C

Senior Splunk Detection Engineer

cri advantage • United State
Relocation
Apply
AI Summary

Design, build, and tune detections to identify malicious activity across diverse data sources. Develop and maintain detection-as-code workflows with version control, testing, and CI/CD. Collaborate with threat intelligence, incident response, and SOC teams to translate emerging threats into actionable alerts.

Key Highlights
Expertise in Splunk SPL for detection content development
Experience with Splunk Enterprise Security and AI Toolkit
MITRE ATT&CK framework mapping and detection lifecycle management
Key Responsibilities
Design, develop, and maintain detection content using Splunk Search Processing Language (SPL) to identify threats across diverse data sources
Build and tune correlation searches, notable events, and risk-based alerting within Splunk Enterprise Security (ES)
Map detection coverage to the MITRE ATT&CK framework and identify gaps in visibility
Technical Skills Required
Splunk SPL Splunk Enterprise Security MITRE ATT&CK framework
Benefits & Perks
Relocation assistance available
Nice to Have
Detection-as-code practices and tools (Git, CI/CD pipelines)
Proficiency in Python for data processing and model development
Knowledge of SOAR platforms and detection automation
Relevant certifications (Splunk Certified Power User/Admin, Splunk Enterprise Security Certified Admin, GIAC)

Job Description


Description

In this role, the selected candidate will design, build, and tune detections that identify malicious activity across our environment, working at the intersection of security analysis, data engineering, and machine learning.

We are looking for a candidate who lives and breathes Splunk and gets excited about turning raw telemetry into high-fidelity alerts.

Responsibilities

  • Design, develop, and maintain detection content using Splunk Search Processing Language (SPL) to identify threats across diverse data sources.
  • Build and tune correlation searches, notable events, and risk-based alerting within Splunk Enterprise Security (ES).
  • Leverage the Splunk App for Data Science and Deep Learning (DSDL) to operationalize machine learning models for anomaly detection and advanced threat identification.
  • Apply the Splunk App for Anomaly Detection and the Splunk AI Toolkit (AITK) to develop statistical and ML-driven detections that go beyond signature-based approaches.
  • Map detection coverage to the MITRE ATT&CK framework and identify gaps in visibility.
  • Collaborate with threat intelligence, incident response, and SOC teams to translate emerging threats into actionable detections.
  • Reduce false positives and alert fatigue through continuous tuning and detection lifecycle management.
  • Develop and maintain detection-as-code workflows, including version control, testing, and CI/CD for detection content.
  • Create documentation, runbooks, and detection specifications to support downstream analysts.

Requirements

  • Be willing to relocate to Idaho Falls, Idaho. (Relocation assistance may be available)
  • Have a current "L" or "Q" clearance.
  • Have the following required skillsets:
  • Deep expertise in Splunk SPL, including advanced search commands, statistical functions, data models, and performance optimization.
  • Hands-on experience with Splunk Enterprise Security, including correlation searches, risk-based alerting (RBA), notable events, and the ES framework.
  • Working knowledge of the Splunk AI Toolkit (AITK) for building and applying ML-based detections.
  • Experience with the Splunk App for Data Science and Deep Learning (DSDL), including custom model development and deployment.
  • Strong understanding of the MITRE ATT&CK framework and detection engineering methodology.
  • Familiarity with common attack techniques, log sources, and security data (EDR, network, cloud, identity, etc.).

Preferred Qualifications

  • Experience with detection-as-code practices and tools (Git, CI/CD pipelines).
  • Proficiency in Python for data processing and model development.
  • Knowledge of SOAR platforms and detection automation.
  • Relevant certifications (Splunk Certified Power User/Admin, Splunk Enterprise Security Certified Admin, GIAC, etc.).
  • Prior experience in a SOC, threat hunting, or incident response role.

Similar Jobs

Explore other opportunities that match your interests

Recruiting Coordinator

Devops
•
2d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

rainmaker technology corporati...

United State

Senior Cloud Security Engineer

Devops
•
2d ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Mid-Senior level

Voto Consulting LLC

United State

Azure Engineer II/III

Devops
•
2d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

agwest farm credit

United State

Subscribe our newsletter

New Things Will Always Update Regularly