Lead Engineer, IT Security (SIEM/Splunk)
Core
Lead Splunk engineering, administration, and content development to support incident response, threat hunting, and cyber threat intelligence operations.
Role type
Senior IC Splunk Lead Engineer
Builds
Splunk Cloud environment, automated security analytics, and log ingestion pipelines
Domain
Financial services cybersecurity
Deliverable
production ML models | infrastructure | dashboards & analysis
Required skills
Splunk engineering, Splunk Cloud administration, Linux/Windows system administration, networking, Python/PowerShell/Bash scripting, API integration, Syslog-NG management
Preferred skills
Splunk Certified Architect, CISSP, CCNA
Technologies
Splunk Cloud, Syslog-NG, Linux, Windows, PowerShell, Python, Bash, Postman, Insomnia, Hopscotch, SOAR platforms
Responsibilities
Lead architecture and optimization of Splunk Cloud; manage platform health including clustering and performance tuning; develop and maintain Splunk content (dashboards, alerts, data models); lead automation initiatives for log onboarding and evidence collection; troubleshoot complex ingestion and search issues; support global Syslog-NG environment; participate in on-call rotation for major incidents
Seniority
Senior, hands-on IC with technical leadership