> Markdown version of [/jobs/ext/1646197-security-analytics-engineer](https://www.wearedevelopers.com/jobs/ext/1646197-security-analytics-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analytics Engineer - **Company:** Amazon.com, Inc. - **Location:** Chantilly, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $100,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Business Analytics Applications, Cloud Computing Security, Cyber Security, Information Engineering, Data Transformation, Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Information Systems Security Architecture Professional, Python (Programming Language), Network Security, Machine Learning, Parsing, Performance Tuning, Windows PowerShell, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Scripting, In-Plane Switching (IPS), Data Ingestion, System Availability, Software Security, Mitre Att&ck, Cyber Threat Analysis, Indexer, Information Technology, Cybercrime, Data Management, Splunk, Data Pipelines, Security Orchestration, Automation & Response, Servicenow - **Published:** July 5, 2026 - **Apply:** https://www.careerjet.com/job/us84d4aa88afdec6ce350ea6b7ae3b4e35/eaa ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field. * 5+ years of experience designing and supporting enterprise security analytics platforms. * Extensive hands-on experience administering and engineering: * Splunk Enterprise Security (ES) * Splunk SOAR * Splunk UEBA * Splunk Enterprise * Extensive experience designing and managing CRIBL pipelines for enterprise log management and security telemetry. * Experience developing detection content, correlation searches, dashboards, and security analytics. * Strong understanding of SIEM architecture, log management, telemetry normalization, and security data engineering. * Experience integrating enterprise security technologies including EDR, IDS/IPS, cloud security, identity platforms, vulnerability management, and network security tools. * Experience with scripting or automation using Python, PowerShell, or similar languages. * Strong understanding of MITRE ATT&CK, detection engineering methodologies, and Security Operations Center workflows. * Excellent analytical and troubleshooting skills., * Splunk Enterprise Certified Architect * Splunk Enterprise Certified Admin * Splunk Core Certified Power User * CRIBL Certified Administrator or equivalent experience * CISSP (Certified Information Systems Security Professional) * GIAC Certified Enterprise Defender (GCED) * Experience supporting federal government cybersecurity programs. * Experience supporting custom security analytics platforms, including proprietary Security Fusion Center analytics solutions. * Experience with ServiceNow Security Incident Response (SIR) integrations and workflows. Knowledge, Skills, and Abilities * Expert knowledge of Splunk Enterprise Security architecture, engineering, and optimization. * Deep understanding of CRIBL data engineering, log routing, parsing, enrichment, and telemetry optimization. * Ability to design scalable enterprise security analytics architectures supporting large and complex environments. * Strong understanding of detection engineering, threat analytics, and adversary behavior. * Ability to engineer integrations between enterprise security platforms and automate operational workflows. * Experience evaluating emerging security technologies and recommending enterprise adoption strategies. * Excellent collaboration skills with Security Operations, Threat Intelligence, Threat Hunting, Incident Response, and Security Engineering teams. * Ability to translate operational requirements into scalable, maintainable security engineering solutions. ## Description The Security Analytics Engineer is responsible for engineering, optimizing, and sustaining the enterprise security analytics platform that supports the organization's Security Fusion Center (SFC). This role designs, implements, and maintains security monitoring capabilities by developing advanced detection analytics, optimizing security telemetry, integrating enterprise security tools, and enabling automation across the cybersecurity ecosystem. The ideal candidate is an expert in Splunk Enterprise Security and the broader Splunk platform, with extensive experience implementing and managing CRIBL data pipelines, security analytics, detection engineering, and enterprise log management. This individual partners with Threat Intelligence, Threat Hunting, Incident Response, and Security Operations teams to ensure security technologies provide timely, high-fidelity detection of evolving adversary tactics, techniques, and procedures (TTPs)., Security Analytics Engineering * Design, develop, and maintain enterprise security analytics supporting the Security Fusion Center. * Develop advanced detection logic, correlation searches, dashboards, reports, and alerts to identify emerging cyber threats. * Continuously improve detection capabilities by developing analytics aligned with current adversary tactics, techniques, and procedures (TTPs). * Engineer scalable solutions that improve security visibility, operational efficiency, and threat detection effectiveness. Splunk Platform Engineering * Administer, configure, and optimize Splunk Enterprise Security (ES), Splunk User and Entity Behavior Analytics (UEBA), and Splunk Security Orchestration, Automation, and Response (SOAR). * Develop and maintain Splunk searches, correlation rules, risk-based alerting, dashboards, and knowledge objects. * Optimize data ingestion, indexing, data models, and search performance across large enterprise environments. * Support lifecycle management, upgrades, performance tuning, and operational maintenance of the Splunk platform. CRIBL & Security Data Pipeline Engineering * Design, implement, and maintain CRIBL pipelines to efficiently collect, normalize, enrich, filter, and route enterprise security telemetry. * Optimize log ingestion and data transformation processes to improve analytics quality while reducing storage and licensing costs. * Develop parsing, enrichment, and routing logic supporting enterprise detection engineering. * Integrate data from cloud, endpoint, network, identity, and application security platforms into the Security Fusion Center analytics environment. Detection Engineering & Security Tool Integration * Develop and maintain detection analytics supporting proactive identification of advanced cyber threats. * Evaluate emerging security technologies and recommend enhancements aligned with enterprise cybersecurity strategy. * Support integration of enterprise security platforms, including SIEM, SOAR, EDR, identity security, vulnerability management, and cloud security tools. * Collaborate with Threat Hunting and Threat Intelligence teams to operationalize new detections based on emerging threats. Security Platform Operations * Operate, maintain, and continuously improve the Security Fusion Center Analytics Platform (SFCAP). * Support engineering efforts for enterprise security analytics platforms, including custom and commercial solutions. * Maintain an inventory of enterprise security tools and document system capabilities, integrations, and operational dependencies. * Support platform reliability, availability, scalability, and security. Automation & AI * Implement AI-enabled analytics and automation capabilities to improve ingestion, normalization, enrichment, correlation, and analysis of security telemetry. * Identify opportunities to automate repetitive engineering and operational tasks. * Research emerging technologies supporting security analytics, machine learning, and operational efficiency. * Assist in evaluating AI-enabled security operations capabilities and recommending implementation strategies. ServiceNow Security Integration * Develop security use cases supporting enterprise adoption of ServiceNow Security Incident Response (SIR). * Design and document integrations between ServiceNow and enterprise security platforms. * Collaborate with operational teams to improve incident workflows through automation and orchestration. ## Related Videos - [Optimizing Discovery: PostgreSQL's Role in Transforming GetYourGuide's Search](https://www.wearedevelopers.com/videos/1647-optimizing-discovery-postgresql-s-role-in-transforming-getyourguide-s-search) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Dynamic Entities in .NET: Building Low-Code Systems on Top of Entity Framework Core](https://www.wearedevelopers.com/videos/100218-dynamic-entities-in-net-building-low-code-systems-on-top-of-entity-framework-core) - [Building a Compiler with C#](https://www.wearedevelopers.com/videos/116-building-a-compiler-with-c) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production)