Security Engineer - Siem (Splunk) Platform & Operations Organization

Samsung
San Jose, CA, United States
11 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cloud Computing Cyber Security Data Normalization Internet Security Intrusion Detection and Prevention Intrusion Detection Systems Security Information and Event Management Software Engineering Cloud Platform System Cyber Threat Analysis Firewalls (Computer Science)
+2 more
Splunk Network Server

Job description

As Security Engineer, you’ll join the Cybersecurity Operations team, where you’ll serve as the frontline detective monitoring and correlating real-time threat data from firewalls, cloud assets, EDR, and AI-driven platforms like Darktrace. You’ll design, tune, and optimize Splunk Enterprise Security dashboards, detection rules, and correlation searches to cut false positives while delivering rapid, high-fidelity alerts. Leveraging your experience SOC environments, you’ll lead deep incident investigations, spearhead proactive threat-hunting missions, and drive remediation priorities based on risk and business impact. Collaboration is key: you’ll partner with global engineers, cloud specialists, and incident-response teams to continuously improve our security posture and document best-practice playbooks., * Monitor and analyze security event logs from multiple sources, including firewalls, intrusion detection/prevention systems, endpoint protection platforms, servers, cloud environments, and tools like Darktrace, to identify potential threats.

  • Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise Security (ES) platform.
  • Assist in improving SIEM processes, detection coverage, alert fidelity, and operational workflows including creating dashboards
  • Support the onboarding and integration of logs from enterprise systems into the Splunk environment.
  • Validate log source completeness, data normalization, rule logic, and alert relevance across critical systems and infrastructure
  • Perform initial analysis of security events, escalate incidents when appropriate, and assist with root cause identification.
  • Conduct in-depth investigations of security incidents and recommend remediation and containment actions.
  • Conduct proactive threat hunting using SIEM, EDR, CASB, and network detection tools, such as Darktrace, to identify suspicious activity that may have bypassed traditional controls.
  • Tune and optimize correlation searches, detection rules, dashboards, and use cases to improve operational efficiency and reduce false positives.
  • Prioritize remediation efforts based on risk, severity, and business impact.
  • Participate in incident response activities and support threat hunting initiatives as needed.
  • Collaborate with cross-functional teams to respond effectively to cybersecurity incidents and strengthen overall security posture.
  • Create and maintain documentation for log flows, detection use cases, triage procedures, playbooks, cybersecurity processes, and operational standards.

Requirements

Artificial Intelligence (AI), Best Practices, Cloud Computing, Computer Security, Continuous Improvement, Cross-Functional, Documentation, Endpoint Security, Enterprise Protection, Establish Priorities, Firewalls, Hunting, Incident Response, Internet Security, Intrusion Detection Systems, Intrusion Detection and Prevention (IDP), Onboarding, Operational Improvement, Operational Strategy, Operations Processes, Process Improvement, Reporting Dashboards, Risk, Root Cause Analysis, Search Engine Optimization (SEO), Security Analysis, Security Attacks, Security Information and Event Management (SIEM), Security Monitoring, Service Delivery, Software Engineering, Splunk, Technical Support, Use Cases

About the company

Samsung SDS America (SDSA) serves as the U.S. technology and innovation hub for Samsung’s global enterprise solutions, delivering secure, scalable, and high-performance IT services that support some of the world’s most complex business environments. As SDSA continues to expand its cloud, mobility, analytics, and cybersecurity capabilities, maintaining a resilient security operations foundation is essential to protecting the company’s digital assets and ensuring uninterrupted service delivery.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:27 min

Binding executable logic into network servers

Saoussen Chaabnia Saoussen Chaabnia · Europe 2026 Virtual

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all