Working with the Cybersecurity Incident Response Team and Threat Intelligence Team to identify content improvements.
Assisting the Cybersecurity Incident Response Team and Threat Intelligence Team with searches by acting an expert in Splunk Search Language.
Provides input to the overall SIEM security architecture, governance model.
Provide technical oversight, standardization and validation of the effectiveness of SIEM content service.
Participate in efforts to research, design and implement components in the SIEM content development space there are standards-based, high-performing, highly available and secure.
Educated internal and external users of security technologies to continually improve the knowledge and skill-base of the organization on how best to operate and support the technology and security services.
Supports, implements and promotes standard configuration and change management, processes and practices.