Overview
Splunk Use Case Engineer — Expertise: Splunk Enterprise Security (ES) Certified Admin or Splunk Core Certified Power User, with minimum 5+ years in SOC use case development.
Responsibilities
- Dedicated full-time to Use Case Lifecycle Management (Development, Tuning, Optimization).
- Develop, fine-tune, and maintain SOC/security use cases aligned with regulatory and threat intelligence frameworks.
- Optimize correlation searches, alerts, and dashboards.
- Maintain documentation for the application onboarding configurations to Splunk.
- Stay current with emerging threats and attack techniques.
- Reduce false positives and enhance detection fidelity.
- L2/L3 investigation of security alerts and incidents.
Qualifications
- Proven experience in managing enterprise Splunk environments at scale (preferably in banking/financial institutions).
- Certified Splunk engineers across architecture, administration, and use case development.
- Ability to provide at least 5 full-time technical resources.
- 24x7 support capabilities with SLA-driven response times.
- Familiarity with regulatory and compliance requirements in the financial sector (SAMA CSF, NCA, PCI DSS, etc.).
Note: This description removes boilerplate application form text and unrelated notices while preserving the core responsibilities and qualifications.