Splunk Enterprise Security Expert

Jobgether

India

On-site

INR 2,500,000 - 4,000,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Partner Company in India seeks a seasoned Splunk Enterprise Security Expert to govern enterprise Splunk content, define CIM normalization standards, and architect scalable data models. You will drive lifecycle management of knowledge objects, promote content through CI/CD via GitOps, and collaborate across cloud, security ops, and compliance teams.

You will enable detection engineers and SOC teams by delivering scalable, well-documented, and maintainable Splunk solutions, with focus on

Qualifications

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field, or equivalent experience.
  • 8+ years hands-on Splunk experience in enterprise environments.
  • 3+ years direct experience in Splunk knowledge management, CIM normalization, SIEM content engineering, or large-scale Splunk environments.
  • Experience with large-scale Splunk deployments, ideally handling 20+ TB of data per day.
  • Deep expertise in Splunk Enterprise Security and related components.
  • Advanced proficiency in SPL and related commands.
  • Strong understanding of Splunk data models, acceleration strategies, and ES dependencies.
  • Experience with Splunk knowledge objects lifecycle and content packaging.

Responsibilities

  • Provide centralized governance and lifecycle management for Splunk knowledge objects and data models.
  • Establish enterprise naming conventions, taxonomy, ownership models, and lifecycle processes for Splunk content.
  • Audit knowledge object libraries to consolidate or retire content.
  • Develop automation to monitor data ingestion, normalization, and data flow consistency.
  • Lead knowledge object promotion through development to production using CI/CD/GitOps.
  • Collaborate with platform teams on permission structures and sharing models.
  • Design and maintain CIM mappings across data sources and MITRE ATT&CK mappings.
  • Create reusable templates for searches, dashboards, reports, lookups, and macros.

Skills

Splunk ES
SPL
CIM normalization
Data models
Knowledge objects
GitOps
Python
Bash
Linux/Windows

Education

Bachelor's degree in CS/IS

Tools

Python
Bash
GitHub Actions
Deployment Server

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Splunk Enterprise Security Expert based in India.

This role offers the opportunity to shape enterprise‑wide Splunk governance and security content architecture at significant scale.
You’ll serve as a technical authority across Splunk Enterprise, Enterprise Security, CIM normalization, data models, and knowledge object lifecycle management.
Your work will help security teams improve detection quality, search performance, governance, and operational consistency across complex environments.
You’ll establish standards, automate processes, and ensure security content moves reliably from development through testing and production.
The role combines hands‑on engineering with architecture, documentation, cross‑functional collaboration, and governance leadership.
You’ll work across cloud, infrastructure, security operations, compliance, and detection engineering teams to create scalable and maintainable solutions.
This is an ideal opportunity for a seasoned Splunk professional who enjoys solving complex platform challenges and establishing enterprise‑level technical standards.

Accountabilities
  • Provide centralized governance and lifecycle management for Splunk knowledge objects, including saved searches, correlation searches, field extractions, tags, aliases, event types, lookups, macros, data models, workflow actions, and KV Store collections.
  • Establish and enforce enterprise‑wide naming conventions, taxonomy standards, ownership models, permissions, and lifecycle processes for Splunk content.
  • Audit knowledge object libraries to identify duplicate, orphaned, deprecated, or conflicting content and drive consolidation or retirement where appropriate.
  • Develop automation to monitor data ingestion, data flow consistency, normalization drift, and other critical aspects of the Splunk environment.
  • Maintain an enterprise knowledge object registry documenting ownership, scope, purpose, permissions, and lifecycle stage.
  • Collaborate with platform teams to define appropriate permission structures and sharing models across applications, environments, and user groups.
  • Lead the promotion of knowledge objects through development, testing, staging, and production using change control, CI/CD, and GitOps practices.
  • Serve as the enterprise authority for Splunk Common Information Model (CIM) normalization and maintain compliant field mappings across endpoint, network, identity, cloud, and application data sources.
  • Design, build, and maintain Splunk data models supporting Pivot users, Enterprise Security correlation searches, reporting, and risk‑based analytics.
  • Manage data model acceleration strategies, including TSIDX, tstats, and summary indexing, while monitoring search load, acceleration performance, and coverage.
  • Define and enforce source‑type and index taxonomy standards to improve search performance, configuration consistency, and usability across teams.
  • Ensure asset zones, network zones, identity tiers, and other entity enrichment are incorporated into data models and Enterprise Security frameworks.
  • Maintain CIM coverage matrices connecting data model fields with MITRE ATT&CK techniques, detection use cases, and compliance controls.
  • Own the enterprise Splunk knowledge architecture, including taxonomy hierarchies, content standards, metadata schemas, and classification frameworks.
  • Develop and maintain knowledge management standards covering naming conventions, lifecycle stages, ownership, permissions, CIM mappings, and change control procedures.
  • Lead a cross‑functional knowledge governance working group involving detection engineering, SOC operations, platform engineering, compliance, and application teams.
  • Create reusable templates for correlation searches, dashboards, reports, lookups, and macros to accelerate development while maintaining governance standards.
  • Design and implement automation using Python, Bash, GitHub Actions, and related tooling to improve knowledge object management and deployment.
  • Maintain clear technical documentation, including architecture documentation, standards guides, runbooks, and operational procedures.
  • Support detection engineering, threat hunting, and SOC teams by ensuring Splunk content is reliable, discoverable, performant, and aligned with operational needs.
Requirements
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.
  • 8+ years of hands‑on Splunk experience in enterprise environments.
  • At least 3 years of direct experience in Splunk knowledge management, CIM normalization, SIEM content engineering, or comparable large‑scale Splunk environments.
  • Experience working with large‑scale Splunk deployments, ideally handling 20+ TB of data per day.
  • Deep expertise in Splunk Enterprise Security, including correlation searches, notable events, risk‑based alerting, ES data models, threat intelligence, and asset and identity frameworks.
  • Advanced proficiency in SPL, including complex statistical pipelines, tstats, macros, sub-searches, evaluation functions, and streaming and non‑streaming commands.
  • Strong understanding of Splunk data models, acceleration strategies, Pivot functionality, and Enterprise Security dependencies.
  • Comprehensive knowledge of Splunk knowledge objects and their full lifecycle, including field extractions, lookups, KV Store collections, macros, tags, aliases, event types, workflow actions, saved searches, and correlation searches.
  • Deep administrative and engineering experience with distributed, multi‑site, and clustered Splunk Enterprise environments.
  • Experience developing or reviewing Splunk Technology Add-ons and applications, including packaging and deployment through Deployment Server and Deployer.
  • Strong understanding of Splunk configuration management, including configuration files, btool, precedence rules, and the Splunk Admin Config Service.
  • Experience with Splunk Edge Processor or Ingest Processor and awareness of pipeline‑level routing and data transformation.
  • Practical experience integrating telemetry from AWS, Azure, and GCP environments and normalizing cloud‑native data sources.
  • Strong Linux and Windows administration knowledge.
  • Experience using Python and Bash/Shell scripting to automate Splunk administration, knowledge object management, and API‑driven deployments.
  • Experience with GitHub, GitHub Actions, CI/CD pipelines, and version‑controlled content promotion workflows.
  • Familiarity with MITRE ATT&CK, NIST CSF, N
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Admin
Splunk Admin

Lorven Technologies Inc. • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Splunk Developer/ Splunk Consultant
Splunk Developer/ Splunk Consultant

Cosmonaut Technologies • Pune District

On-site
INR 1,800,000 - 2,800,000
Senior Associate - Cyber Security SIEM Splunk
Senior Associate - Cyber Security SIEM Splunk

PwC • Hyderabad, Pune District, Bengaluru

On-site
INR 1,200,000 - 1,800,000
Splunk Architect - DM/ Manager | Pune
Splunk Architect - DM/ Manager | Pune

Deloitte Shared Services India • Pune District

On-site
INR 1,800,000 - 3,000,000
Data Engineer
Data Engineer

Accenture in India • Bengaluru

On-site
INR 900,000 - 1,500,000
Splunk Administrator
Splunk Administrator

Capgemini • Hyderabad, Pune District, Bengaluru

On-site
INR 1,200,000 - 2,400,000
Principal Infrastructure Engineer - Splunk Admin (SIEM)
Principal Infrastructure Engineer - Splunk Admin (SIEM)

Silicon Valley Bank • Karnataka

On-site
INR 2,500,000 - 4,500,000
Splunk Architect
Splunk Architect

Tekskills • Bulandshahr

On-site
INR 1,800,000 - 3,000,000
Splunk Architect
Splunk Architect

Tekskills • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Splunk Architect
Splunk Architect

Tekskills • Chennai District

On-site
INR 1,800,000 - 2,400,000