Senior Splunk SIEM Engineer
Role details
Job location
Tech stack
Job description
The Senior Splunk Enterprise Security professional serves as a subject matter expert for designing, implementing, tuning, and maintaining Splunk Enterprise and Enterprise Security to support enterprise-level security monitoring, threat detection, and incident response. This role works closely with security engineering, SOC operations, threat intelligence, and IT infrastructure teams to enhance visibility, strengthen detection capabilities, and ensure the overall effectiveness of SIEM operations., * Architect and administer Splunk Enterprise Security in distributed environments
- Develop correlation searches, RBA models, dashboards, and detections
- Lead data onboarding, parsing, normalization, and CIM mapping
- Manage Splunk infrastructure including indexers, search heads, and forwarders
- Optimize performance, health, and scalability across clustered environments
- Support detection engineering aligned to MITRE ATT&CK and SOC operations
Requirements
- Strong SPL skills with dashboards, data models, and search optimization
- Expertise in data onboarding, CIM mapping, and props/transforms
- Solid understanding of SIEM operations, SOC workflows, and threat detection
- Experience with Splunk architecture, clustering, and configuration files
- Knowledge of Linux/Unix, networking fundamentals, and security tools
Education/Certifications: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience)
Experience: 5-10+ years of hands-on Splunk Enterprise and ES experience. 3+ years of related experience in SIEM engineering, cybersecurity monitoring, or security analytics
Clearance: Candidates must be able to obtain and/or maintain a Department of Defense Top Secret/SCI as a condition and continuation of employment (clearance sponsorship not offered at this time)
Technical Skills:
- Splunk certifications (Architect, Consultant, ES, Power User)
- Experience with Splunk SOAR for automation
- Knowledge of MITRE ATT&CK detection development
- Scripting skills in Python, Bash, or PowerShell
- Exposure to cloud logging (AWS, Azure, GCP)
- Experience supporting federal or regulated environments