You will design, implement, and maintain core security monitoring and data processing solutions using Splunk.
Responsibilities
Build and update custom detection rules, integrating detections with third-party tools, specifically within a Risk Based Alerting format.
Architect and implement specialized Splunk solutions, focusing on Splunk Enterprise Security (ES) to generate actionable insights.
Design and build workflows for pre and post ticket automation using Splunk SOAR and related tools.
Create executive and engineer dashboards to measure security detection readiness.
Conduct performance tuning and health checks on the Splunk environment, optimizing search latency and resource utilization.
Required Skills
5+ years of progressive experience with the Splunk platform, including at least 1 year in dedicated detection engineering.
Proficiency in Python and Bash for deployment automation, configuration management, and API integration.
Hands-on experience deploying and managing Splunk across AWS, Azure, or GCP environments.
Technical depth with Splunk Deployment Servers, Data Collection Nodes, Intermediary Forwarders, DB Connect, and Universal Forwarders (Linux, Solaris, Windows, Mac).
Experience managing disparate source types within a large data ingestion pipeline.