Splunk Engineer (SIEM)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+5 more
Job description
This is a hands-on Splunk engineering role - not a SOC analyst or monitoring position. You will own the day-to-day engineering, administration, and health of a distributed Splunk environment (cloud and/or hybrid), build the detection and reporting content that the citywide Security Operations Center (SOC) relies on, and automate the operational work around it. You’ll work across the full engineering lifecycle - design, build, integrate, tune, and document - partnering with the SOC and internal security teams.
If you live in Splunk every day - search heads, indexers, forwarders, SPL, data onboarding, and Enterprise Security - this role is built for you.
WHAT YOU’LL DO
- Engineer and administer distributed Splunk - search head and indexer clusters, deployment server/deployer, license manager, and heavy/universal forwarder management across a cloud and/or hybrid deployment
- Onboard and normalize log sources (application, database, network, cloud, endpoint) - sourcetype tuning, field extractions, and CIM normalization via props/transforms
- Build detection and reporting content - advanced SPL, data models, tstats, correlation searches, dashboards, reports, and alerts for both technical and executive audiences
- Tune detections to cut false positives and sharpen fidelity; develop threat-detection and log-correlation use cases aligned to SOC requirements
- Automate operations with Python, PowerShell, and Bash - log-ingestion validation, reporting, and compliance checks; SOAR/playbook automation a plus
- Support incident investigations using Splunk log, endpoint, and network telemetry; contribute to incident response documentation and playbooks in coordination with the SOC
- Support endpoint security tooling (EDR/host-based monitoring), hardening and configuration validation, vulnerability-remediation tracking, patch validation, and audit evidence preparation (POA&M)
Requirements
5+ years hands-on Splunk Enterprise and/or Splunk Cloud administration and engineering - building and operating a distributed environment, not just searching it
- Demonstrated experience with indexer/search-head clustering, deployment server/forwarder management, and Splunk configuration (indexes, inputs, props, transforms)
- Strong data onboarding and normalization - getting messy log sources into Splunk, parsed and CIM-compliant
- Fluent in advanced SPL and building dashboards, correlation searches, and alerts
- Scripting/automation in Python, PowerShell, and/or Bash
- Working knowledge of incident response, log correlation, threat detection, IDS/IPS, and EDR/host-based security tools
- Able to work on-site in Lower Manhattan 3 days per week (hybrid)
PREFERRED
- Splunk Enterprise Certified Admin or Architect
- Splunk Enterprise Security (ES) content development experience
- Splunk SOAR / Phantom automation
- CISSP, CEH, GCIH, Security+, or equivalent
- Public sector / regulated-environment experience
About the company
OZ Solutions Group is a technology services company delivering IT and cybersecurity solutions to government and public sector clients across New York City. We are hiring one (1) Splunk Engineer (SIEM) to support a highly visible cybersecurity program for a large-scale public sector organization in Lower Manhattan.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DevOps Engineer Salary [2023]
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?