SPLUNK ES DETECTION ENGINEER / SPLUNK CLOUD SME

Remote • Posted 12 hours ago • Updated 12 hours ago
Full Time
No Travel Required
Remote
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • CompTIA
  • Cloud Architecture
  • Change Management
  • Capacity Management
  • Security Operations
  • SPL

Summary

Position Summary

The Splunk ES Detection Engineer / Splunk Cloud SME carries two connected responsibilities on ACI's Splunk platform management program: the standing detection engineering function for the Security Operations Center, and ownership of the Splunk Cloud platform architecture. Working with minimal supervision, this individual builds and tunes the detections the SOC runs on, designs the program's risk-based alerting framework, and keeps the Splunk Cloud environment available, current, and sized for the agency's data growth.

 

Key Responsibilities

·      Create and maintain event-based and finding-based detections in Splunk Enterprise Security, with quick turnaround as new SOC requirements arise.

·      Design and operate the risk-based alerting framework, including risk thresholds and adaptive risk scoring.

·      Deliver and maintain a fully documented ES detection library, including the logic, data dependencies, and tuning history behind every detection.

·      Maintain asset and identity lookups, Active Directory and identity system integration for real-time user and asset data, and ES KV Store lookups and data enrichment standards.

·      Manage threat intelligence lookup files and feeds, and review feed effectiveness on a recurring cycle.

·      Build and maintain detection tracking dashboards and produce the weekly notable event trend report.

·      Tune detections on a regular cycle to reduce false positives without losing detection sensitivity.

·      Own Splunk Cloud architecture and availability across the hybrid environment, including software updates and configuration changes under change management.

·      Design, maintain, and test disaster recovery, backup, and business continuity procedures for the Splunk environment.

·      Perform capacity planning and resource utilization management as agency data volumes grow.

 

Demonstrated Hands-On Experience (Evaluation Emphasis)

The selected individual must demonstrate hands-on experience building detections in Splunk Enterprise Security and administering Splunk Cloud in a production environment. The candidate shall clearly describe direct technical experience authoring correlation searches and finding-based detections in SPL, implementing risk-based alerting, normalizing data sources to the Common Information Model, and administering Splunk Cloud, including the environments supported, data volumes handled, and operational outcomes achieved. Experience limited primarily to SOC monitoring, alert triage, or consuming dashboards and detections built by others, without substantial detection authoring and platform administration responsibilities, will be viewed as less competitive.

 

Required Qualifications

·      Minimum of six years of hands-on Splunk experience, including detection engineering in Splunk Enterprise Security and Splunk Cloud administration. Demonstrated hands-on experience is mandatory and may not be substituted.

·      Demonstrated proficiency in SPL, CIM data models and data normalization, risk-based alerting, asset and identity framework management, and threat intelligence integration.

·      Splunk Cloud Certified Admin (or Splunk Enterprise Certified Admin with substantial Splunk Cloud experience) is required for this position. Splunk Enterprise Security Certified Admin is strongly preferred.

·      Additional relevant certifications are preferred where practicable, such as Splunk Core Certified Power User, GIAC GCDA, or CompTIA CySA+.

 

Clearance and Work Conditions

·      Place of performance: Remote work, based within United States.

·      Schedule: standard business hours, Monday through Friday, excluding Federal holidays.

·      Successfully complete an Government background investigation

·      Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.

  • Dice Id: 10229270
  • Position Id: 9098424
  • Posted 12 hours ago
Contact the job poster
CC

Colleen Crowder

Director of Human Resources @ ACI Solutions
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

•

Today

Easy Apply

Contract

$60 - $65

Remote

•

Yesterday

Easy Apply

Contract, Third Party

Depends on Experience

Remote or Juno Beach, Florida

•

Today

Contract

$70 - $80 hourly

Remote

•

Today

Easy Apply

Full-time

Depends on Experience

Search all similar jobs