Overview
Skills
Job Details
We are seeking an experienced Splunk Engineer with strong hands-on expertise in Splunk development and SIEM/SOAR platforms. The ideal candidate will work in large-scale, hybrid cloud environments to design, develop, and optimize security monitoring, analytics, automation, and reporting solutions while ensuring compliance with industry security frameworks.
Design, develop, and maintain Splunk dashboards, alerts, reports, and searches
Implement and support SIEM/SOAR solutions using Splunk and related platforms
Develop trending, metrics, and management reports for security and operations teams
Integrate Splunk with data lakes and data warehouses (AWS S3, Snowflake, Databricks)
Automate security and operational tasks using Python, Ansible, or PowerShell
Work with hybrid cloud environments (on-prem + AWS/Azure)
Apply security frameworks such as MITRE ATT&CK, CIS in monitoring and detection use cases
Troubleshoot complex issues related to data ingestion, performance, and searches
Collaborate with security, cloud, and infrastructure teams in large enterprise environments
Strong hands-on experience with Splunk development
5+ years experience with SIEM / SOAR platforms (Splunk, Elastic, Datadog, Cribl, etc.)
Experience with Splunk Search Processing Language (SPL) and Regex
Hands-on experience with AWS or Azure
Knowledge of Data Lake / Data Warehouse technologies (AWS S3, Snowflake, Databricks)
Strong scripting skills (Python, Ansible, PowerShell preferred)
Experience working in complex, large-scale enterprise environments
Solid understanding of networking fundamentals (TCP/IP)
Strong troubleshooting and analytical skills
Familiarity with MITRE ATT&CK Framework
Knowledge of CIS benchmarks and modern security principles
Experience in hybrid cloud security monitoring
Knowledge of automation and orchestration workflows
Exposure to DevSecOps practices