Security Platform Engineer

Noblesoft Technologies
Raleigh, NC, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Cyber Security Continuous Integration Distributed Systems Intrusion Detection and Prevention JSON Python (Programming Language) Parsing
+20 more
Windows PowerShell Zero Trust Network Access Security Information and Event Management Systems Integration Scripting Google Cloud Enterprise Software Applications Okta Data Ingestion Mitre Att&ck Software Troubleshooting Git Infrastructure Automation Frameworks Palo Alto Networks Microsoft Sentinel Cortex XSOAR Platform Restful APIs Splunk Data Pipelines Security Orchestration, Automation & Response

Job description

We are seeking an experienced Security Platform Engineer with strong expertise in Splunk Enterprise/Enterprise Security, Cribl Stream, and Security Automation platforms. The ideal candidate will be responsible for designing, implementing, optimizing, and supporting enterprise-scale SIEM and log management platforms while enabling automation across SOC operations., * Design, implement, and maintain Splunk Enterprise and Splunk Enterprise Security environments.

  • Deploy, configure, and manage Cribl Stream for log routing, filtering, masking, enrichment, and optimization.
  • Develop and maintain data onboarding pipelines from various security and infrastructure sources.
  • Configure and troubleshoot log ingestion, parsing, normalization, CIM mapping, and data models.
  • Optimize Splunk searches, dashboards, reports, and correlation searches for performance and scalability.
  • Build and maintain detection use cases, alerts, and security monitoring content.
  • Develop automation workflows using SOAR platforms such as Tines, Splunk SOAR, Cortex XSOAR, or similar automation tools.
  • Integrate security tools including Microsoft Defender, CrowdStrike, Palo Alto, Zscaler, Okta, Azure, AWS, and other enterprise technologies.
  • Perform troubleshooting of ingestion issues, parsing problems, search performance, and distributed architecture.
  • Work closely with SOC analysts, security engineers, architects, and infrastructure teams.
  • Implement best practices for platform monitoring, health checks, capacity planning, and upgrades.
  • Create technical documentation, SOPs, and operational runbooks.

Requirements

  • 5+ years of hands-on experience with Splunk Enterprise.
  • Strong experience administering and supporting Splunk Enterprise Security (ES).
  • Hands-on experience with Cribl Stream administration and pipeline development.
  • Strong understanding of log onboarding, parsing, field extraction, normalization, and CIM.
  • Experience with Splunk Search Processing Language (SPL).
  • Experience with index management, forwarders, deployment server, search heads, indexers, and clustered environments.
  • Experience integrating cloud and security products with Splunk.
  • Knowledge of Linux administration and troubleshooting.
  • Experience with REST APIs and JSON.
  • Scripting experience using Python, PowerShell, or Bash.
  • Strong troubleshooting and analytical skills.

Preferred Skills

  • Experience with security automation platforms such as Tines, Splunk SOAR, Cortex XSOAR, Swimlane, or Torq.
  • Experience with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto, AWS, Azure, or Google Cloud Platform.
  • Knowledge of MITRE ATT&CK framework.
  • Familiarity with security operations and incident response workflows.
  • Experience with Git, CI/CD, and Infrastructure as Code.
  • Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Cribl Certified User/Admin, or security certifications such as CISSP or GIAC.

Nice to Have

  • Experience designing enterprise SIEM architectures.
  • Experience with threat detection engineering.
  • Experience implementing SOC automation and orchestration workflows.
  • Exposure to cloud-native security monitoring and observability platforms.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · WWC 2025

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

Videos

See all

Related articles

See all