2 months ago
Taguig City, PhilippinesStaff+
Responsibilities
- Own enterprise Splunk Cloud architecture, platform health, configuration, indexing strategy, data models, detection content, and long-term evolution.
- Define and enforce engineering standards for Splunk correlation searches, dashboards, reports, field extractions, CIM compliance, use cases, and detection coverage.
- Own AWS architecture supporting security data pipelines and SIEM operations, including cloud-native log integration, telemetry instrumentation, reliability, and cost optimization.
- Own Cribl architecture, deployment strategy, governance, pipeline design, data routing, enrichment, data reduction, noise filtering, and licensing cost management.
- Set technical direction and engineering standards for the SIEM engineering team and serve as the final escalation point for complex platform, detection, and pipeline challenges.
- Partner with the Senior Manager and senior leadership on SIEM roadmaps, maturity metrics, technical risk, data retention standards, vendor relationships, and emerging technologies.
- Mentor SIEM engineers, support hiring and technical interviews, and lead post-incident and post-project reviews.
- Analyze security events, operationalize threat intelligence, lead remediation plans, and drive automation and platform improvements.
Requirements
- BA or BS in Computer Science, Management Information Systems, Engineering, or a related field is required; significant practical experience combined with certifications may be considered instead, and an MS is strongly preferred.
- 10+ years of progressive computing and information security experience with a trajectory toward senior technical leadership.
- 7+ years of deep, hands-on Splunk experience, including Splunk Cloud architecture, administration, content development, and optimization; this is a hard requirement.
- 5+ years architecting and managing security data pipelines in AWS, including S3, Kinesis, Lambda, CloudWatch, IAM, and related services.
- 3+ years of hands-on enterprise Cribl experience covering pipeline architecture, data routing, and optimization.
- Documented ownership of and contribution to enterprise SIEM program direction, plus experience executing multi-year technical roadmaps with senior leadership.
- Experience with ArcSight, QRadar, ELK, or Sentinel is complementary but does not replace the required Splunk expertise.
- Understanding of TCP/IP, ICMP, DHCP, DNS, and other core network protocols.
- Proficiency in one or more programming or scripting languages such as Python, PowerShell, or Bash, with the ability to drive automation initiatives.
- Deep knowledge of Linux environments, including configuration management and application administration.
- Splunk Certified Architect and Splunk Enterprise Security Certified Admin certifications are strongly required; Splunk Certified Administrator is required, and AWS and Cribl certifications are desired or strongly desired as specified.
Benefits
- Requires some weekend and evening assignments and availability during scheduled and unscheduled off-hours activities.
- Requires awareness of platform health and program status beyond standard business hours.
About Asurion
As the world’s leading tech care company, Asurion eliminates the fears and frustrations associated with technology, to ensure our 300 million customers get the most out of their devices, appliances and connections. We provide insurance, repair, replacement, installation and 24/7 support for everything from cellphones to laptops and household appliances. Our experts are available online, on the phone, at one of our more than 800 stores, or can even come to you.
