Security Analyst III (Senior Privilege Access Monitoring Implementation Specialist)

Talteam Inc.

$100K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years experience in security operations or SIEM engineering
  • 3+ years of hands-on experience with Splunk
  • Advanced skills in developing Splunk correlation searches and dashboards
  • 2+ years of experience using SOAR platforms like Cortex XSOAR
  • Deep understanding of IAM and privilege access monitoring
  • Experience with alert tuning and reducing false positives

Responsibilities

  • Design privilege access event monitoring logic to identify relevant security activity
  • Develop intelligent alert routing to differentiate security threats from normal events
  • Optimize Splunk correlation searches and custom alert rules
  • Configure rules to reduce alert noise and improve quality
  • Automate incident handling through SOAR workflows and playbooks
  • Integrate SIEM, SOAR, and ticketing for consistent incident management
  • Create dashboards for monitoring alert performance and operational effectiveness

Benefits

  • Opportunity to work with cutting-edge SIEM and SOAR technologies
  • Contribute to key projects enhancing security operations
  • Collaborate with experienced security engineering teams
  • Gain valuable experience in privilege access monitoring methodologies
  • Opportunity for knowledge transfer and professional development
Full Job Description
Security Analyst III (Senior Privilege Access Monitoring Implementation Specialist)

Must haves: 4-5 years Splunk experience, 4-5 years IAM experience, monitoring-preferred (previous analyst work)

The contingent worker will serve as a Senior Privilege Access Monitoring Implementation Specialist responsible for designing, building, testing, and documenting a privilege access event monitoring solution within the organization's security operations environment. This resource will support the enhancement of security alerting capabilities by improving privileged access visibility, reducing false positives, and implementing intelligent alert routing and automation using SIEM and SOAR technologies.

The resource will work closely with the security operations and engineering teams to implement advanced Splunk correlation searches, risk-based alerting logic, SOAR playbooks, alert enrichment workflows, and operational dashboards. The engagement will focus on delivering a production-ready monitoring capability that enables more accurate detection, prioritization, and handling of privileged access-related events.

Key Responsibilities
The contingent worker will be responsible for the following activities:

Design and implement privilege access event monitoring logic to identify security-relevant privileged access activity.
Develop intelligent alert routing and correlation logic to distinguish true security threats from routine operational events.
Build and optimize Splunk correlation searches, custom alert rules, and risk-based alerting logic.
Configure filtering, suppression, and enrichment rules to reduce alert noise and improve alert quality.
Design and develop SOAR workflows and playbooks to automate incident handling and alert consolidation.
Integrate SIEM, SOAR, and ticketing processes to support consistent incident routing and management.
Create enrichment logic that adds relevant context to alerts, including user, asset, access, and threat-level information.
Build dashboards and reports to monitor alert health, performance, volume, and operational effectiveness.
Test the implementation against historical datasets of at least 60 days to validate alert accuracy and volume reduction.
Document all implemented searches, workflows, logic, playbooks, dashboards, edge cases, and operating procedures.
Create runbooks and operational guides for ongoing support and maintenance.
Provide knowledge transfer and training to security operations and engineering teams prior to engagement completion.
Required Skills and Experience
The requested resource must have the following skills and experience:

Minimum of 5 years of experience in security operations, SIEM engineering, security engineering, or a related cybersecurity function.
At least 3 years of hands-on Splunk experience in production environments.
Advanced proficiency developing Splunk correlation searches, custom alert rules, dashboards, and reports.
Experience configuring and implementing Splunk Risk-Based Alerting for security use cases.
Strong understanding of Splunk data pipelines, search performance optimization, indexing, field extraction, and alert tuning.
At least 2 years of hands-on experience with SOAR platforms such as Cortex XSOAR, Demisto, or comparable orchestration platforms.
Experience designing and implementing complex SOAR playbooks, workflows, automation logic, and incident handling processes.
Experience integrating SOAR platforms with SIEM tools, ticketing systems, and other security operations technologies.
At least 2 years of experience with privilege access monitoring, identity and access management security, privileged access management, or related security operations use cases.
Understanding of privilege escalation detection methodologies, authorization frameworks, access control models, and IAM-related security monitoring.
Proven experience reducing false positives and improving alert fidelity in high-volume security

Similar Jobs

More Jobs at Talteam Inc.

  • Engineer
    $80K — $95K *
    Liberty, NC 27298 (Randolph County)
    Manufacturing & Automotive
    In-Person
  • Cloud DevOps Engineer
    $110K — $130K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person
  • Structural/Civil Field Engineer
    $80K — $95K *
    San Antonio, TX 78228 (Bexar County)
    Real Estate & Construction
    In-Person
  • Project Manager - Marketing
    $100K — $120K *
    Burbank, CA 91505 (Los Angeles County)
    Business Services
    In-Person
  • Cloud Engineer
    $110K — $130K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Security Analyst III (Senior Privilege Access Monitoring Implementation Specialist) jobs: