Support Engineer - Geylang
Geylang Temporary
We are looking for Support Engineer, the proposed Splunk Engineer shall have the following qualifications:
- At least 3 years’ experience working on Splunk system
- Possess Splunk Enterprise Certified Admin certifications or equivalent.
- The Splunk Engineer shall perform critical high-risk works during maintenance windows specified by the Client, which may be off-office hours or during weekends.
- The Splunk Engineer shall be responsible of all the corrective and preventive maintenance of the Splunk systems in all environments.
- The Splunk Engineer shall remediate all vulnerabilities or penetration test findings pertaining to the Splunk systems.
- The Splunk Engineer can raise tickets to Splunk principal for support and queries.
- Perform checks and troubleshoot, if necessary, to ensure the Client’s Splunk services are running as intended for all environments.
- Maintain and monitor Splunk infrastructure (Search Heads, Indexers, Forwarders, Deployment Server, Cluster Master, etc.).
- Ensure uptime and system health via monitoring, tuning, and log analysis (including introspection, metrics logs).
- Manage indexing performance and storage usage: data retention, index lifecycle, bucket management.
- Generate and check reports from the system to ensure the system and agents are working as intended
- Perform checks and troubleshoot, if necessary, to ensure that the Splunk forwarders (agents) are working and can pipe logs back to Splunk systems.
- Perform checks and troubleshoot, if necessary, to ensure the Splunk systems can receive logs from sources such as CloudWatch or syslog servers.
- Integrate Splunk with the Client’s systems and processes to perform real-time monitoring and alert when Splunk infrastructure is not working well, so that issues can be attended to early. (e.g., log breaks, disconnected agents, search-head hung from insufficient resources, etc)
- Fine tune Splunk rules according to the Client’s request.
- Perform parser validation or write new custom parser according to the Client’s request
- Work closely with the Client’s SOC to ensure Splunk supports threat detection, auditing, and incident response use cases.
- Change the passwords for all privilege and services accounts for the Splunk systems regularly
- Ensure the Splunk systems is working as intended during the Client’s periodic BCP and DR exercises.
- Investigate problems and provide assistance to triage issues.
- Correct defects in the System, including temporary corrections or workarounds until permanent fixes or updates are available.
- Prepare incident report including the root cause analysis and necessary resolution
- Track and report issues, support cases and incident resolutions on a weekly basis.
- Monitor Security advisory, new releases, notifications and maintenance expiry dates for all Software used in the System and assess the impact, if any.
- Recommend to the Client the best course of action to take and provide all relevant documentation.
- If the issue arises from a security vulnerability or software incompatibility, the RE shall evaluate and implement fixes to address the vulnerability or incompatibility.
- Check and remediate findings from the Client’s periodic vulnerability and compliance scans.
- Track and update the Client on the DLP End of Life (EOL) and End of Support (EOS) and plans to maintain product supportability.
- Deploy and test system changes in the non-Production environments when required.
- Demonstrate that System functionality and performance are not degraded.
- Implement the system changes into the Production environment upon the Client’s acceptance of the testing results.
- Implementation of additional use cases, report design and development and tuning to reduce false positives and negatives.
- Create or provide the Client with all System related documentation, including standards and procedures, operation manuals, workflows, processes, etc.
- Update the relevant documentation when changes are made to the System or processes.
Geylang
About the role
Gissmatic Automatisierung Pte Ltd is seeking a talented Technical Support Engineer to join our growing team. As a Technical Support Engineer, you will be responsible for providing high-quality technical support for industrial...
UNISON CONSULTING PTE. LTD.Bedok, 4 km from Geylang
The Splunk Engineer shall remediate all vulnerabilities or penetration test findings pertaining to the Splunk systems.
• The Splunk Engineer can raise tickets to Splunk principal for support and queries.
System Operations
a)Perform checks and troubleshoot...
Toa Payoh, 4 km from Geylang
We are looking for Support Engineer, the proposed Splunk Engineer shall have the following qualifications:
• At least 3 years’ experience working on Splunk system
• Possess Splunk Enterprise Certified Admin certifications or equivalent...