What is the Opportunity?
RBC Defensive Threat Operations (DTO) team is seeking an experienced Splunk Engineer with demonstrated competence and thought leadership capability to contribute toward the success of our Cyber Resiliency initiatives. Under the direction of the Director of Correlation Engineering, the Senior Splunk Engineer is responsible for maintaining the RBC Security Information Event Management (SIEM) platform and data pipeline infrastructure.
What will you do?
The Senior Splunk Engineer is a hands‑on technologist who is an expert in the technologies that comprise the RBC SIEM platform architecture and creates and tunes SIEM rules to adjust the specifications of alerts and security incidents. The scope of this position is enterprise‑wide and requires a deep understanding of the security controls RBC uses and how they provide value to the business. The incumbent will work closely with other members of the Global Security teams to ensure the security posture of RBC is maintained and take a proactive approach in continually assessing the effectiveness and efficiency of the SIEM platform.
Essential Functions
- Serve as a Subject Matter Expert (SME) for the SIEM and Splunk platform.
- Develop and implement effective correlation rules.
- Tune SIEM components to ensure maximum reliability and reduce false positives.
- Review security context alerts and log sources.
- Develop and implement effective data pipelines and routing rules.
Essential Capabilities
- Ability to relate to non‑technical users in user‑friendly language.
- Ability to understand or learn the technical implications of security threats.
- Ability to manage multiple concurrent objectives or activities, and effectively make judgments in prioritizing and time allocation in a high‑pressure environment.
Qualifications
Must‑have
- Bachelor of Science in a technology‑related discipline or 3 years of relevant experience.
- 5 years of experience in a role dedicated to the configuration, maintenance and administration of Splunk Enterprise Security and data pipeline infrastructure such as Cribl.
- Proficiency in developing and optimizing Splunk queries, dashboards, and alerts.
- Significant experience with and working knowledge of Syslog.
- Experience with scripting languages (Python, Bash, or PowerShell) for automation and tool integration.
- Significant experience with and expertise in creating event correlation logic and rules.
- Hands‑on experience deploying and managing Splunk in cloud environments (AWS, Azure, GCP).
- Excellent troubleshooting, problem‑solving, and verbal/written communication skills.
- Ability to manage critical situations and maintain solid relationships with colleagues.
- 3+ years of experience in data pipeline infrastructure configuration, maintenance, and administration with Cribl or similar platforms.
Nice‑to‑have
- Splunk Enterprise Certified Architect (preferred).
- Splunk Core Certified Power User or Admin (minimum).
- Cribl Certified Administrator (CCA).
- Certified Information Systems Security Professional (CISSP).
Benefits
- A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable.
- Leadership support for development through coaching and management opportunities.
- Opportunity to make a difference and lasting impact.
- Working in a dynamic, team-oriented, progressive, and high‑performing team.
- A world‑class training program in financial services.
- Flexible work/life balance options.
Job Skills
- Decision Making
- Group Problem Solving
- Identity Access Management (IAM)
- Information Security
- Information Technology Security
- IT Systems Integration
- Negotiation
- Security Controls
- Security Information
- Security Information and Event Management (SIEM)
- SIEM Tools
- Software Development
- Software Development Life Cycle (SDLC)
- Strategic Objectives
#J-18808-Ljbffr
📌 Senior Splunk Engineer (Global Security) (Toronto)
🏢 RBC
📍 Toronto