Job Description
- 100% project-driven work aligned to two major transformation initiatives (no BAU)
- Support a CrowdStrike-led convergence project, migrating from Splunk to a next-gen SIEM
- Lead log-scale migrations, including deploying CrowdStrike agents across endpoints
- Partner closely with IT and data engineering to ensure full asset and log coverage
- Review SIEM indexes and log types to confirm proper parsing and ingestion
- Build, validate, and tune rules and detections across Splunk and the next-gen SIEM
- Perform data integrity and parity checks to ensure accuracy between environments
- Translate and migrate datasets between toolsets (e.g., Splunk → CrowdStrike)
- Act as a hands-on security engineering representative, bridging SOC, governance, and engineering teams
- Coordinate with vendors as needed to keep migration timelines moving
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Required Skills & Experience
- Strong experience with CrowdStrike and a next-gen SIEM 2-5 years experience
- Deep familiarity with Splunk (current SIEM “powerhouse”)
- Experience validating log parsing, ingestion, and data accuracy
- Exposure to vulnerability and security tooling such as: Checkmarx, Obsidian, Invicti, Tenable VM
- Some software development or automation experience, especially for integrations
- Python preferred, but language-agnostic is acceptable
- Prior involvement in a SIEM migration or major SIEM integration
- Experience moving data between platforms and environments (roughly 50% of the role)
- Ability to operate in a project-only environment with urgency and ownership
Nice to Have Skills & Experience
- Security certifications such as CCSE or CCSA
- Experience in banking, finance, or other large regulated enterprises
- Previous work in large-scale enterprise environments
- Broader industry experience beyond security (helpful for integrations)
- Proven success on multi-tool security transformations
- Background that shows strong ownership during periods of turnover or net-new project builds
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.