Mission: SOC | Splunk Architect at NATIXIS BANK
Splunk Architect within the SSI SOC team:
- Operational management of the SOC team (incident response management)
- Splunk architecture administration:
• Large architecture 1 Tb per day
• Splunk enterprise security
• Indexes clustering, search head clustering
• Deployment server
• Interconnection with other infrastructure
- Development and updating of security control algorithms (connection of an absent user, identity theft, atypical behaviour ...)
- Development and updating of information leak detection algorithms (emails, internet uploads, printing)
- Development of a scoring tool to identify user’s atypical behaviour
- Data onboarding
- Participation in a various intergroup and interbank security committees
- Animate Splunk training
- Participation in the development of Cyber defense strategy and cyber crisis
Title: Splunk Expert
Key words: Splunk, Splunk ES, SOC, RSA Analytics, BigData, Machine Learning, Python, Compliance, Threat Intelligence, CERT
- Drive Splunk integration projects at Topnet, AMDM and GIRC
- Drive Splunk POCs at Amen Bank, COMAR, AGIL
- Member of Alliacert team
- Design and development of a threat intelligence application
Mission: Splunk | Monitoring Expert at BNP CIB
In the CIB-ITO-Corporate Banking Entity
Member of the expertise team of the Connexis Cash application (Treasury Operations, Cash Flow)
- Splunk architecture administration:
• Search head pooling
• Deployment server
• Interconnection with other infrastructure
- Manage monitoring of Connexis cash framework in different environments: UAT, Qualif and Prod
- Prepare technical roadmaps
- Participate in Stress Testing, capacity planning and performance optimization
- Drive studies, POCs in pre-project phase
- Manage security projects: files scan, strong authentication, SSO
Mission: Splunk Expert at Kering Group
- Hybrid architecture (3 search head + 4 indexers + 2 heavy forwarders + 100 forwarders) License 200 GB / day
- Splunk enterprise security POC
- Apps installations and configuration
- Alerts and dashboards development
- Splunk support and troubleshooting
- Animate Splunk training
Mission: Splunk Expert at Palatine Bank
- Splunk architecture administration:
- Apps installations and configuration
- Alerts and dashboards development
- Splunk support and troubleshooting
- Animate Splunk training
Title: Pre-sales | integration engineer
- Drive Splunk integration projects at STEG, Attijari Bank and the Ministry of Higher Education
- POC Splunk in Orange, Tunisiana, Tunisair, ULT,
- Pre-sales manager of security products like Splunk, Veeam, VMware, Storage, GFI, Solarwinds, ESET, Fortinet and PaloAlto
Enregistrer tout