Role: Splunk SIEM Engineer
Location - San Jose, CA
Role Summary: Client is seeking a SIEM Migration & Implementation Lead to drive the implementation and migration to a modern SaaS-based SIEM platform, including log onboarding, detection engineering, operational readiness, and SOC transition.
Key Responsibilities
· Lead Splunk SIEM implementation and migration activities.
· Design log collection, parsing, normalisation, and correlation architectures.
· Migrate log sources, detections, dashboards, reports, and integrations.
· Develop detection content, correlation rules, dashboards, and security analytics.
· Write complex SIEM queries for investigations, detections, reporting, and threat hunting.
· Onboard endpoint, firewall, DNS, identity, cloud, DLP, proxy, email, and application logs.
· Support testing, cutover, go-live, and operational transition activities.
Required Experience
· 8–10 years of experience in SIEM Engineering, Security Monitoring, Detection Engineering, or Security Operations.
· Proven experience leading enterprise SIEM migrations or greenfield deployments.
· Strong hands-on experience with one or more SIEM platforms.
· Strong expertise in SIEM query writing, dashboard development, correlation rule creation, and detection engineering.
· Experience integrating and onboarding diverse enterprise security telemetry sources.
· Strong scripting and automation experience (Python, PowerShell, APIs).
· Strong understanding of MITRE ATT&CK and threat detection methodologies.
Success Criteria
· Successful migration of log sources, detections, dashboards, and reporting.
· Improved security visibility and detection coverage.
· Smooth transition into steady-state SOC operations.
· Splunk Experience is Must