SIEM Engineer – Splunk & Splunk Cloud
Core
Engineer and support enterprise SIEM environments using Splunk Enterprise and Splunk Cloud, focusing on data ingestion, detection tuning, and platform reliability.
Role type
Senior IC SIEM Engineer (Splunk)
Builds
Production SIEM platforms, detection rules, and dashboards for SOC teams
Domain
Cybersecurity / Security Operations Center (SOC)
Deliverable
production ML models | product features | dashboards & analysis
Required skills
Splunk Enterprise, Splunk Cloud, SPL, SIEM architecture, log source onboarding, syslog, JSON, XML, regular expressions, Linux, Windows, cloud troubleshooting
Preferred skills
Google SecOps, YARA-L, Microsoft Sentinel, KQL, Sumo Logic, Microsoft Defender, Azure Security, AWS Security, Palo Alto, CrowdStrike, SOAR, automation scripting, Git, Infrastructure as Code
Technologies
Splunk, Microsoft 365, Azure, AWS, EDR, Microsoft Sentinel, Sumo Logic, Palo Alto, CrowdStrike
Responsibilities
Engineer and support Splunk Enterprise and Splunk Cloud; Manage indexers, search heads, forwarders, apps and add-ons; Onboard and troubleshoot security log sources; Develop and tune SPL searches, alerts and dashboards; Support SOC teams with detection and investigation requirements; Troubleshoot ingestion, search and platform performance issues; Integrate Microsoft 365, Azure, AWS, EDR and identity data
Seniority
Senior, hands-on IC