Job Search and Career Advice Platform

Enable job alerts via email!

Senior Splunk Engineer

DXC Technology

Riyadh

On-site

SAR 200,000 - 300,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A global technology company located in Riyadh is seeking a Senior Splunk Engineer to design, implement, and optimize Splunk solutions. The role involves supporting log onboarding, developing correlation rules, and collaborating with security teams to enhance security operations. Candidates should have over 5 years of SIEM engineering experience, proficiency in SPL, and familiarity with diverse log sources. The company fosters an inclusive work environment prioritizing collaboration and individual wellbeing.

Qualifications

  • 5+ years hands-on experience in SIEM with focus on Splunk.
  • Proficient in SPL and data onboarding.
  • Strong understanding of security operations workflows.

Responsibilities

  • Design and implement end-to-end Splunk solutions.
  • Develop and maintain custom correlation rules and dashboards.
  • Onboard new log sources using best practices.
  • Perform health checks and configuration backups.
  • Support threat detection initiatives with actionable queries.
  • Collaborate with teams to ensure data quality.
  • Implement data retention policies.
  • Automate tasks using scripts.

Skills

5+ years of hands-on experience in SIEM engineering
Proficient in SPL (Search Processing Language)
Experience integrating diverse log sources
Strong understanding of security operations
Familiarity with Splunk ES, UBA, ITSI
Experience with scripting and automation
Good knowledge of networking and security protocols
Job description
Summary :

The Senior Splunk Engineer will be responsible for the design, implementation, administration, and optimization of Splunk Enterprise or Splunk Cloud within a large‑scale enterprise or managed services environment. The engineer will support log onboarding, correlation rule development, dashboard creation, and performance tuning, ensuring the Splunk platform delivers accurate, actionable insights for security operations and compliance monitoring.

Key Responsibilities :
  • Design and implement end‑to‑end Splunk solutions including data ingestion, parsing, indexing, and search optimization.
  • Develop and maintain custom correlation rules, alerts, dashboards, and visualizations to support security monitoring and incident response.
  • Onboard new log sources from infrastructure, security, application, and cloud systems using best practices (e.g., via UF, HF, syslog, APIs).
  • Perform regular health checks, indexer and search head performance tuning, license usage monitoring, and configuration backups.
  • Support threat detection initiatives by translating security use cases into actionable Splunk queries and alerts.
  • Assist in troubleshooting ingestion failures, parsing errors, and inefficient searches.
  • Collaborate with SOC, threat intelligence, and infrastructure teams to ensure data relevance, completeness, and quality.
  • Maintain Splunk Enterprise Security (ES) configurations, including CIM compliance, notables, and risk‑based alerting (RBA).
  • Implement and manage data retention policies and storage utilization in line with compliance requirements.
  • Automate tasks and processes using scripts (Python, Bash, PowerShell) and configuration management tools where needed.
  • Provide technical guidance and mentoring to junior Splunk engineers and analysts.
Required Skills & Experience :
  • 5+ years of hands‑on experience in SIEM engineering with at least 3 years focused on Splunk Enterprise or Splunk Cloud.
  • Proficient in SPL (Search Processing Language), data onboarding, and CIM normalization.
  • Experience integrating diverse log sources including firewalls, endpoints, cloud (AWS, Azure), identity systems, and threat intel feeds.
  • Strong understanding of security operations, detection engineering, and incident response workflows.
  • Familiarity with Splunk ES, UBA, ITSI, and SOAR (preferred but not mandatory).
  • Experience with scripting and automation (Python, Bash, PowerShell).
  • Good knowledge of networking, security protocols, and system administration (Windows / Linux).

At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in‑person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.