Strong hands-on experience with Splunk Enterprise Security (ES).
Experience implementing and supporting SIEM platforms, preferably Splunk.
Good understanding of SOAR platforms (Splunk SOAR preferred; experience with Cortex XSOAR, IBM Resilient, Microsoft Sentinel Automation, or similar products is also acceptable).
Security use case development and content engineering.
Detection engineering, correlation searches, dashboards and reporting.
Incident investigation and threat hunting.
MITRE ATT&CK framework, Cyber Kill Chain and SOC processes.
Log onboarding, parsing, CIM normalisation and data models.
Experience integrating security products such as Firewalls, EDR, IAM, Cloud and Network Security solutions.
Strong troubleshooting and customer-facing consulting skills.