Security Engineer - SIEM (Splunk) Platform & Operations
Core
Frontline detective monitoring and correlating real-time threat data from firewalls, cloud assets, EDR, and AI-driven platforms to identify potential threats and deliver rapid, high-fidelity alerts.
Role type
Security Engineer (SIEM Operations & Detection)
Builds
Splunk Enterprise Security dashboards, detection rules, correlation searches, and incident response playbooks
Domain
Cybersecurity / SIEM Operations / Threat Detection
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Splunk Enterprise Security (ES) administration, Splunk log ingestion and data normalization, SPL query development, detection engineering, correlation rule development, incident response workflows, threat analysis, log source validation, root cause identification, proactive threat hunting
Preferred skills
Splunk Enterprise Security Certified Admin, Darktrace, CrowdStrike, Netskope, AWS, Azure
Technologies
Splunk, Darktrace, CrowdStrike, Netskope, AWS, Azure, Windows, Linux, Firewalls, EDR, CASB
Responsibilities
Monitor and analyze security event logs from multiple sources to identify potential threats; Triage and investigate alerts within the Splunk SIEM platform; Tune and optimize correlation searches, detection rules, and dashboards to reduce false positives; Conduct proactive threat hunting using SIEM, EDR, and network detection tools; Perform initial analysis of security events and assist with root cause identification; Create and maintain documentation for log flows, detection use cases, and operational standards
Seniority
Mid-level, hands-on IC