Sr. Splunk Engineer-KSA

Itsecurityct

Saudi Arabia

On-site

SAR 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Itsecurityct is seeking a Senior Splunk Engineer to design, implement, and optimize Splunk solutions within a large-scale enterprise. The role involves onboarding log sources, creating dashboards, and ensuring performance tuning.

The ideal candidate will have over 5 years of SIEM experience with a strong focus on Splunk Enterprise or Cloud and a solid understanding of security operations. Certifications like Splunk Core Certified Power User are essential.

Qualifications

  • 5+ years of hands-on experience in SIEM engineering with at least 3 years focused on Splunk.
  • Familiarity with integrating diverse log sources including cloud systems.
  • Good knowledge of networking, security protocols, and system administration.

Responsibilities

  • Design and implement end-to-end Splunk solutions including data ingestion.
  • Develop and maintain custom correlation rules, alerts, dashboards.
  • Automate tasks and processes using scripts and configuration management tools.

Skills

SPL (Search Processing Language)
SIEM engineering
Data onboarding
Scripting (Python, Bash, PowerShell)
Security operations

Education

Splunk Core Certified Power User
CompTIA Security+, CISSP

Tools

Splunk Enterprise
Splunk Cloud
Splunk ES
AWS
Azure

Job description

IT Security C&T is an innovative, fast-growing security consulting and training company. Our management team combined with our consultants and engineers work together to deliver comprehensive security solutions to our customers around the MENA region. The company is continuously expanding its team of qualified professionals for a wide range of opportunities.

Job Description

Job Summary: The Senior Splunk Engineer will be responsible for the design, implementation, administration, and optimization of Splunk Enterprise or Splunk Cloud within a large-scale enterprise or managed services environment. The engineer will support log onboarding, correlation rule development, dashboard creation, and performance tuning, ensuring the Splunk platform delivers accurate, actionable insights for security operations and compliance monitoring.

Key Responsibilities:

  • Design and implement end-to-end Splunk solutions including data ingestion, parsing, indexing, and search optimization.
  • Develop and maintain custom correlation rules, alerts, dashboards, and visualizations to support security monitoring and incident response.
  • Onboard new log sources from infrastructure, security, application, and cloud systems using best practices (e.g., via UF, HF, syslog, APIs).
  • Perform regular health checks, indexer and search head performance tuning, license usage monitoring, and configuration backups.
  • Support threat detection initiatives by translating security use cases into actionable Splunk queries and alerts.
  • Assist in troubleshooting ingestion failures, parsing errors, and inefficient searches.
  • Collaborate with SOC, threat intelligence, and infrastructure teams to ensure data relevance, completeness, and quality.
  • Maintain Splunk Enterprise Security (ES) configurations, including CIM compliance, notables, and risk‑based alerting (RBA).
  • Implement and manage data retention policies and storage utilization in line with compliance requirements.
  • Automate tasks and processes using scripts (Python, Bash, PowerShell) and configuration management tools where needed.
  • Provide technical guidance and mentoring to junior Splunk engineers and analysts.
Qualifications

Required Skills & Experience:

  • 5+ years of hands‑on experience in SIEM engineering with at least 3 years focused on Splunk Enterprise or Splunk Cloud.
  • Proficient in SPL (Search Processing Language), data onboarding, and CIM normalization.
  • Experience integrating diverse log sources including firewalls, endpoints, cloud (AWS, Azure), identity systems, and threat intel feeds.
  • Strong understanding of security operations, detection engineering, and incident response workflows.
  • Familiarity with Splunk ES, UBA, ITSI, and SOAR (preferred but not mandatory).
  • Experience with scripting and automation (Python, Bash, PowerShell).
  • Good knowledge of networking, security protocols, and system administration (Windows/Linux).
  • Exposure to regulatory and compliance requirements such as ISO 27001, NCA, SAMA, PCI‑DSS, etc.

Preferred Certifications:

  • Splunk Core Certified Power User – Required
  • Splunk Enterprise Security Certified Admin – Preferred
  • Splunk Certified Architect or Consultant – Highly Desirable
  • CompTIA Security+, CISSP, or equivalent – Advantageous
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Splunk/SIEM Administrator- Dubai, UAE
Senior Splunk/SIEM Administrator- Dubai, UAE

DS DeepSource • Riyadh

On-site
SAR 260,000 - 420,000
Senior Splunk Engineer - SIEM & Cloud Security Lead
Senior Splunk Engineer - SIEM & Cloud Security Lead

Itsecurityct • Saudi Arabia

On-site
SAR 120,000 - 150,000
Splunk Engineer
Splunk Engineer

exequt MENA • Riyadh

On-site
SAR 240,000 - 420,000
Performance-based compensation
Medical insurance (Golden Tier)
Ongoing training and mentorship
+2
Title: Splunk Customer Success Engineer - KSA
Title: Splunk Customer Success Engineer - KSA

Cisco Systems, Inc. • Riyadh

Hybrid
SAR 120,000 - 150,000
Healthcare and Insurance
Employee Stock Purchase program
Flexible Spending Benefit
+1
Splunk Operations Lead
Splunk Operations Lead

Visible Stars • Riyadh

On-site
SAR 360,000 - 540,000
Splunk Use Case Engineers
Splunk Use Case Engineers

Visible Stars, Inc. • Riyadh

On-site
SAR 180,000 - 240,000
Senior Splunk Operations Lead - SIEM & Security Analytics
Senior Splunk Operations Lead - SIEM & Security Analytics

Visible Stars • Riyadh

On-site
SAR 360,000 - 540,000
Splunk Integration & Data Engineers
Splunk Integration & Data Engineers

Visible Stars, Inc. • Riyadh

On-site
SAR 300,000 - 500,000
Splunk Operations Lead
Splunk Operations Lead

Visible Stars, Inc. • Riyadh

On-site
Splunk Integration & Data Engineers
Splunk Integration & Data Engineers

Visible Stars Company • Riyadh

On-site
SAR 224,000 - 338,000