About The Role
Join our Cyber Security Operations Center (CSOC) as an Intermediate Engineer focused on strengthening enterprise security monitoring and detection capabilities through Splunk and Splunk Enterprise Security. In this role, you will enhance SIEM effectiveness, improve detection coverage, support complex incident investigations, and collaborate with Information Security, IT, and Delivery teams to advance security operations, automation, and threat visibility across the organization.
Responsibilities
- Develop, configure, and maintain Splunk and Splunk Enterprise Security content, including correlation searches, dashboards, reports, data models, knowledge objects, and security analytics
- Own detection engineering activities by creating, tuning, and optimizing SIEM detection content to improve alert fidelity, expand threat coverage, and reduce false positives
- Collaborate with Information Security, IT, Delivery teams, and CSOC analysts to strengthen monitoring capabilities, improve investigations, and enhance operational effectiveness
- Onboard, normalize, and validate security data sources, ensuring data quality, correct field extraction, CIM compliance, and reliable monitoring coverage
- Act as an L2 escalation point, investigating complex security alerts and incidents, supporting threat analysis, and providing guidance to L1 analysts during investigations
- Build dashboards, analytics, and reporting solutions that support security monitoring, incident response, performance tracking, and detection engineering initiatives
- Implement integrations between security platforms and enterprise services, support operational issue resolution, validate SIEM functionality after updates, and coordinate with platform support teams when needed
- Leverage scripting, automation, SOAR, and AI-enabled technologies to streamline investigations, support operational workflows, contribute to continuous improvement initiatives, and maintain technical documentation
Requirements
- At least 2 years of hands‑on experience in security operations, SOC/CSOC analysis, SIEM engineering, detection engineering, security engineering, or a related cybersecurity role
- Strong practical experience with Splunk and Splunk Enterprise Security, including confident use of Splunk Search Processing Language (SPL)
- Experience creating and tuning correlation searches, security alerts, dashboards, reports, notable events, and detection content within SIEM platforms
- Knowledge of security data onboarding, normalization, field extraction, data quality management, log‑source coverage, and Splunk Common Information Model (CIM) concepts
- Solid understanding of incident investigation, alert triage, Windows and Linux environments, and common security technologies including EDR, IDS/IPS, firewalls, email security, and identity services
- Familiarity with MITRE ATT&CK and understanding of security frameworks such as NIST CSF and ISO 27001
- Experience with Python, PowerShell, SOAR platforms, automation technologies, or similar tools, with the ability to utilize AI‑enabled tools effectively
- Strong analytical, problem‑solving, and technical documentation skills, with the ability to independently investigate moderately complex issues and communicate effectively in English at B1/B2 level or higher
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Management Information Systems, or a related field; relevant security and Splunk certifications are considered an advantage
SoftServe is an equal opportunity employer. Qualified applicants will receive consideration regardless of race, color, ancestry, ethnicity, national origin, religion, sex, sexual orientation, gender identity or expression, age, citizenship, disability, health condition, marital or family status, veteran status, or any other characteristic protected by applicable law.