City : Austin
State : Texas
Neos is Seeking a
Sr. Cybersecurity Engineer/Architect - Splunk for a contract role for with our client in Austin, TX.
***REMOTE- ONLY CANDIDATES CURRENTLY RESIDING IN THE U.S. WILL BE CONSIDERED***Position is 100% Remote, outside of Austin
The Office of Attorney General (OAG) is seeking a senior-level Splunk Security Architect / Cloud Security Engineer to support the Security Engineering Management Team by architecting, implementing, configuring, integrating, and maintaining enterprise security tools and services across a complex hybrid environment.
This role requires deep expertise in Splunk architecture, security engineering, cloud security (AWS + Azure), and automation, with a strong ability to design visibility and detection coverage so the organization can "see what it needs to see" across endpoints, identities, networks, cloud workloads, and SaaS platforms.
The ideal candidate has experience leveraging AI-driven security workflows and understands how to integrate Microsoft Copilot / AI capabilities into security operations and Splunk-driven use cases (automation, enrichment, detection engineering, reporting, proactive threat hunting).
Key ResponsibilitiesSplunk Architecture + SIEM Engineering:
- Architect, deploy, and optimize enterprise Splunk environments (Cloud or Enterprise) for performance, scalability, and reliability.
- Engineer and manage log onboarding, parsing, normalization, and indexing strategies to support security analytics and compliance reporting.
- Build and tune Splunk correlation searches, detection logic, dashboards, and alerting aligned to enterprise security objectives.
- Design Splunk visibility across cloud, endpoint, identity, network, and SaaS to ensure complete monitoring coverage.
Cloud Security (AWS + Azure) Integration:
- Integrate AWS security telemetry into Splunk (example sources: CloudTrail, GuardDuty, Security Hub, VPC Flow Logs).
- Integrate Azure security telemetry into Splunk (example sources: Azure AD logs, Defender telemetry, Activity Logs, NSG Flow Logs).
- Ensure cloud log integrity and coverage across accounts/subscriptions, regions, and environments.
- Support cloud security engineering controls and data pipelines to strengthen detection and response.
Security Tooling Implementation + Enterprise Integration:
- Perform hands-on deployment and integration of enterprise security solutions including:
- SIEM (Splunk)
- CASB
- DLP
- Endpoint Detection & Response (EDR)
- Additional security controls and monitoring platforms as needed
- Integrate security tooling into enterprise infrastructure, ensuring appropriate telemetry, controls, and alerting are in place.
- Troubleshoot complex security technology issues across hybrid systems and "multi-vendor" environments.
Automation, SOAR, AI + Copilot Enablement
- Design and implement automated workflows using Splunk-native or integrated tools (examples: Splunk SOAR, APIs, scripting, orchestration tools).
- Build automation for repetitive security operations (alert enrichment, triage workflows, ticketing integration, notifications, and response actions).
- Partner with security leadership to identify where AI + Copilot capabilities can enhance security engineering outcomes (faster investigation, better detection coverage, improved operational efficiency).
- Develop secure approaches to integrating AI workflows with Splunk and enterprise security tooling.
Required Qualifications- 8+ years of experience in security engineering, SIEM engineering, or security architecture.
- 8+ years of experience with Splunk (architecture, onboarding, search optimization, dashboards, correlation rules, alerts).
- 5+ years of experience of hands-on experience supporting environments across AWS and/or Azure.
- 5+ years of experience with Splunk ES (Enterprise Security) and security content development.
- 2+ years experience with Microsoft Copilot / AI-powered security workflows, including integrating AI into operational processes.
- Proven background implementing and integrating enterprise security tooling such as SIEM, CASB, EDR, and DLP.
- Experience troubleshooting complex issues across hybrid/heterogeneous enterprise infrastructures.
- Ability to design for full security visibility across enterprise systems (identity, endpoint, cloud, network, SaaS).
- Experience with Splunk SOAR and orchestration/automation use cases.
- Experience leveraging AI to improve security engineering functions (alert reduction, correlation improvements, investigation workflows).
- Cloud security certifications (preferred): AWS, Azure, security-focused credentials.
#DICE#LI-IC