TriOptus LLC
Charlotte / Global
You have blocked notifications
Oops! You have blocked notifications. Click here for more info
You have blocked notifications, please check your browser settings.
You're currently subscribed to job notifications
Subscribe to notifications
You will no longer receive notifications
Charlotte / Global
Senior Privileged Access Monitoring Implementation Specialist
Financial Services Account | Remote - US
Client Location:- Charlotte North Carolina
Duration: 6 months with possible extension
Employment Type: Contract
Work Arrangement: Remote - Onshore/Offshore
About the Role
Our financial services client is seeking a Senior Privileged Access Monitoring Implementation Specialist to design, build, test, and document a production-ready privileged access monitoring solution within the security operations environment.
This role will focus on improving privileged access visibility, security alerting, false-positive reduction, intelligent alert routing, and automation using Splunk SIEM and SOAR technologies .
The ideal candidate will bring strong hands-on Splunk and IAM/PAM experience , along with a background in security monitoring or security operations.
Key Responsibilities
Design and implement monitoring logic for privileged access and identity-related security events.
Develop Splunk correlation searches, custom alert rules, and Risk-Based Alerting (RBA) logic.
Build filtering, suppression, enrichment, and alert-routing rules to improve alert fidelity.
Develop SOAR playbooks and workflows to automate incident handling and alert consolidation.
Integrate SIEM, SOAR, ticketing, and security operations processes.
Develop alert enrichment workflows incorporating user, asset, access, and threat context.
Build Splunk dashboards and reports to monitor alert volume, health, performance, and effectiveness.
Analyze historical data to validate alert accuracy and reduce false positives.
Test monitoring implementations against at least 60 days of historical datasets .
Optimize Splunk searches, data pipelines, field extractions, indexing, and search performance.
Document correlation searches, workflows, playbooks, dashboards, logic, edge cases, and procedures.
Develop operational runbooks and support documentation.
Partner with Security Operations and Security Engineering teams throughout implementation.
Provide knowledge transfer and training to operational teams before engagement completion.
Required Qualifications 4-5+ years of hands-on Splunk experience - must be clearly shown on resume .
4-5+ years of IAM experience - must be clearly shown on resume .
Previous security monitoring / security analyst experience is strongly preferred .
5+ years of experience in security operations, SIEM engineering, security engineering, or related cybersecurity functions.
Advanced experience developing Splunk correlation searches, alerts, dashboards, and reports .
Hands-on experience with Splunk Risk-Based Alerting (RBA) .
Strong knowledge of Splunk data pipelines, field extraction, indexing, search optimization, and alert tuning.
2+ years of hands-on SOAR experience such as Cortex XSOAR, Demisto, or comparable platforms.
Experience developing SOAR playbooks, workflows, automation logic, and incident-response processes.
Experience integrating SOAR with SIEM, ticketing, and security technologies.
2+ years of experience with Privileged Access Monitoring, IAM security, PAM, or related security monitoring use cases .
Understanding of privilege escalation detection, authorization frameworks, access controls, and IAM security.
Proven ability to reduce false positives and improve alert quality in high-volume environments.
Preferred Skills Experience with Cortex XSOAR / Demisto .
PAM solutions and privileged identity monitoring.
Advanced Splunk RBA implementations.
Security automation and alert enrichment.
Experience supporting financial services or other highly regulated environments.
Strong documentation, communication, and stakeholder-management skills.
What We're Looking For
We need a hands-on Splunk + IAM security professional , not simply a general Splunk administrator. The strongest candidates will have demonstrated experience building privileged-access monitoring use cases, tuning security alerts, developing RBA/correlation logic, and automating response through SOAR .
Top 6 Must-Have Skills
Splunk - 4-5+ years
IAM / Privileged Access Monitoring - 4-5+ years
Security Monitoring / SOC Analyst Experience
Splunk Correlation Searches & Risk-Based Alerting
SOAR / Playbook Development
Alert Tuning, Enrichment & False-Positive Reduction
Charlotte / Global
Charlotte / Global
Charlotte / Global
Charlotte / Global
Charlotte / Global
Charlotte / Global