Senior Cybersecurity Expert - Splunk H/F Visian
- Paris - 75
- Freelance
- Bac +5
- Services aux Entreprises
- Exp. 4 à 10 ans
À noter sur ce job
Vous avez ces compétences ? Cliquez dessus pour les ajouter rapidement à votre profil !
Détail du poste
What they need
Context
As a Splunk Administrator in the Global Security Operations Center (GSOC) on the Detection & Automation team, you will play a pivotal role in identifying, investigating, and mitigating cybersecurity threats within a complex and dynamic environment. Your primary responsibility will be to work collaboratively with other analysts, MSSP (Managed Security Service Provider), and CERT teams to respond to and prevent cyber incidents, while ensuring the security and integrity of the organization's infrastructure. This is an advanced role requiring a deep understanding of security operations, incident response, and the latest cyber threat trends.
As a Splunk Expert within GSOC, you will deliver comprehensive support to maintain the reliability and efficiency of cybersecurity monitoring platforms. Responsibilities include integration of data sources and entities, access and asset management, data quality assurance, log normalization, and recovery of log collection in case of disruptions.
Given the 24/7 nature of GSOC operations, participation in an on-call rotation is required, typically scheduled for one week per month, depending on the rotation plan defined by the Service Delivery Manager.
Missions
Administer applications and manage user access within the Splunk platform.
Perform regular maintenance and ensure platform stability.
Design and generate reports and dashboards to support operational and security needs.
Manage data ingestion processes and oversee integration of data sources and logging equipment into Splunk.
Ensure accuracy, consistency, and cleanliness of ingested data.
Restore log collection in case of data loss or interruption.
Communicate with internal teams and external clients, primarily in French and English.
Contribute to the expansion and evolution of monitoring and detection coverage.
Support automation efforts for data integration and quality assurance workflows.
Create technical documentation and user guides for internal and external use.
Participate in a shared on-call rotation (6-person team) for Splunk and related tools.
Assist with migration and transformation initiatives related to Splunk or associated collection systems.
Develop and deploy machine learning algorithms to enhance analytical and detection capabilities.
Contribute to the creation of cybersecurity detection rules and implementation of use cases.
Continuously propose enhancements to tools, procedures, and incident response to strengthen threat detection and mitigation.
Build dashboards and define security metrics and KPIs.
Engage in internal security communities and contribute to knowledge sharing across teams.
Tools & Environment
Splunk platform handling 8 TB of data per day
Splunk Core, Splunk Enterprise Security, Splunk ITSI, Splunk SC4S
Python scripting for automation and support
Ticketing systems (e.g., ServiceNow) and SLA management
Confluence for procedure management
Collaboration with MSSP and CERT teams
Machine learning algorithms for detection enhancement
Additional Information
Reference: MOE-26-09-04-1461 / ITS-FR-436-25-Security-Cybersecurity expert-Senior
Response date: 17/09/2026
Le profil recherché
Profile wanted
- At least 4 years of hands-on experience managing complex Splunk production environments, including Splunk Enterprise Security, Splunk ITSI, Splunk Cloud, and Splunk SC4S
- Proven track record in designing, implementing, and optimizing detection rules
- Solid experience in developing automation and support scripts using Python
- Experience with ticketing systems and SLA management
- Strong expertise with SPLUNK (8-10 years experience)
- Operational rigor and ability to interact with cyber, cloud, and data teams
- Excellent communication skills
- Solid understanding of network security principles and operating systems
- Scripting capabilities to automate repetitive actions
- Experience with modern ticketing systems such as ServiceNow and ITIL-based service management frameworks
- Good familiarity with Confluence for procedure management
Infos complémentaires
Publiée le 11/09/2026 - Réf : 8390b1ef703e2820f3ee2447d1e7c251