> Markdown version of [/jobs/ext/2589283-splunk-enterprise-security-certified-administrator](https://www.wearedevelopers.com/jobs/ext/2589283-splunk-enterprise-security-certified-administrator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Splunk Enterprise Security Certified Administrator - **Company:** Coalfire Systems, Inc. - **Location:** United States - **Salary:** $80,000.0 - $134,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Github, Ansible, Security Information and Event Management, Cloud Platform System, Mitre Att&ck, Gitlab, Microsoft Sentinel, Sumo Logic (Software), Terraform, Splunk - **Published:** August 31, 2026 - **Apply:** https://jobs.military.com/career/324576/detection-response-engineer-splunk-illinois-il-chicago ## About the Role * 24 years of experience operating within largescale enterprise security environments, including exposure to cloudhosted or hybrid infrastructures. \n * Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations. \n * Handson experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment. \n * Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds. \n * Proven ability to independently investigate and respond to security alerts, performing deepdive analysis across multiple log sources to determine scope, root cause, and impact. \n * Experience escalating confirmed or highconfidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers. \n * Experience conducting structured and cyclical threathunting activities using hypothesisdriven and behaviorbased methodologies. \n * Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts. \n * Handson experience developing, optimizing, and maintaining custom detection and threathunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic. \n * Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs. \n * Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly. \n * Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials. \n * Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor. \n * Critical thinking skills to balance robust security requirements against mission objectives. \n * Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments. \n * Experience utilizing a Detection-as-Code framework \n * Experience working with NIST 800-53 environments \n, * Professional services background: Prior experience supporting external clients from within a consulting or professional services organization. \n * Automation capabilities: Experience automating workflows in GitLab or GitHub with Terraform and Ansible. \n * Compliance frameworks: Understanding of FedRAMP, FISMA, HIPAA, HITRUST, PCI, and similar regulatory standards. \n ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)