CareerPlanSign in

Detection and Response Engineer (SPLUNK)

United States💼 Full-time🗓 2026-07-21 → 2026-09-26

Core

Develop, optimize, and maintain custom detection and threat-hunting queries across SIEM platforms to support proactive defense and alert tuning for client environments.

Role type

Mid-level IC detection and response engineer (SIEM)

Builds

Production detection rules, threat-hunting queries, dashboards, and updated runbooks for client security operations.

Domain

Cybersecurity / SIEM / Threat Intelligence

Deliverable

production ML models | product features | dashboards & analysis | client delivery

Required skills

SIEM query development, threat hunting, alert triage, incident investigation, MITRE ATT&CK mapping, detection gap analysis, runbook creation, cloud telemetry analysis, detection-as-code, NIST 800-53 compliance

Preferred skills

Professional services background, workflow automation (GitLab/GitHub/Terraform/Ansible), regulatory compliance frameworks (FedRAMP/FISMA/HIPAA)

Technologies

Splunk, Microsoft Sentinel, ELK, LogRhythm, Sumo Logic, Azure, AWS, GCP

Responsibilities

Collect and operationalize threat intelligence for proactive detection; develop and tune detection queries across multiple SIEMs; lead hypothesis-driven threat hunts; investigate and respond to security alerts; identify detection gaps and data quality issues; create dashboards and updated runbooks.

Seniority

Mid-level, hands-on IC

Sourced via lever · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.