Security Engineer (Splunk & Automation)

Zachary Piper
Durham, NC, United States
10 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$124,800.0 - $137,280.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Cyber Security Data Integrity Intrusion Detection and Prevention Python (Programming Language) Security Information and Event Management Systems Integration Scripting Cyber Threat Analysis SC Clearance Restful APIs Splunk
+2 more
Api Management Security Orchestration, Automation & Response

Job description

Piper Companies is seeking a Security Engineer (Splunk & Automation) to join a leading cybersecurity team supporting enterprise security operations. The Security Engineer will serve as a key technical resource responsible for Splunk development, security tool integrations, automation, and threat intelligence workflows that strengthen detection, investigation, and response capabilities. This role is ideal for candidates who have progressed from a SOC Analyst background into Security Engineering and enjoy building solutions that connect tools, data, and processes across the security ecosystem. This is a fully on-site position in Durham, North Carolina form 8-5 PM EST that is a long term contract that has high likelihood for extension and conversion., * Design, develop, and maintain integrations between Splunk, threat intelligence platforms, case management tools, and other security technologies.

  • Build and support security automation solutions that improve SOC efficiency and accelerate incident response activities.
  • Develop and maintain Splunk searches, alerts, dashboards, reports, data models, and custom applications.
  • Integrate and operationalize threat intelligence feeds, enrichment workflows, and intelligence-sharing processes.
  • Create Python-based automation to streamline security monitoring, investigations, and remediation efforts.
  • Design and implement data quality and telemetry validation processes to ensure accurate and reliable security visibility.
  • Collaborate with SOC analysts, threat intelligence teams, detection engineers, and platform owners to improve workflows and reduce manual effort.
  • Perform data integrity monitoring and create alerts to identify gaps that could impact threat detection, compliance reporting, or incident response efforts.
  • Support security platform interoperability through API integrations and custom engineering solutions., Keywords: Security Engineer, Splunk Engineer, Security Automation Engineer, Security Operations Engineer, Detection Engineer, Cybersecurity Engineer, Splunk Enterprise, SPL, Python, Threat Intelligence, OpenCTI, TheHive, SIEM, SOAR, Security Integrations, Incident Response, Detection Engineering, Security Analytics, API Integration, Security Monitoring, Secret Clearance.

Requirements

  • Active Secret Clearance required.
  • 3+ years of experience in Security Engineering, Splunk Engineering, Security Automation, Detection Engineering, or a related cybersecurity role.
  • Strong hands-on experience with Splunk Enterprise, including SPL, dashboards, alerts, saved searches, and reporting.
  • Experience integrating security tools and platforms into Splunk environments.
  • Strong Python scripting and automation experience.
  • Understanding of SOC operations, incident response, threat detection, and security monitoring workflows.
  • Experience leveraging APIs to integrate security technologies and workflows.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent communication skills and ability to work cross-functionally with technical and non-technical stakeholders., * Previous experience as a SOC Analyst who transitioned into Security Engineering or Security Operations Engineering.
  • Experience with OpenCTI, TheHive, SOAR platforms, or other threat intelligence and case management solutions.
  • Experience managing threat intelligence feeds and enrichment workflows.
  • Knowledge of detection engineering and security operations best practices.
  • Experience supporting enterprise cybersecurity environments.
  • Familiarity with data integrity monitoring, telemetry validation, and security analytics.

Technical Environment:

  • Splunk Enterprise
  • SPL
  • Python
  • OpenCTI
  • TheHive
  • Security Automation & SOAR
  • REST APIs
  • Threat Intelligence Platforms
  • Detection Engineering
  • Incident Response
  • Security Analytics
  • Data Quality & Telemetry Validation

Benefits & conditions

  • $60-$66/hour (flexible for the right candidate)
  • Medical, Dental, Vision, PTO, Holidays, and Sick Leave Required by Law

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all