About the Role
Seeking a Senior Splunk Security Engineer with extensive experience in enterprise cybersecurity environments, focusing on Splunk, SIEM, threat detection, and incident response.
Responsibilities
- Administer and support Splunk Enterprise/Cloud environments, including Search Heads, Indexers, Deployers, Deployment Servers, Heavy/Universal Forwarders, and Splunk applications.
- Onboard and normalize application, database, network, cloud, and endpoint log sources.
- Develop and maintain Splunk dashboards, reports, alerts, searches, and threat detection use cases.
- Monitor security events, analyze logs, investigate incidents, and support SOC operations and incident response.
- Develop automation using PowerShell, Python, and Bash to improve operational efficiency, reporting, and security processes.
- Support endpoint security, including EDR, endpoint hardening, vulnerability remediation, patch validation, and compliance reporting.
- Monitor firewall and network security logs, support user access reviews, audits, security documentation, architecture diagrams, POAM tracking, and remediation validation.
Requirements
- 7+ years of experience with Splunk Enterprise and/or Splunk Cloud.
- Experience onboarding log sources and developing detection logic.
- Knowledge of enterprise logging, including application, web, database, security, and endpoint logs.
- Experience with PowerShell, Python, and Bash scripting.
- Experience with Endpoint Detection & Response (EDR) tools.
- Knowledge of incident response procedures.
- Understanding of log correlation and threat detection techniques.
- Experience with IDS/IPS and host-based security tools.
- Strong analytical, problem-solving, verbal, and written communication skills.
Skills
- Splunk Enterprise
- Splunk Cloud
- SIEM engineering
- Security operations
- Threat detection
- Scripting
- Automation
- Endpoint security
- Incident response
- PowerShell
- Python
- Bash
- EDR
- IDS/IPS
- Log correlation
Location
- Hybrid
Work Type
- Hybrid
- Full-time
Experience Level
- Senior
- 7+ years
Education Level
- Splunk Enterprise Certified Admin or Architect
- CISSP
- CEH
- GCIH
- Security+
