Cybersecurity Specialist, Splunk Engineer

Posted 2 days ago

This is a fully remote position, open to applicants in Tennessee.

📋 Description

• Oversee, install, configure, and maintain Splunk cloud, on-premises, and various SIEM/log management tools.

• Create, audit, and enhance correlation rules while collaborating with ESOC to develop detections.

• Construct and uphold dashboards, reports, alerts, and visual representations.

• Generate and refine SPL queries and oversee knowledge objects management.

• Integrate and manage data sources such as syslog, HEC, forwarders, and APIs.

• Handle deployment servers and forwarders effectively.

• Ensure inputs, reporting, and alerting functions are maintained across Azure and AWS environments.

• Enhance system performance and suggest platform improvements.

• Create scripts and integrations utilizing Python, Bash, and PowerShell.

• Employ workflow automation tools with ServiceNow and other security/infrastructure platforms.

• Utilize regex for parsing, extraction, and automation tasks.

• Document data ingestion procedures and uphold access controls for compliance purposes.

• Establish configuration standards, policies, and procedures.

• Develop metrics to evaluate monitoring effectiveness.

• Address incidents and issues while incorporating changes through change-management processes.

• Train and guide ESOC personnel on SIEM functionalities and best practices.

• Collaborate with analysts and business stakeholders to ensure tools, dashboards, and applications fulfill requirements.

• Communicate effectively with teams and clients.

• Operate across Linux and Windows platforms.

• Leverage networking, workflow, and IT-reporting expertise.


⛳️ Requirements

• Bachelor’s Degree along with 5+ years of experience in cybersecurity operations or software analysis/programming, or a master’s degree with 3+ years of relevant experience.

• An additional 4 years of experience may be accepted as a substitute for a degree.

• Proven experience in administering and engineering Splunk.

• Required to obtain the Splunk Core Certified Admin certification within the first 3 months of employment.

• Must achieve the Azure AZ-900: Microsoft Azure Fundamentals certification within 6 months of employment.

• Must acquire the AWS Cloud Practitioner certification within 9 months of employment.

• Flexibility to work varied hours and be available for on-call duties during rotations.

• Must be a US Citizen.


🏝️ Benefits

• Flexible working hours.

• On-call availability during rotation periods.

People also viewed

EXL1 day ago

AVP, Cyber Application Security Architect

US flagNew Jersey OnlyFull-timeCybersecurity / Security Engineer$160k – $195.1k/year
ApplyView job
Reli Group2 days ago

Senior Cybersecurity Disaster Recovery, Contingency Planning SME

US flagMaryland OnlyFull-timeCybersecurity / Security Engineer$140k – $150k/year
ApplyView job
Second Nature2 days ago

Cloud Specialist – Security SSR

AR flagArgentina OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
ASRC Federal2 days ago

Information Security Engineer

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Kyndryl2 days ago

Lead, Application Consulting – Workday Security

US flagIllinois, +1 more stateFull-timeCybersecurity / Security Engineer$92k – $174.8k/year
ApplyView job
HomeServe USA2 days ago

Senior Cybersecurity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$114.5k – $167.9k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers