Splunk Engineer with Enterprise Security
Remote role
40 hours per week
Experience level - 8+ yrs.
This role requires technical Splunk expertise and security operations collaboration to ensure effective threat detection and response.
Splunk Enterprise Security Engineer
Role Overview
We are seeking an experienced Splunk Engineer specializing in Splunk Enterprise Security (ES) to administer, manage, and optimize our Splunk operations. The ideal candidate will be responsible for configuring, monitoring, and maintaining Splunk ES to support our security operations, working closely with Security Analysts to ensure effective threat detection and response.
Splunk Enterprise Security (ES) Configuration & Management
l Configure, customize, and maintain Splunk Enterprise Security to meet organizational security monitoring needs.
l Able to monitor and resolve data breachesand catch up the alerts
l Develop, tune, and monitor security alerts, correlation searches, and dashboards within Splunk ES.
l Implement and manage use cases, data models, and risk-based alerting frameworks.
Collaboration & Security Operations Support
l Work closely with Security Analysts to triage, investigate, and respond to security alerts generated by Splunk ES.
l Provide timely and accurate data from Splunk to support incident investigation and forensic analysis.
l Assist in developing and refining detection rules, reports, and visualizations to improve analyst efficiency.
Required Skills & Experience
l Proven experience as a Splunk security engineer with hands-on expertise in Splunk Enterprise Security.
l Strong ability to configure, run, and monitor alerts within Splunk ES.
l Experience working collaboratively with Security Analysts in a SOC or similar environment.
l Familiarity with security data sources, log formats, and SIEM integration.
Preferred Qualifications
l Splunk certifications (e.g., Splunk Certified Admin, Splunk Enterprise Security Certified Admin) are a plus
l Knowledge of security frameworks, compliance requirements, and threat intelligence integration.
l Scripting skills (Python, Bash, etc.) for automation and customization.
l Experience in large-scale or multi-site Splunk deployments.