> Markdown version of [/jobs/ext/2271791-splunk-engineer](https://www.wearedevelopers.com/jobs/ext/2271791-splunk-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Splunk Engineer - **Company:** United Global Technologies - **Location:** United States (Remote available) - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Continuous Integration, Information Engineering, Intrusion Detection and Prevention, Python (Programming Language), Machine Learning, Performance Tuning, Runbook, Data Processing, Mitre Att&ck, Deep Learning, Git, Cybercrime, Splunk, Software Version Control - **Published:** August 27, 2026 - **Apply:** https://www.dice.com/job-detail/58d6f534-2041-4864-9879-46413b5bb2ab ## About the Role Qualifying individual must have a current "L" or "Q" clearance OR Top Secret 100% REMOTE 3. Qualifying individual "MUST" have the following skillsets: · Deep expertise in Splunk SPL, including advanced search commands, statistical functions, data models, and performance optimization · Hands-on experience with Splunk Enterprise Security, including correlation searches, risk-based alerting (RBA), notable events, and the ES framework · Working knowledge of the Splunk AI Toolkit (AITK) for building and applying ML-based detections · Experience with the Splunk App for Data Science and Deep Learning (DSDL), including custom model development and deployment · Strong understanding of the MITRE ATT&CK framework and detection engineering methodology · Familiarity with common attack techniques, log sources, and security data (EDR, network, cloud, identity, etc.) 4. Qualifying individual "NICE" to have the following skillsets: · Experience with detection-as-code practices and tools (Git, CI/CD pipelines) · Proficiency in Python for data processing and model development · Knowledge of SOAR platforms and detection automation · Relevant certifications (Splunk Certified Power User/Admin, Splunk Enterprise Security Certified Admin, GIAC, etc.) · Prior experience in a SOC, threat hunting, or incident response role In this role, the selected candidate will design, build, and tune detections that identify malicious activity across our environment, working at the intersection of security analysis, data engineering, and machine learning. We're looking for a candidate that lives and breathes Splunk and gets excited about turning raw telemetry into high-fidelity alerts, we want to hear from you. ## Description · Design, develop, and maintain detection content using Splunk Search Processing Language (SPL) to identify threats across diverse data sources · Build and tune correlation searches, notable events, and risk-based alerting within Splunk Enterprise Security (ES) · Leverage the Splunk App for Data Science and Deep Learning (DSDL) to develop machine learning models for anomaly detection and advanced threat identification · Apply the Splunk App for Anomaly Detection and the Splunk AI Toolkit (AITK) to develop statistical and ML-driven detections that go beyond signature-based approaches · Map detection coverage to the MITRE ATT&CK framework and identify gaps in visibility · Collaborate with threat intelligence, incident response, and SOC teams to translate emerging threats into actionable detections · Reduce false positives and alert fatigue through continuous tuning and detection lifecycle management · Develop and maintain detection-as-code workflows, including version control, testing, and CI/CD for detection content · Create documentation, runbooks, and detection specifications to support downstream analysts ## Related Videos - [Designing UX for SRE Agents in High-Stakes Incidents](https://www.wearedevelopers.com/videos/100003-designing-ux-for-sre-agents-in-high-stakes-incidents) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [The AI Security Survival Guide: Practical Advice for Stressed-Out Developers](https://www.wearedevelopers.com/videos/1015-the-ai-security-survival-guide-practical-advice-for-stressed-out-developers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 166: Sycophancy, Zip bombs and AI Native Development](https://www.wearedevelopers.com/magazine/585-dev-digest-166-sycophancy-zip-bombs-and-ai-native-development)