Splunk / SOC Engineer

Zachary Piper
United States
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$100,000.0 - $120,000.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Cloud Computing Security Cyber Security Data Normalization Intrusion Detection and Prevention Parsing Security Information and Event Management Systems Integration Data Ingestion Splunk

Job description

is seeking a highly skilled to support the development and optimization of enterprise security monitoring and analytics within a fast-paced environment. This role plays a critical part in enhancing detection capabilities, improving security visibility, and driving operational efficiency through Splunk engineering and automation. This is a full-time opportunity working closely with SOC analysts, cloud teams, and engineering stakeholders hybrid .

· Developing, maintaining, and optimizing Splunk Security detections, dashboards, and correlation searches.

· Onboarding, parsing, normalizing, and enriching diverse security data sources into Splunk.

· Troubleshooting ingestion pipelines, forwarder connectivity, indexing issues, and search performance challenges.

· Assisting with configuration, maintenance, and troubleshooting across distributed Splunk environments.

· Leveraging data models and accelerated searches to improve detection performance and reporting efficiency.

· Collaborating with SOC analysts and engineering teams to enhance threat detection, visibility, and response workflows.

· Participating in incident response activities, including deep-dive investigations into security alerts.

Requirements

· Minimum of 5+ years of experience in SIEM engineering, security operations, or incident response environments.

· Strong proficiency with Splunk, including writing complex SPL queries and building production-grade dashboards.

· Hands-on experience with data normalization, ingestion, and troubleshooting within Splunk Enterprise or Splunk ES.

· Experience integrating and onboarding security data sources into a centralized SIEM platform.

· Familiarity with integrating tools such as AWS Security Hub or similar cloud-native security services.

· Strong understanding of Splunk knowledge objects, field extractions, lookups, and CIM normalization.

· Ability to perform effectively in high-pressure incident response situations and a willingness to participate in on-call rotations.

Benefits & conditions

· Salary range: $100,000 - $120,000

· Comprehensive benefits package including Medical, Dental, Vision, 401k, PTO, holidays, and sick leave as required by law.

Keywords: Splunk Enterprise, Splunk Enterprise Security (ES), Splunk SOAR, SIEM Engineering, Security Information and Event Management, SIEM, SPL, Search Processing Language, Correlation Searches, detection engineering, security analytics, Data ingestion, data onboarding, data normalization, CIM, log parsing, field extractions, pipeline troubleshooting, Security operations center, SOC, incident response, threat detection, alert investigation, AWS, AWS security, AWS security hub, Azure security, Entra ID, Azure AD, distributed splunk environment, forwarders

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:56 min

Open-sourcing a complex parsing library for game data

Johan Hutting Johan Hutting · WWC 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all