Unknown Company

Splunk Detection Engineer

Remote • Posted 2 days ago
Remote Full Time IT & Technology

Overview

Splunk Detection Engineer (Level IV or Strong Level III)

12+ months • Fully Remote

Scope: The Splunk Detection Engineer will play an important role in ensuring that security logs are appropriately formatted, ingested, tagged, and used to detect possible security events.

Typical tasks may include:

  • Integrate new data sources, which may include databases, APIs, files, etc. This may involve setting standards and working with IT administrators to update their configurations
  • Validating and creating appropriate configurations for CIM compliant logs
  • Processing requests from cybersecurity analysts for new detections within Splunk Enterprise Security
  • Analyzing existing logs to identify poorly formatted logs and potential gaps when implementing new detections
  • Adding and maintaining threat feeds within Splunk Enterprise Security
  • Monitoring the performance of and tuning detections
  • Managing asset and identity inventory within Splunk Enterprise Security
  • Creating and maintaining new Splunk apps
  • Recommending additions or changes to Splunk or its data models to meet detection needs
  • Developing searches, reports, and other functionalities for cyber-based use-cases, including active response, intrusion detection, vulnerability management, and related use cases

Responsibilities

  • Carry out activities to ensure proper formatting, ingestion, tagging, and utilization of security logs for detection of events
  • Collaborate with cybersecurity analysts and IT teams to implement detections and data models
  • Develop and maintain detections, searches, and dashboards in Splunk Enterprise Security
  • Drive continuous improvement of processes, data quality, and tooling related to Splunk
  • Provide guidance and knowledge transfer to team members on Splunk Enterprise Security usage

Qualifications

Minimum Qualifications:

  • Significant experience with Splunk and Splunk Enterprise Security
  • Significant experience with event logging solutions (e.g., Splunk Universal Forwarder, syslog, Cribl)
  • Experience with ticketing/case management
  • Experience with Git pipelines
  • Familiarity with using Linux CLI
  • Ability to craft queries using common languages; comfort with regex, JSON and APIs; basic scripting in Python/PowerShell/Bash
  • Excellent analytical, problem-solving, and communication skills both with stakeholders, peers, and internal customers; able to operate under pressure in a shift or on-call environment

Preferred Additional Qualifications:

  • Strong grasp of TCP/IP, OSI model, and common protocols (HTTP, DNS, SMTP). Windows/Linux/macOS fundamentals; Active Directory/Azure AD concepts; basic cloud logging
  • Experience in system and network administration
  • Relevant cybersecurity experience including investigations and data analysis
  • Experience with SOAR tools and automation development
  • Experience using identity security/management tools (e.g., Entra ID, Active Directory, Shibboleth, CrowdStrike Identity Protection)
  • Cloud security experience (e.g., CloudTrail/GuardDuty, Azure Defender/M365, GCP Security Command Center)

#J-18808-Ljbffr

Splunk Detection Engineer in Remote at Unknown Company

This position is listed as full time and able to be worked remotely.

Back to Job Search