palo_alto_networks
Sr Information Security Engineer
palo_alto_networks, Santa Clara, California, us, 95053
OVERVIEW
Come join Palo Alto Networks as part of the Security Engineering team as a Sr. Information Security Engineer specializing in Splunk management. We are seeking creative problem solvers with a passion for innovation to join our team. In this role you will be responsible for executing security related data engineering programs and managing data management platforms. You will be working very closely with cross functional teams to manage and develop tools and infrastructure that enable the Information Security team to prevent, detect, contain and manage risks within the Palo Alto Networks enterprise environment. You will have an extensive background in managing and engineering Splunk solutions within an enterprise environment; including design, implementation, and maintenance of all aspects of Splunk and its components. This is a fast-paced, post-startup environment. Successful candidates will be customer-oriented, results-driven and passionate about building great products that will impact across the organization.
RESPONSIBILITIES:
Demonstrate a mastery of Splunk and its components.
Understand and interpret customer requirements for Splunk implementation for an enterprise solution.
Provide deployment strategies with the understanding of affordable risk based on customer acceptance.
Develop dashboards with visual metrics for stakeholders.
Maintain the overall Splunk solution to include maintenance, enhancements and integration.
Support testing of new integrations for infrastructure and production performance.
Develop and manage Splunk data visualizations, reports, alerts, searches, dashboards for information security programs and be an expert of critical security application such as Enterprise Security.
Collaborate with internal customers to establish strong requirements and develop project plans to deliver products and services.
Partner with security engineers, threat management staff and infrastructure engineers to build security products that help secure the brand, trust and customer experience.
Work with security operation team to transfer knowledge and operational process to publish services for run-the-business consumption of developed solutions.
Participate in working groups to problem solve and identify methods to improve or enhance existing tools, products and services.
Perform work on security data analytics involving data mining, ETL, machine learning and data visualization.
Assist with security incidents, investigations, root-cause analysis and support real-time tools development to enable prevention, or to drive down detection and containment times in partnership with the Security Operations and Engineering teams.
Adopt and evangelize our prevention oriented network security architecture, and embody the role of first customer of Palo Alto Networks’ product suite.
REQUIREMENTS:
US citizen or permanent resident (green card holder).
Bachelor degree in Computer Science or related field or equivalent experience/training, Master’s Degree in Computer Science a plus.
Knowledge of and practical experience of integration of COTS or open source tools into Splunk.
3+ years experience in managing Splunk platform.
Strong in Splunk search language and Regular Expression.
Strong understanding of logging technologies (Syslog, Windows Events and UNIX logging).
Extensive knowledge of tier Splunk installation, indexers, forwarders, search heads, clustering.
Experience in at least one scripting language preferably Python, Perl, Ruby, PowerShell or Shell script.
Knowledge in MVC, MySQL, Postgres, SQL, RESTful API.
Good understanding of XML, XML schema, and related technologies.
Good understanding of statistical and predictive modeling concepts, machine-learning approaches, clustering and classification techniques, and recommendation and optimization algorithms.
Experience in working and developing in both Unix/Linux and Windows environments.
Knowledge of network devices, firewalls, IDS/IPS, TCP/IP protocols, and general network architecture.
Excellent written and verbal communication skills.
Experience with Agile development, SCRUM or extreme programming methodologies.
Ability to establish priorities, work independently and proceed with objectives.
Must be well organized and able to leverage best practices, able to thrive in fast-paced environment, and, most importantly, have the ability to approach problems with an innovative, can-do attitude.
This position is located in Santa Clara, CA.
PREFERRED QUALIFICATIONS:
Splunk certifications are a plus.
CNSE (Palo Alto Networks), CCNP, CCIE, CISSP/CISM, SANS GIAC, or other Networking and Security certifications a plus.
Security engineering experience across the stack (Network, Application, Physical layers) a plus.
Experience with multiple technologies including Hortonworks, Cloudera, Cassandra or other Big Data Solutions, ELK or other Data Collection and Aggregation Solutions.
Demonstrated interest in security research.
Proficient in MS Office applications including Visio and PowerPoint.
Experience with Cloud computing a plus.
#J-18808-Ljbffr
#J-18808-Ljbffr