enterprise and Splunk Enterprise Security (ES).

This role is ideal for candidates who have experience managing enterprise-scale Splunk environments and developing SIEM capabilities that support Security Operations Centre (SOC) teams. The successful candidate will act as the technical owner of the Splunk platform, driving platform stability, data quality, detection engineering, and continuous security monitoring improvements.


Core Competencies Required

1.Splunk Enterprise Administration & Engineering

Candidates should possess hands-on experience in:

  • Deploying, configuring, and managing Splunk Enterprise environments.
  • Administering Splunk components including:

-Search Heads

-Indexers

-Heavy Forwarders

-Universal Forwarders

-Deployment Servers

-Clustered Splunk environments


  • Splunk platform installation, maintenance, troubleshooting, and lifecycle management.
  • Planning and executing Splunk upgrades, migrations, and platform modernization activities.
  • Performance tuning, capacity planning, and platform optimization.
  • Log forwarding architecture, onboarding, and data ingestion troubleshooting.
  • Data parsing, field extraction, indexing, and CIM normalization.
  • Dashboard, report, and KPI development for operational and security use cases.
  • Troubleshooting search performance, ingestion bottlenecks, and infrastructure-related issues.


2.Splunk Enterprise Security (ES) & SIEM Engineering

Candidates should have proven hands-on experience in developing and operating SIEM capabilities using Splunk Enterprise Security, including:

  • Onboarding and integrating security-relevant data sources.
  • Troubleshooting data onboarding, parsing, CIM compliance, and normalization issues.
  • Developing, maintaining, and tuning correlation searches.
  • Designing and implementing Risk-Based Alerting (RBA).
  • Creating and managing notable events and investigation workflows.
  • Developing security use cases aligned with SOC detection requirements.
  • Detection engineering for:

-Authentication attacks

-Privileged account misuse

-Malware and endpoint threats

-Lateral movement

-Data exfiltration

-Insider threats


  • Continuous tuning to reduce false positives and improve detection effectiveness.
  • Building operational and security dashboards for SOC monitoring and reporting.
  • Working closely with SOC analysts to improve threat detection, investigation, and incident response processes.


Ideal Candidate Profile

  • We are looking for a candidate who can demonstrate practical, hands-on experience in most of the following areas:
  • Managing and supporting production Splunk Enterprise environments
  • Deploying, upgrading, migrating, and troubleshooting Splunk infrastructure
  • Designing and implementing log forwarding and data onboarding solutions
  • Creating Splunk dashboards, reports, and operational monitoring solutions
  • Building and operating SIEM use cases using Splunk Enterprise Security
  • Developing correlation searches, notable events, and Risk-Based Alerting frameworks
  • Troubleshooting ingestion, parsing, normalization, and ES-related issues
  • Collaborating with SOC teams to enhance threat detection and reduce alert fatigue
  • Supporting large-scale enterprise or regulated environments

Peringatan Penting

Jangan pernah kongsikan maklumat bank atau kad kredit anda semasa memohon pekerjaan. Elakkan membuat sebarang pembayaran atau mengisi survey yang tidak berkaitan. Jika ada yang mencurigakan, sila laporkan iklan pekerjaan ini segera.

Lebih Lanjut