> Markdown version of [/jobs/ext/1714574-splunk-engineer-siem](https://www.wearedevelopers.com/jobs/ext/1714574-splunk-engineer-siem). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Splunk Engineer (SIEM) - **Company:** Oz Solutions Group Inc. - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $65,000.0 - $150,000.0 - **Contract:** Temporary contract - **Skills:** Bash Shell, Cloud Computing, CompTIA Security+, Cyber Security, Databases, Distributed Computing Environment, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Parsing, Windows PowerShell, Security Information and Event Management, Scripting, Data Ingestion, Indexer, Splunk, Plan of Action and Milestones - **Published:** July 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=dd6edfb5cce71d1f ## About the Role 5+ years hands-on Splunk Enterprise and/or Splunk Cloud administration and engineering - building and operating a distributed environment, not just searching it - Demonstrated experience with indexer/search-head clustering, deployment server/forwarder management, and Splunk configuration (indexes, inputs, props, transforms) - Strong data onboarding and normalization - getting messy log sources into Splunk, parsed and CIM-compliant - Fluent in advanced SPL and building dashboards, correlation searches, and alerts - Scripting/automation in Python, PowerShell, and/or Bash - Working knowledge of incident response, log correlation, threat detection, IDS/IPS, and EDR/host-based security tools - Able to work on-site in Lower Manhattan 3 days per week (hybrid) PREFERRED - Splunk Enterprise Certified Admin or Architect - Splunk Enterprise Security (ES) content development experience - Splunk SOAR / Phantom automation - CISSP, CEH, GCIH, Security+, or equivalent - Public sector / regulated-environment experience ## Description This is a hands-on Splunk engineering role - not a SOC analyst or monitoring position. You will own the day-to-day engineering, administration, and health of a distributed Splunk environment (cloud and/or hybrid), build the detection and reporting content that the citywide Security Operations Center (SOC) relies on, and automate the operational work around it. You'll work across the full engineering lifecycle - design, build, integrate, tune, and document - partnering with the SOC and internal security teams. If you live in Splunk every day - search heads, indexers, forwarders, SPL, data onboarding, and Enterprise Security - this role is built for you. WHAT YOU'LL DO - Engineer and administer distributed Splunk - search head and indexer clusters, deployment server/deployer, license manager, and heavy/universal forwarder management across a cloud and/or hybrid deployment - Onboard and normalize log sources (application, database, network, cloud, endpoint) - sourcetype tuning, field extractions, and CIM normalization via props/transforms - Build detection and reporting content - advanced SPL, data models, tstats, correlation searches, dashboards, reports, and alerts for both technical and executive audiences - Tune detections to cut false positives and sharpen fidelity; develop threat-detection and log-correlation use cases aligned to SOC requirements - Automate operations with Python, PowerShell, and Bash - log-ingestion validation, reporting, and compliance checks; SOAR/playbook automation a plus - Support incident investigations using Splunk log, endpoint, and network telemetry; contribute to incident response documentation and playbooks in coordination with the SOC - Support endpoint security tooling (EDR/host-based monitoring), hardening and configuration validation, vulnerability-remediation tracking, patch validation, and audit evidence preparation (POA&M) ## Related Videos - [Optimizing Discovery: PostgreSQL's Role in Transforming GetYourGuide's Search](https://www.wearedevelopers.com/videos/1647-optimizing-discovery-postgresql-s-role-in-transforming-getyourguide-s-search) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Building a Compiler with C#](https://www.wearedevelopers.com/videos/116-building-a-compiler-with-c) - [Dynamic Entities in .NET: Building Low-Code Systems on Top of Entity Framework Core](https://www.wearedevelopers.com/videos/100218-dynamic-entities-in-net-building-low-code-systems-on-top-of-entity-framework-core) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)