You will design, implement, and maintain core security monitoring and data processing solutions using the Splunk platform.
This role is remote.
Responsibilities
Build and update custom detection rules, integrating them with third-party tools in a Risk Based Alerting format.
Architect and implement specialized Splunk Enterprise Security (ES) solutions to generate actionable insights.
Design and build pre- and post-ticket automation workflows using Splunk SOAR.
Create executive and engineer dashboards to measure security detection readiness.
Conduct performance tuning and health checks on the Splunk environment to optimize search latency and resource utilization.
Required Skills
5+ years of progressive experience with the Splunk platform, including at least 1 year in dedicated detection engineering.
Proficiency in Python and Bash for deployment automation, configuration management, and API integration.
Hands-on experience deploying and managing Splunk across AWS, Azure, or GCP environments.
Technical depth with Splunk Deployment Servers, Data Collection Nodes, Intermediary Forwarders, DB Connect, and Universal Forwarders (Linux, Solaris, Windows, Mac).
Experience managing disparate source types within a large data ingestion pipeline.