Hiring.Camp

Senior Privilege Access Monitoring Implementation Specialist

TheStaffed

·

Yesterday

Type
Contract
Seniority
Senior
Experience
5+ years
Source
RecruiterFlow

Description

Our client is seeking a Senior Privilege Access Monitoring Implementation Specialist to design, build, and optimize enterprise-grade privilege access event monitoring and alerting infrastructure, focusing on implementing intelligent correlation logic, SOAR workflows, and alert tuning to enhance security operations maturity and reduce false positives at scale.

Responsibilities & Qualifications

  • Design and implement privilege access event monitoring logic and correlation searches within Splunk, translating security requirements into operational detection rules
  • Develop intelligent alert routing, filtering, suppression, and enrichment logic to optimize alert quality and reduce false positives
  • Build and optimize Splunk correlation searches, Risk-Based Alerting (RBA) rules, and custom alert rules tailored to privilege access monitoring use cases
  • Design, develop, and deploy SOAR workflows and playbooks (Cortex XSOAR/Demisto) to automate incident handling and integrate with ticketing and SIEM platforms
  • Create monitoring dashboards, reports, and metrics to track alert health, tuning effectiveness, and operational KPIs
  • Test implementations against historical datasets and validate alert performance; document all searches, workflows, playbooks, and operational procedures
  • Provide knowledge transfer, training, and runbook development to security operations and incident response teams

Requirements

  • 5–8 years of experience in security operations, SIEM engineering, and privilege access monitoring or related disciplines
  • Advanced proficiency with Splunk, including correlation searches, Risk-Based Alerting, alert tuning, and custom rule development
  • Hands-on experience with SOAR platforms (Cortex XSOAR and/or Demisto) and SOAR playbook development
  • Strong background in Privileged Access Management (PAM) concepts and enterprise privilege access event detection and monitoring
  • Demonstrated expertise in alert tuning, false positive reduction, and alert enrichment logic design
  • Proven ability to integrate SIEM, SOAR, and ticketing systems; experience with incident handling workflows is essential
  • 1099, C2C, or W2 contract eligibility required

Skills

SIEMSplunk