Detection and Response Engineer (SPLUNK)
Core
Develop, optimize, and maintain custom detection and threat-hunting queries across SIEM platforms to support proactive defense and alert tuning for client environments.
Role type
Mid-level IC detection and response engineer (SIEM)
Builds
Production detection rules, threat-hunting queries, dashboards, and updated runbooks for client security operations.
Domain
Cybersecurity / SIEM / Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
SIEM query development, threat hunting, alert triage, incident investigation, MITRE ATT&CK mapping, detection gap analysis, runbook creation, cloud telemetry analysis, detection-as-code, NIST 800-53 compliance
Preferred skills
Professional services background, workflow automation (GitLab/GitHub/Terraform/Ansible), regulatory compliance frameworks (FedRAMP/FISMA/HIPAA)
Technologies
Splunk, Microsoft Sentinel, ELK, LogRhythm, Sumo Logic, Azure, AWS, GCP
Responsibilities
Collect and operationalize threat intelligence for proactive detection; develop and tune detection queries across multiple SIEMs; lead hypothesis-driven threat hunts; investigate and respond to security alerts; identify detection gaps and data quality issues; create dashboards and updated runbooks.
Seniority
Mid-level, hands-on IC