OverviewThe Enterprise SIEM data engineering team is responsible for adhering to the bank’s Security Logging and Monitoring standard, along with Governance, Compliance, Access Control, Automation, and data onboarding across multiple technologies.LocationToronto, Ontario, CanadaHours37.5 hours per weekSalary$96,900 - $136,800 CADJob ResponsibilitiesProvide expert Splunk platform engineering, including proposal, data onboarding, and automation.Maintain up‑to‑date knowledge of SIEM platforms such as Splunk and Azure Sentinel.Lead solutions in areas including Enterprise Splunk suite (ITSI, UBA, CRIBL), Microsoft Security Solutions, virtualization and cloud platforms (Azure, Google, AWS), and advanced security monitoring toolsets.Architect, engineer, design, build, support, and document security engineering solutions in collaboration with business, security engineering, and wider engineering teams.Drive high‑profile technology initiatives, manage project goals and deadlines, and interface with leadership, infrastructure, application development, vendors, and service providers.Technical RequirementsAdvanced knowledge of Enterprise Splunk applications and administration.Experience with CIM compliance.Proficiency with Azure Cloud platform.Expertise with Microsoft Security Solutions.Understanding of Windows and/or RHEL/Unix log formats.Proficient in Python scripting.Knowledge of network and server log formats.Experience with Splunk ITSI, UBA, and advanced dashboard and alerting skills.Knowledge of ITS, CRIBL, and onboarding APIs, databases, and Splunkbase apps.Job RequirementsWork autonomously on high‑risk,
complex initiatives with significant organizational impact.Assess and select security tools to meet bank security requirements.Build complex security engineering infrastructure and lead teams.Adhere to security regulatory and compliance requirements.Develop and support less experienced team members.Design, implement, and lead educational programs for the PADE Team.Enforce internal policies for efficiency and responsiveness.Collaborate with stakeholders to onboard data and meet target timelines.Create high‑level and technical presentations for varied audiences.Leverage analytical, reasoning, and organizational skills.Possess excellent verbal and written communication skills.Build effective relationships with internal and external personnel.Manage multiple priorities in a fast‑paced environment.Adapt to changing requirements, handle ambiguity, and make timely decisions.Coordinate with internal engineering, deployment, and operations teams.Apply vendor management and coordination concepts.Document work and transfer knowledge to team members.Lead engineering design decisions and continuous improvement.Education & AccreditationUniversity, postgraduate degree, or 10+ years of experience.Splunk certifications.ISC candidate or Certified Cyber Security Skilled.Strong academic background in computer science or engineering.Certifications in Azure Admin, Splunk Admin, Splunk Developer.Security+, CISSP, CISM, or CISA.Additional InformationAdaptability and continuous learning are critical for designing, building, and automating new technologies.High motivation and a track record of implementing cross‑line‑of‑business security solutions.Exceptional customer service orientation and ability to interact across all organizational levels.Strong negotiation and influencing skills, with vendor management experience as an asset.Excellent oral, written, and presentation skills.#J-18808-Ljbffr
📌 Siem Engineer - C$96,900 - C$136,800 A Year (Toronto)
🏢 TD
📍 Toronto