OVERVIEW
Come join Palo Alto Networks as part of the Security Engineering team as
a Sr. Information Security Engineer specializing in Splunk management.
We are seeking creative problem solvers with a passion for innovation to
join our team. In this role you will be responsible for executing
security related data engineering programs and managing data management
platforms. You will be working very closely with cross functional teams
to manage and develop tools and infrastructure that enable the
Information Security team to prevent, detect, contain and manage risks
within the Palo Alto Networks enterprise environment. You will have an
extensive background in managing and engineering Splunk solutions within
an enterprise environment; including design, implementation, and
maintenance of all aspects of Splunk and its components. This is a
fast-paced, post-startup environment. Successful candidates will be
customer-oriented, results-driven and passionate about building great
products that will impact across the organization.
RESPONSIBILITIES:
- Demonstrate a mastery of Splunk and its components.
- Understand and interpret customer requirements for Splunk
implementation for an enterprise solution.
- Provide deployment strategies with the understanding of affordable
risk based on customer acceptance.
- Develop dashboards with visual metrics for stakeholders.
- Maintain the overall Splunk solution to include maintenance,
enhancements and integration.
- Support testing of new integrations for infrastructure and
production performance.
- Develop and manage Splunk data visualizations, reports, alerts,
searches, dashboards for information security programs and be an
expert of critical security application such as Enterprise Security.
- Collaborate with internal customers to establish strong requirements
and develop project plans to deliver products and services.
- Partner with security engineers, threat management staff and
infrastructure engineers to build security products that help secure
the brand, trust and customer experience.
- Work with security operation team to transfer knowledge and
operational process to publish services for run-the-business
consumption of developed solutions.
- Participate in working groups to problem solve and identify methods
to improve or enhance existing tools, products and services.
- Perform work on security data analytics involving data mining, ETL,
machine learning and data visualization.
- Assist with security incidents, investigations, root-cause analysis
and support real-time tools development to enable prevention, or to
drive down detection and containment times in partnership with the
Security Operations and Engineering teams.
- Adopt and evangelize our prevention oriented network security
architecture, and embody the role of first customer of Palo Alto
Networks’ product suite
REQUIREMENTS:
- US citizen or permanent resident (green card holder)
- Bachelor degree in Computer Science or related field or equivalent
experience/training, Master’s Degree in Computer Science a plus
- Knowledge of and practical experience of integration of COTS or open
source tools into Splunk
- 3+ years experience in managing Splunk platform
- Strong in Splunk search language and Regular Expression
- Strong understanding of logging technologies (Syslog, Windows Events
and UNIX logging).
- Extensive knowledge of tier Splunk installation, indexers,
forwarders, search heads, clustering.
- Experience in at least one scripting language preferably Python,
Perl, Ruby, PowerShell or Shell script
- Knowledge in MVC, MySQL, Postgres, SQL, RESTful API
- Good understanding of XML, XML schema, and related technologies
- Good understanding of statistical and predictive modeling concepts,
machine-learning approaches, clustering and classification
techniques, and recommendation and optimization algorithms.
- Experience in working and developing in both Unix/Linux and Windows
environments
- Knowledge of network devices, firewalls, IDS/IPS, TCP/IP protocols,
and general network architecture
- Excellent written and verbal communication skills
- Experience with Agile development, SCRUM or extreme programming
methodologies
- Ability to establish priorities, work independently and proceed with
objectives
- Must be well organized and able to leverage best practices, able to
thrive in fast-paced environment, and, most importantly, have the
ability to approach problems with an innovative, can-do attitude
- This position is located in Santa Clara, CA
PREFERRED QUALIFICATIONS:
- Splunk certifications are a plus
- CNSE (Palo Alto Networks), CCNP, CCIE, CISSP/CISM, SANS GIAC, or
other Networking and Security certifications a plus
- Security engineering experience across the stack (Network,
Application, Physical layers) a plus
- Experience with multiple technologies including Hortonworks,
Cloudera, Cassandra or other Big Data Solutions, ELK or other Data
Collection and Aggregation Solutions
- Demonstrated interest in security research
- Proficient in MS Office applications including Visio and PowerPoint
- Experience with Cloud computing a plus
LEARN MORE ABOUT PALO ALTO NETWORKS HERE AND CHECK OUT OUR FAST FACTS !