TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Splunk Engineer or CTI Gig?

1 点作者 igotroot超过 4 年前
Been spitballing my future career options and I&#x27;m curious on what someone else thinks.<p>I&#x27;m currently a SecOps Analyst, with the main focus being Splunk. We are a 95% on-prem enviroment so I deal with the watering&#x2F;feeding of Splunk from the forwardering tier to the dashboard creation. There&#x27;s some other security stuff thrown into my workflow but Splunk would be a big chunk of it.<p>I&#x27;ve been thinking about the next step career wise, and I&#x27;m stuck between two interests. I enjoy working with Splunk creating useful dashboards and overall dealing with data. A Splunk Engineer would be the logical progression from where I am now, but my concern lies on being a product guy. I&#x27;d for sure be working with other technologies (AWS, Azure, etc) at the next gig, but it&#x27;s still a concern.<p>Apart of my job is applying (not gathering) cyber threat intelligence. I enjoy reading all about CTI, the intelligence side, as well as the geopolitical landscape and how that could affect cyber threats. I&#x27;ve been planning out setting up a honey pot in the cloud, writing about it, going deeper with MITRE&#x2F;Kill Chain&#x2F;Diamond Model, and building my skill set that way.<p>Ideally I&#x27;d like to move to the DMV area and work for&#x2F;win the government since my area isn&#x27;t super techy. CTI jobs can be remote&#x2F;with the fed, and Splunk has a big presence in the public sector, so I&#x27;ve been going back and forth internally on what I&#x27;d like to focus on.<p>Any advice would be awesome, thanks!

1 comment

HelloNurse超过 4 年前
You seem divided between becoming more involved with security, continuing as a Splunk expert, and becoming a &quot;product guy&quot;.<p>Choosing between these and other career directions is mostly a matter of finding a specific good job in a specific good workplace.<p>My impression about Splunk (as a casual user who consults logs to debug application errors) is that if you are already managing data sources and creating dashboards you don&#x27;t have much left to learn about Splunk: the logical step forward, depending on how senior you are, is either (instead of wasting time with more Splunk) switching to something else to learn a lot about some other important product (not to mention different people, culture, projects etc. in another job) or climbing one step in the architecture ladder and becoming the engineer who plans Splunk deployments and chooses between it and competing and complementary products.
评论 #25093901 未加载