> Markdown version of [/jobs/ext/1903628-security-engineer-siem-splunk-platform-operations-organization](https://www.wearedevelopers.com/jobs/ext/1903628-security-engineer-siem-splunk-platform-operations-organization). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - Siem (Splunk) Platform & Operations Organization - **Company:** Samsung - **Location:** San Jose, CA, United States - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing, Cyber Security, Data Normalization, Internet Security, Intrusion Detection and Prevention, Intrusion Detection Systems, Security Information and Event Management, Software Engineering, Cloud Platform System, Cyber Threat Analysis, Firewalls (Computer Science), Splunk, Network Server - **Published:** July 31, 2026 - **Apply:** https://www.careerbuilder.com/job-details/security-engineer-siem-splunk-platform-operations-san-jose-ca--cb7d72a3-0cf1-4b3a-a5d1-f90d282c6826 ## About the Role Artificial Intelligence (AI), Best Practices, Cloud Computing, Computer Security, Continuous Improvement, Cross-Functional, Documentation, Endpoint Security, Enterprise Protection, Establish Priorities, Firewalls, Hunting, Incident Response, Internet Security, Intrusion Detection Systems, Intrusion Detection and Prevention (IDP), Onboarding, Operational Improvement, Operational Strategy, Operations Processes, Process Improvement, Reporting Dashboards, Risk, Root Cause Analysis, Search Engine Optimization (SEO), Security Analysis, Security Attacks, Security Information and Event Management (SIEM), Security Monitoring, Service Delivery, Software Engineering, Splunk, Technical Support, Use Cases ## Description As Security Engineer, you'll join the Cybersecurity Operations team, where you'll serve as the frontline detective monitoring and correlating real-time threat data from firewalls, cloud assets, EDR, and AI-driven platforms like Darktrace. You'll design, tune, and optimize Splunk Enterprise Security dashboards, detection rules, and correlation searches to cut false positives while delivering rapid, high-fidelity alerts. Leveraging your experience SOC environments, you'll lead deep incident investigations, spearhead proactive threat-hunting missions, and drive remediation priorities based on risk and business impact. Collaboration is key: you'll partner with global engineers, cloud specialists, and incident-response teams to continuously improve our security posture and document best-practice playbooks., * Monitor and analyze security event logs from multiple sources, including firewalls, intrusion detection/prevention systems, endpoint protection platforms, servers, cloud environments, and tools like Darktrace, to identify potential threats. * Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise Security (ES) platform. * Assist in improving SIEM processes, detection coverage, alert fidelity, and operational workflows including creating dashboards * Support the onboarding and integration of logs from enterprise systems into the Splunk environment. * Validate log source completeness, data normalization, rule logic, and alert relevance across critical systems and infrastructure * Perform initial analysis of security events, escalate incidents when appropriate, and assist with root cause identification. * Conduct in-depth investigations of security incidents and recommend remediation and containment actions. * Conduct proactive threat hunting using SIEM, EDR, CASB, and network detection tools, such as Darktrace, to identify suspicious activity that may have bypassed traditional controls. * Tune and optimize correlation searches, detection rules, dashboards, and use cases to improve operational efficiency and reduce false positives. * Prioritize remediation efforts based on risk, severity, and business impact. * Participate in incident response activities and support threat hunting initiatives as needed. * Collaborate with cross-functional teams to respond effectively to cybersecurity incidents and strengthen overall security posture. * Create and maintain documentation for log flows, detection use cases, triage procedures, playbooks, cybersecurity processes, and operational standards. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data)