Splunk Enterprise Security Engineer

NTT DATA Business Solutions

Cyberjaya

On-site

MYR 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical Insurance
Health Insurance
Optical and Dental Benefits

Job summary

NTT DATA Business Solutions in Cyberjaya is seeking a highly technical Splunk Enterprise Security (ES) Engineer to lead enterprise Splunk environments and SIEM capabilities. The role focuses on platform stability, data quality, and detection engineering within a SOC context.

The ideal candidate will manage production Splunk environments, implement data onboarding, CIM normalization, correlation searches, and Risk-Based Alerting, while collaborating with SOC analysts to improve threat detection

Qualifications

  • Hands-on experience with Splunk Enterprise in production environments.
  • Experience deploying, upgrading, migrating, and troubleshooting Splunk infrastructure.
  • Experience onboarding data sources, CIM compliance, and data normalization.
  • Developing, maintaining, and tuning correlation searches.
  • Designing and implementing Risk-Based Alerting (RBA).
  • Creating and managing notable events and SOC workflows.
  • Building SIEM use cases with Splunk Enterprise Security.

Responsibilities

  • Manage and support production Splunk Enterprise environments.
  • Deploy, upgrade, migrate, and troubleshoot Splunk infrastructure.
  • Design and implement log forwarding and data onboarding solutions.
  • Create Splunk dashboards, reports, and monitoring solutions.
  • Build and operate SIEM use cases with Splunk ES.
  • Develop correlation searches, notable events, and RBA.
  • Collaborate with SOC teams to enhance threat detection and reduce alerts.

Skills

Splunk Enterprise
Splunk Enterprise Security (ES)
SIEM engineering
SOC collaboration
Data ingestion troubleshooting

Tools

Splunk Forwarders
Deployment Server
Search Heads

Job description

At NTT DATA Business Solutions, we drive innovation – from advisory and implementation to managed services and beyond, powered by a global team of over 18,500 experts representing over 90 nations in more than 30 countries. With SAP at our core and a powerful ecosystem of partners like Microsoft and ServiceNow, we continuously improve solutions and AI-driven technology to make them work for companies – and for their people.

We are part of NTT DATA, a $30+ billion business and technology services, AI and digital infrastructure leader. As a Global Top Employer, NTT DATA serves 75% of the Fortune Global 100 and, with experts in over 70 countries, co-innovates solutions that encourage experimentation and recognize great work.

With us, you have endless opportunities to think big, act bold and take ownership. Make this the place where you belong, learn, and build your network.

Make this the place where you grow.

What makes us special:
  • Team-oriented corporate culture, collaboration as equals and steady knowledge transfer
  • Diversity & Inclusion (e.g. various initiatives & communities)
  • Inhouse Academy with a variety of professional technical training, soft skills training, SAP Learning Hub and certification opportunities
  • Company health benefits (e.g. Medical Insurance, Health Insurance, Optical and Dental Benefits)
What We Are Looking For:

We are seeking a highly technical Splunk Enterprise Security (ES) Engineer who possesses strong hands‑on expertise in both Splunk Enterprise and Splunk Enterprise Security (ES).

This role is ideal for candidates who have experience managing enterprise-scale Splunk environments and developing SIEM capabilities that support Security Operations Centre (SOC) teams. The successful candidate will act as the technical owner of the Splunk platform, driving platform stability, data quality, detection engineering, and continuous security monitoring improvements.

Core Competencies Required

Candidates should possess hands‑on experience in:

  • Deploying, configuring, and managing Splunk Enterprise environments.
  • Administering Splunk components including:
  • Search Heads
  • Universal Forwarders
  • Deployment Servers
  • Clustered Splunk environments
  • Splunk platform installation, maintenance, troubleshooting, and lifecycle management.
  • Planning and executing Splunk upgrades, migrations, and platform modernization activities.
  • Performance tuning, capacity planning, and platform optimization.
  • Log forwarding architecture, onboarding, and data ingestion troubleshooting.
  • Data parsing, field extraction, indexing, and CIM normalization.
  • Dashboard, report, and KPI development for operational and security use cases.
  • Troubleshooting search performance, ingestion bottlenecks, and infrastructure-related issues.
2.Splunk Enterprise Security (ES) & SIEM Engineering

Candidates should have proven hands‑on experience in developing and operating SIEM capabilities using Splunk Enterprise Security, including:

  • Onboarding and integrating security‑relevant data sources.
  • Troubleshooting data onboarding, parsing, CIM compliance, and normalization issues.
  • Developing, maintaining, and tuning correlation searches.
  • Designing and implementing Risk-Based Alerting (RBA).
  • Creating and managing notable events and investigation workflows.
  • Developing security use cases aligned with SOC detection requirements.
  • Privileged account misuse
  • Malware and endpoint threats
  • Lateral movement
  • Insider threats
  • Continuous tuning to reduce false positives and improve detection effectiveness.
  • Building operational and security dashboards for SOC monitoring and reporting.
  • Working closely with SOC analysts to improve threat detection, investigation, and incident response processes.
Ideal Candidate Profile
  • We are looking for a candidate who can demonstrate practical, hands‑on experience in most of the following areas:
  • Managing and supporting production Splunk Enterprise environments
  • Deploying, upgrading, migrating, and troubleshooting Splunk infrastructure
  • Designing and implementing log forwarding and data onboarding solutions
  • Creating Splunk dashboards, reports, and operational monitoring solutions
  • Building and operating SIEM use cases using Splunk Enterprise Security
  • Developing correlation searches, notable events, and Risk-Based Alerting frameworks
  • Troubleshooting ingestion, parsing, normalization, and ES-related issues
  • Collaborating with SOC teams to enhance threat detection and reduce alert fatigue
  • Supporting large-scale enterprise or regulated environments
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Splunk Enterprise Security Engineer SIEM & SOC Expert
Senior Splunk Enterprise Security Engineer SIEM & SOC Expert

NTT DATA Business Solutions • Cyberjaya

On-site
MYR 120,000 - 180,000
Medical Insurance
Health Insurance
Optical and Dental Benefits
Senior SIEM Engineer
Senior SIEM Engineer

Randstad Malaysia • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Splunk Administrator
Splunk Administrator

UOB • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Splunk Administrator
Splunk Administrator

Private Advertiser • Kuala Lumpur

On-site
MYR 120,000 - 180,000
SOC Specialist
SOC Specialist

Pride Global • Selangor

On-site
MYR 140,000 - 230,000
Lead Analyst, Digital Security
Lead Analyst, Digital Security

AIA • Sepang

On-site
MYR 80,000 - 120,000
SOC Lead
SOC Lead

XL Axiata • Kuala Lumpur

On-site
MYR 240,000 - 360,000
SOC Specialist
SOC Specialist

Pride Global • Cyberjaya

On-site
MYR 120,000 - 180,000
SOC Lead
SOC Lead

Axonect • Kuala Lumpur

On-site
MYR 180,000 - 240,000
Security Delivery Consultant
Security Delivery Consultant

ABP Group • Kuala Lumpur

On-site
MYR 120,000 - 170,000