Security Platform Engineer
Noblesoft Technologies
Raleigh, NC, United States
3 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source
Tech stack
Amazon Web Services
Microsoft Azure
Bash Shell
Cloud Computing
Cloud Computing Security
Cyber Security
Continuous Integration
Distributed Systems
Intrusion Detection and Prevention
JSON
Python (Programming Language)
Parsing
+20 more
Windows PowerShell
Zero Trust Network Access
Security Information and Event Management
Systems Integration
Scripting
Google Cloud
Enterprise Software Applications
Okta
Data Ingestion
Mitre Att&ck
Software Troubleshooting
Git
Infrastructure Automation Frameworks
Palo Alto Networks
Microsoft Sentinel
Cortex XSOAR Platform
Restful APIs
Splunk
Data Pipelines
Security Orchestration, Automation & Response
Job description
We are seeking an experienced Security Platform Engineer with strong expertise in Splunk Enterprise/Enterprise Security, Cribl Stream, and Security Automation platforms. The ideal candidate will be responsible for designing, implementing, optimizing, and supporting enterprise-scale SIEM and log management platforms while enabling automation across SOC operations., * Design, implement, and maintain Splunk Enterprise and Splunk Enterprise Security environments.
- Deploy, configure, and manage Cribl Stream for log routing, filtering, masking, enrichment, and optimization.
- Develop and maintain data onboarding pipelines from various security and infrastructure sources.
- Configure and troubleshoot log ingestion, parsing, normalization, CIM mapping, and data models.
- Optimize Splunk searches, dashboards, reports, and correlation searches for performance and scalability.
- Build and maintain detection use cases, alerts, and security monitoring content.
- Develop automation workflows using SOAR platforms such as Tines, Splunk SOAR, Cortex XSOAR, or similar automation tools.
- Integrate security tools including Microsoft Defender, CrowdStrike, Palo Alto, Zscaler, Okta, Azure, AWS, and other enterprise technologies.
- Perform troubleshooting of ingestion issues, parsing problems, search performance, and distributed architecture.
- Work closely with SOC analysts, security engineers, architects, and infrastructure teams.
- Implement best practices for platform monitoring, health checks, capacity planning, and upgrades.
- Create technical documentation, SOPs, and operational runbooks.
Requirements
- 5+ years of hands-on experience with Splunk Enterprise.
- Strong experience administering and supporting Splunk Enterprise Security (ES).
- Hands-on experience with Cribl Stream administration and pipeline development.
- Strong understanding of log onboarding, parsing, field extraction, normalization, and CIM.
- Experience with Splunk Search Processing Language (SPL).
- Experience with index management, forwarders, deployment server, search heads, indexers, and clustered environments.
- Experience integrating cloud and security products with Splunk.
- Knowledge of Linux administration and troubleshooting.
- Experience with REST APIs and JSON.
- Scripting experience using Python, PowerShell, or Bash.
- Strong troubleshooting and analytical skills.
Preferred Skills
- Experience with security automation platforms such as Tines, Splunk SOAR, Cortex XSOAR, Swimlane, or Torq.
- Experience with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto, AWS, Azure, or Google Cloud Platform.
- Knowledge of MITRE ATT&CK framework.
- Familiarity with security operations and incident response workflows.
- Experience with Git, CI/CD, and Infrastructure as Code.
- Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Cribl Certified User/Admin, or security certifications such as CISSP or GIAC.
Nice to Have
- Experience designing enterprise SIEM architectures.
- Experience with threat detection engineering.
- Experience implementing SOC automation and orchestration workflows.
- Exposure to cloud-native security monitoring and observability platforms.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
5 months ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
EM
Eli McGarvie
Highest Paying Tech Companies for Developers
over 3 years ago
DC
Daniel Cranney
The Overflow: 5 Security and Privacy Tools for Developers
4 months ago