Splunk Engineer (Project Based)

Lintasarta

Jakarta Pusat

On-site

IDR 180,000,000 - 300,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Lintasarta in Jakarta, Indonesia is seeking a Splunk Security Analyst to join our 24/7/365 Security Operations Center. This on-site role focuses on real-time monitoring of security alerts across SIEM (Splunk), EDR, and cloud logs, with initial triage and escalation.

You will perform deep-dive investigations, tune Splunk searches, and coordinate with IT for remediation, while working a rotating shift schedule.

Qualifications

  • Experience in monitoring and triaging security events in a SOC and IT/NOC settings.
  • Familiarity with Splunk SPL and building dashboards; knowledge of MITRE ATT&CK mapping.
  • Hands-on exposure to EDR/XDR tools and basic containment actions.
  • Understanding of Windows and Linux logs and core networking fundamentals.

Responsibilities

  • Real-time monitoring, triage, and escalation of security events across SIEM, EDR, and cloud logs.
  • Differentiate threats from false positives using playbooks and document incidents with IOAs.
  • Conduct deep-dive investigations, trace attack paths, and perform containment actions.
  • Tune Splunk searches and collaborate with IT/Infrastructure for remediation.

Skills

Splunk
EDR/XDR
Networking
MITRE ATT&CK

Education

Bachelor's degree

Tools

Splunk
CrowdStrike Falcon
Microsoft Defender for Endpoint
Cortex XDR

Job description

About This Job

Lintasarta

Location: Jakarta, Indonesia

Work Mode: On-site

Industry: Technology, Information and Media, IT Services and IT Consulting

Job Description

We are Hiring: Splunk Security Analyst (SOC Hybrid Tier 1/2)

Are you a vigilant cyber defender who knows how to navigate Splunk like the back of your hand? We are looking for a Splunk Security Analyst to join our fast-paced, 24/7/365 Security Operations Center (SOC) team!

In this hybrid role, you will be our frontline defender and core investigator. You will be responsible for real-time security alert monitoring and initial triage, while also taking ownership of escalated alerts to perform deep-dive technical investigations, confirm malicious intent, and drive active containment strategies using the Splunk platform.

Key Responsibilities
  • Real-Time Monitoring, Triage & Escalation
  • Continuously monitor security alerts generated across enterprise SIEM (Splunk), EDR, and cloud logging solutions to identify potential malicious activities.
  • Review and triage security events to accurately differentiate between true security threats and false positives based on established playbooks.
  • Document highly detailed, clear, and comprehensive incident tickets logging the timeline, systems involved, and Indicators of Compromise (IoCs).
  • Execute thorough shift handovers to ensure uninterrupted 24/7/365 operational coverage.
  • Deep-Dive Investigation & Response
  • Investigate complex security alerts by correlating multi-source logs within Splunk, tracing attack paths from initial access to execution.
  • Perform basic static and dynamic triage of suspicious files, scripts, and registry modifications.
  • Execute authorized containment actions during live incidents, including isolating hosts via EDR, revoking compromised credentials, or blocking malicious IPs.
  • Partner with IT and Infrastructure teams to provide technical remediation advice (e.g., patching, configuration changes) following a security event.
  • Review response playbooks and tune Splunk search logic to continually reduce future false positives.
Job Requirements & Qualifications
Experience & Shift Availability
  • Total Security Experience: Minimum of 2–4 years of dedicated experience working inside a Security Operations Center (SOC) or in an IT Support/Network Operations (NOC) role with a strong security focus.
  • Track Record: Proven ability to manage, document, and contain mid-to-high severity security incidents.
  • Shift Flexibility: Full availability and willingness to work in a rotating 24/7/365 shift schedule (including nights, weekends, and holidays).
Technical Skills & Splunk Expertise
  • Splunk Mastery: Strong hands-on experience navigating, querying, and building custom dashboards within Splunk using Search Processing Language (SPL).
  • EDR/XDR Capabilities: Experience running device checks, tracking process trees, and executing remote containment via tools like CrowdStrike Falcon, Microsoft Defender for Endpoint, or Cortex XDR.
  • Infrastructure & Networking: Solid grasp of core networking fundamentals (TCP/IP, DNS, DHCP, routing) and ability to inspect system logs across Windows and Linux environments.
  • Framework Awareness: Practical knowledge of mapping malicious activity patterns directly against the MITRE ATT&CK matrix.
Preferred Certifications & Education
  • Education: Bachelor’s degree in Computer Science, Cyber Security, IT, or equivalent practical experience.
  • Certifications (Highly Prioritized): Holds or is pursuing intermediate designations such as:Splunk Core Certified Power User / Splunk Enterprise Security Certified AdminCompTIA Security+ or Cybersecurity Analyst (CySA+)GIAC Certified Incident Handler (GCIH)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

On-site Splunk SOC Analyst — Real-Time Defender
On-site Splunk SOC Analyst — Real-Time Defender

Lintasarta • Jakarta Pusat

On-site
IDR 180,000,000 - 300,000,000
Security Engineer - SIEM & Splunk Specialist
Security Engineer - SIEM & Splunk Specialist

PT ITSEC Asia Tbk • Jakarta Pusat

On-site
IDR 180,000,000 - 420,000,000
SOC L1 Analyst - Cybersecurity Technology Consulting
SOC L1 Analyst - Cybersecurity Technology Consulting

Ernst & Young Advisory Services Sdn Bhd • Daerah Khusus Ibukota Jakarta

On-site
IDR 12,000,000 - 15,000,000
Senior Splunk & SIEM Engineer – Security Monitoring Lead
Senior Splunk & SIEM Engineer – Security Monitoring Lead

PT ITSEC Asia Tbk • Jakarta Pusat

On-site
Sr. Security Engineer
Sr. Security Engineer

PT ITSEC Asia Tbk • Jakarta Pusat

On-site
SOC L2 Analyst - Cybersecurity Technology Consulting
SOC L2 Analyst - Cybersecurity Technology Consulting

Ernst & Young Advisory Services Sdn Bhd • Daerah Khusus Ibukota Jakarta

On-site
IDR 180,000,000 - 240,000,000
Splunk Engineer
Splunk Engineer

Esha Parama Technology • Jakarta Pusat

Hybrid
IDR 279,000,000 - 502,200,000
IT CYBERSECURITY
IT CYBERSECURITY

PT Dharma Satya Nusantara Tbk • Indonesia

On-site
IDR 300,000,000 - 550,000,000
SOC Analyst (Level 2)
SOC Analyst (Level 2)

Eternaindonesia • Jakarta Pusat

On-site
IDR 200,880,000 - 334,800,000
Private insurance including medical & dental
Paid Time Off (PTO) according to Indonesian law
E-cash allowance for work-related expenses
+3
Cybersecurity Operations Centre (Jakarta)
Cybersecurity Operations Centre (Jakarta)

Meratus Group • Jakarta Pusat

On-site
IDR 240,000,000 - 360,000,000