← Back to jobs
United States
No related jobs found
Key Responsibilities:
• Design, implement, and maintain Splunk Enterprise and Splunk Enterprise Security environments.
• Deploy, configure, and manage Cribl Stream for log routing, filtering, masking, enrichment, and optimization.
• Develop and maintain data onboarding pipelines from various security and infrastructure sources.
• Configure and troubleshoot log ingestion, parsing, normalization, CIM mapping, and data models.
• Optimize Splunk searches, dashboards, reports, and correlation searches for performance and scalability.
• Build and maintain detection use cases, alerts, and security monitoring content.
• Develop automation workflows using SOAR platforms such as Tines, Splunk SOAR, Cortex XSOAR, or similar automation tools.
• Integrate security tools including Microsoft Defender, CrowdStrike, Palo Alto, Zscaler, Okta, Azure, AWS, and other enterprise technologies.
• Perform troubleshooting of ingestion issues, parsing problems, search performance, and distributed architecture.
• Work closely with SOC analysts, security engineers, architects, and infrastructure teams.
• Implement best practices for platform monitoring, health checks, capacity planning, and upgrades.
• Create technical documentation, SOPs, and operational runbooks.
Required Skills
• 5+ years of hands-on experience with Splunk Enterprise.
• Strong experience administering and supporting Splunk Enterprise Security (ES).
• Hands-on experience with Cribl Stream administration and pipeline development.
• Strong understanding of log onboarding, parsing, field extraction, normalization, and CIM.
• Experience with Splunk Search Processing Language (SPL).
• Experience with index management, forwarders, deployment server, search heads, indexers, and clustered environments.
• Experience integrating cloud and security products with Splunk.
• Knowledge of Linux administration and troubleshooting.
• Experience with REST APIs and JSON.
• Scripting experience using Python, PowerShell, or Bash.
• Strong troubleshooting and analytical skills.
Preferred Skills
• Experience with security automation platforms such as Tines, Splunk SOAR, Cortex XSOAR, Swimlane, or Torq.
• Experience with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto, AWS, Azure, or GCP.
• Knowledge of MITRE ATT&CK framework.
• Familiarity with security operations and incident response workflows.
• Experience with Git, CI/CD, and Infrastructure as Code.
• Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Cribl Certified User/Admin, or security certifications such as CISSP or GIAC.
Nice to Have
• Experience designing enterprise SIEM architectures.
• Experience with threat detection engineering.
• Experience implementing SOC automation and orchestration workflows.
• Exposure to cloud-native security monitoring and observability platforms
Bachelor's degree
No related jobs found
← Back to jobs