- Company Name
- Techso
- Job Title
- Administrateur(rice) sécurité et réseaux
- Job Description
-
**Job title**
Security & Network Administrator (Splunk Specialist)
**Role Summary**
Design, implement, and maintain enterprise Splunk environments (Enterprise, ES, ITSI) to support SIEM initiatives for clients. Integrate Splunk with other tools via APIs, CI/CD pipelines, and cloud services. Automate deployments using Infrastructure as Code, develop dashboards, alerts, and incident‑correlation logic. Collaborate with security, DevOps, and client teams to enhance security posture, observability, and incident response. Provide on‑site client support when required.
**Expectations**
- Mobile within the Montréal region to meet clients in person.
- Fluent in French and English (spoken and written) for internal and client communication across Quebec and Canada.
- Proven experience working in Agile/Scrum environments.
- Strong analytical mindset, attention to detail, and team‑oriented attitude.
**Key Responsibilities**
1. Architect, configure, and maintain Splunk Enterprise, ES, and ITSI deployments.
2. Integrate Splunk with external applications and services via API, CI/CD, and cloud pipelines.
3. Deploy and manage Splunk environments using IaC tools such as Terraform, Ansible, or CloudFormation.
4. Build and maintain dashboards, alerts, correlation searches, and automated playbooks for threat detection and response.
5. Collaborate with security and DevOps teams to improve security controls and observability.
6. Investigate, analyze, and resolve security incidents, providing root‑cause findings and improvement recommendations.
7. Continuously refine Splunk configurations, adapters, and dashboards to enhance effectiveness.
8. Document solutions, processes, and best practices for internal knowledge sharing.
**Required Skills**
- Proficiency with Splunk Enterprise, Splunk ES, and Splunk ITSI.
- Experience with AWS or Azure environments and related automation tools (Terraform, Ansible, CloudFormation).
- Scripting skills in Python, Bash, or PowerShell.
- Strong understanding of SIEM concepts, threat detection, and incident response.
- Familiarity with API integration, CI/CD pipelines, and cloud service orchestration.
- Excellent communication skills in French and English.
- Ability to work collaboratively in cross‑functional teams and under Agile methodologies.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related discipline.
- (Optional) Relevant certifications such as Splunk Certified Admin, Splunk Certified Enterprise Search, AWS/Azure Cloud Practitioner, Terraform Associate, or Ansible Automation Engineer are advantageous but not mandatory.