Splunk Engineer (SIEM)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+5 more
Job description
This is a hands-on Splunk engineering role - not a SOC analyst or monitoring position. You will own the day-to-day engineering, administration, and health of a distributed Splunk environment (cloud and/or hybrid), build the detection and reporting content that the citywide Security Operations Center (SOC) relies on, and automate the operational work around it. You’ll work across the full engineering lifecycle - design, build, integrate, tune, and document - partnering with the SOC and internal security teams.
If you live in Splunk every day - search heads, indexers, forwarders, SPL, data onboarding, and Enterprise Security - this role is built for you.
WHAT YOU’LL DO
- Engineer and administer distributed Splunk - search head and indexer clusters, deployment server/deployer, license manager, and heavy/universal forwarder management across a cloud and/or hybrid deployment
- Onboard and normalize log sources (application, database, network, cloud, endpoint) - sourcetype tuning, field extractions, and CIM normalization via props/transforms
- Build detection and reporting content - advanced SPL, data models, tstats, correlation searches, dashboards, reports, and alerts for both technical and executive audiences
- Tune detections to cut false positives and sharpen fidelity; develop threat-detection and log-correlation use cases aligned to SOC requirements
- Automate operations with Python, PowerShell, and Bash - log-ingestion validation, reporting, and compliance checks; SOAR/playbook automation a plus
- Support incident investigations using Splunk log, endpoint, and network telemetry; contribute to incident response documentation and playbooks in coordination with the SOC
- Support endpoint security tooling (EDR/host-based monitoring), hardening and configuration validation, vulnerability-remediation tracking, patch validation, and audit evidence preparation (POA&M)
Requirements
5+ years hands-on Splunk Enterprise and/or Splunk Cloud administration and engineering - building and operating a distributed environment, not just searching it
- Demonstrated experience with indexer/search-head clustering, deployment server/forwarder management, and Splunk configuration (indexes, inputs, props, transforms)
- Strong data onboarding and normalization - getting messy log sources into Splunk, parsed and CIM-compliant
- Fluent in advanced SPL and building dashboards, correlation searches, and alerts
- Scripting/automation in Python, PowerShell, and/or Bash
- Working knowledge of incident response, log correlation, threat detection, IDS/IPS, and EDR/host-based security tools
- Able to work on-site in Lower Manhattan 3 days per week (hybrid)
PREFERRED
- Splunk Enterprise Certified Admin or Architect
- Splunk Enterprise Security (ES) content development experience
- Splunk SOAR / Phantom automation
- CISSP, CEH, GCIH, Security+, or equivalent
- Public sector / regulated-environment experience
About the company
OZ Solutions Group is a technology services company delivering IT and cybersecurity solutions to government and public sector clients across New York City. We are hiring one (1) Splunk Engineer (SIEM) to support a highly visible cybersecurity program for a large-scale public sector organization in Lower Manhattan.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DevOps Engineer Salary [2023]
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
Software Engineer Salary London