Expertise in SIEM (secure identify and Event Management) tools such as Splunk
Transition management of security operations Center (SOC) from current set up to the proposed new state (and define its roadmap, transition plan, actionable, responsibilities and project schedule)
Proven experience (8-12 Years) Splunk administration, optimization, and performance tuning in enterprise-level environments.
Deep understanding of Spunk architecture, configuration and best practices for data ingestion , indexing search and storage.
Strong knowledge of Splunk search processing language (SPL) and experience in optimizing complex search queries.
Familiarity with Splunk data models, pivot, and visualization capabilities.
Good understanding of IT infrastructure components, including networking, systems, applications, and security.
Strong communication and interpersonal skills, with the ability to effectively communicate technical concepts to non technical stakeholders.
Splunk certification (e.g., Splunk certified Architect, splunk Certified Admin ) are a plus