Logo
ITmPowered Consulting

ITmPowered Consulting is hiring: Splunk Threat Content Developer – Cloud API Thr

ITmPowered Consulting, Atlanta, GA, United States, 30383

Save Job

Splunk Threat Content Developer – Cloud API Threat Detection (BHJOB22048_760) Join to apply for the Splunk Threat Content Developer – Cloud API Threat Detection (BHJOB22048_760) role at ITmPowered Consulting Splunk Threat Content Developer – Cloud API Threat Detection (BHJOB22048_760) 3 months ago Be among the first 25 applicants Join to apply for the Splunk Threat Content Developer – Cloud API Threat Detection (BHJOB22048_760) role at ITmPowered Consulting ITmPowered Consulting Splunk Threat Content Developer – Cloud and API Threat Detection – Remote Splunk Threat Content Developer will develop, implement, and oversee content development for Threat Detection, Threat Analysis, and Threat investigations focused on Cloud Security and API Security. Bring your Splunk Content Engineering in Threat Detection, Threat analysis, Threat investigation, Splunk Security Analytics, for Cloud (Azure, AWS, SaaS, IaaS, PaaS) as well as API Security / OWASP threats. Contract Atlanta, GA Posted 2 years ago ITmPowered Consulting Splunk Threat Content Developer – Cloud and API Threat Detection – Remote Splunk Threat Content Developer will develop, implement, and oversee content development for Threat Detection, Threat Analysis, and Threat investigations focused on Cloud Security and API Security. Bring your Splunk Content Engineering in Threat Detection, Threat analysis, Threat investigation, Splunk Security Analytics, for Cloud (Azure, AWS, SaaS, IaaS, PaaS) as well as API Security / OWASP threats. Responsibilities Lead Splunk content development focused on Threat (detection, analytics, investigation, and response) for Cloud Security (SaaS / IaaS / PaaS) and API Security (OWASP) threat use cases. Focus on: Cloud and API Threat Detection engineering, Content engineering, Splunk Enterprise Security, Cloud and API Security Threat content (OWASP, API Security, Cloud Security, and Healthcare security). Develop and implement Custom Splunk content and dashboards for analysts on emerging Cloud/API threats. Provide threat visibility and awareness for Cyber Security organization for new security capabilities. Engineer Splunk content Cloud /API Security Threat Detection, alerting, dashboards, IR runbooks, automation. Develop Splunk Content for Cloud / API Security threat use cases (cloud, container, or orchestration misconfiguration, OWASP vulnerabilities, Injection Flaws, insecure network policies, logging & monitoring / runtime threats, CI/CD pipeline & supply chain flaws, cloud IAM roles, Account hijacking, Data exfiltration) Cloud Identity Management, privileged access escalation, Key Management threat scenarios. Engineer Splunk content to monitor continuously for anomalous API traffic, remediate threats near real time. Engineer Splunk content for API Security Threat use cases (Broken authentication / access controls, security misconfigurations, automated threats, unsafe API consumption, Injection, request forgery, etc.) Engineer cloud threat Splunk correlation searches which provide the alerting mechanisms used by the SOC. Review newly ingested data sources for potential security alerts and create dashboards. Qualifications, Skills, And Experience Splunk experience and certifications Strong experience in Splunk content development, building dashboards, reports and lookup tables. Experience with API Security, Cloud Security, and OWASP Familiarity with Cloud Security (Azure) and / or Cloud Security Posture Management (CSPM) Programming experience (Splunk SPL, Python, Java, C++, Perl, HTML, CSS, Ansible, other) Expertise in large scale cyber security data analytics, identifying data-driven threat collection opportunities. Implementation, Operation and/or Management of SIEM solutions Experience with common enterprise IT tools and logs (AD/AAD, IAM/MFA, CSPM, etc.) Experience with Windows and Linux tools Security certifications (GIAC/SANS, ISC (2), EC-Council, etc.) Experience with automating common repeatable tasks using a variety of tools and methods. Information security analysis experience in a Cyber Security Operations Center (CSOC) Soft Skills Ability to collaborate with others, leveraging many project approaches (Agile/Scrum, Waterfall, Gantt Charts) Comfortable working remotely with team members around the country. Self-starter with intellectual curiosity Development of technical documents or presentations – IR/SOC threat runbooks Logistics Work remotely anywhere in Domestic US. Preferred locations Colorado or Georgia. COVID-19 Vaccine and Booster Required – OR must provide valid medical exemption from doctor in advance. Must be able to successfully pass a 12-panel drug screen, 10-year background check, employment verification. You will need to be a current US Citizen or valid Green Card holder. No need for visa now or in future. This role is not able to offer visa transfer or sponsorship now or in the future. W2 only – No sub vendors. Sponsorship NOT available. Must have direct contact information on resume (phone / email) to be considered. To apply for this job email your details to careers@itmpowered.com Seniority level Seniority level Entry level Employment type Employment type Full-time Job function Job function Marketing, Public Relations, and Writing/Editing Industries Business Consulting and Services Referrals increase your chances of interviewing at ITmPowered Consulting by 2x Sign in to set job alerts for “Content Developer” roles. Resume Bank - Content & Creative Positions Technical Writer, Data Centers, Supply Chain Technical Writing Learning & Development Content Developer Atlanta, GA $80,000.00-$95,000.00 1 week ago Content Marketing Specialist (Copywriter) Public Relations Events & Content Creation Intern Television & Film Agent – Content Distribution & Acquisitions Atlanta, GA $80,000.00-$110,000.00 4 days ago Manager - Affiliate Content Center, CNN Newsource Newsgathering Analyst, Digital Content & Product Data - Remote Digital Content Marketing Specialist (Hybrid) Digital Solutions Go to Market and Content Manager Marketing Content Manager - Healthcare/Medical Device Analyst, Category Experience- Enterprise Content Sandy Springs, GA $35.00-$45.00 4 days ago Atlanta Metropolitan Area $40.00-$45.00 4 days ago We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI. #J-18808-Ljbffr