Cyber Analyst current L, Q or TS mandatory

Gilder Search Group

Idaho Falls, Northern (ID, KY)

Hybrid

USD 120,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Gilder Search Group in Idaho Falls, ID seeks a Splunk-focused security analytics professional to design, build, and tune detections that identify threats across diverse data sources. You will apply ML techniques using DS/Deep Learning tools and map coverage to MITRE ATT&CK, ensuring high-fidelity alerts and efficient SOC operations.

Relocation to Idaho Falls is required, and no remote work is offered. Candidates must hold a current L, Q, or Top Secret clearance and be willing to relocate.

Qualifications

  • Current DOE L, Q, or Top Secret clearance required.
  • Willingness to relocate to Idaho Falls, ID.
  • Deep expertise in Splunk SPL with advanced search, data models and performance optimization.
  • Hands-on Splunk ES experience including correlation searches, risk-based alerting, notable events, ES framework.
  • Experience with the Splunk App for Data Science and Deep Learning (DSDL) including custom model development.
  • Strong understanding of MITRE ATT&CK framework and detection engineering methodology.
  • Familiarity with security data sources (EDR, network, cloud, identity) and attack techniques.

Responsibilities

  • Design, build, and tune detections using Splunk SPL across diverse data sources.
  • Develop and tune correlation searches, notable events, and risk-based alerting in Splunk ES.
  • Utilize DSDL and AITK for ML-based anomaly detection and threats identification.
  • Map detection coverage to MITRE ATT&CK and identify visibility gaps.
  • Collaborate with threat intelligence, incident response, and SOC teams to translate threats into detections.
  • Reduce false positives through lifecycle management and tuning.
  • Create detection-as-code workflows with version control, testing, and CI/CD.
  • Produce documentation and runbooks to support analysts.

Skills

Splunk SPL
Splunk Enterprise Security
Splunk AI Toolkit
Splunk App for DS and DL
MITRE ATT&CK
Threat hunting
Detection engineering
Security data awareness

Tools

Git
CI/CD
SOAR platforms
Python

Job description

Must have current, not active, DOE L, Q or TS and above to be qualified

Salary and if needed, per diem to be onsite in Idaho Falls Idaho. NO REMOTE WORK

1. Qualifying individual must be willing to relocate to Idaho Falls, Idaho.

2. Qualifying individual must have a current “L” or “Q” clearance OR Top Secret

3. Qualifying individual “MUST” have the following skillsets:

  • Deep expertise in Splunk SPL, including advanced search commands, statistical functions, data models, and performance optimization
  • Hands-on experience with Splunk Enterprise Security, including correlation searches, risk-based alerting (RBA), notable events, and the ES framework
  • Working knowledge of the Splunk AI Toolkit (AITK) for building and applying ML-based detections
  • Experience with the Splunk App for Data Science and Deep Learning (DSDL), including custom model development and deployment
  • Strong understanding of the MITRE ATT&CK framework and detection engineering methodology
  • Familiarity with common attack techniques, log sources, and security data (EDR, network, cloud, identity, etc.)

4. Qualifying individual “NICE” to have the following skillsets:

  • Experience with detection-as-code practices and tools (Git, CI/CD pipelines)
  • Proficiency in Python for data processing and model development
  • Knowledge of SOAR platforms and detection automation
  • Relevant certifications (Splunk Certified Power User/Admin, Splunk Enterprise Security Certified Admin, GIAC, etc.)
  • Prior experience in a SOC, threat hunting, or incident response role

In this role, the selected candidate will design, build, and tune detections that identify malicious activity across our environment, working at the intersection of security analysis, data engineering, and machine learning. We’re looking for a candidate that lives and breathes Splunk and gets excited about turning raw telemetry into high-fidelity alerts, we want to hear from you.

What the candidate is expected to perform:

  • Design, develop, and maintain detection content using Splunk Search Processing Language (SPL) to identify threats across diverse data sources
  • Build and tune correlation searches, notable events, and risk-based alerting within Splunk Enterprise Security (ES)
  • Leverage the Splunk App for Data Science and Deep Learning (DSDL) to develop machine learning models for anomaly detection and advanced threat identification
  • Apply the Splunk App for Anomaly Detection and the Splunk AI Toolkit (AITK) to develop statistical and ML-driven detections that go beyond signature-based approaches
  • Map detection coverage to the MITRE ATT&CK framework and identify gaps in visibility
  • Collaborate with threat intelligence, incident response, and SOC teams to translate emerging threats into actionable detections
  • Reduce false positives and alert fatigue through continuous tuning and detection lifecycle management
  • Develop and maintain detection-as-code workflows, including version control, testing, and CI/CD for detection content
  • Create documentation, runbooks, and detection specifications to support downstream analysts
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Analyst- Level 3
Cyber Analyst- Level 3

CRI Advantage, Inc. • Idaho Falls (ID)

On-site
USD 110,000 - 170,000
Telemetry Engineer
Telemetry Engineer

Openkyber • Alaska

On-site
USD 130,000 - 180,000
Principal Splunk-Threat Detection & Integration Engineer
Principal Splunk-Threat Detection & Integration Engineer

Quzara LLC • United States

On-site
USD 120,000 - 160,000
Splunk Security Detection Engineer
Splunk Security Detection Engineer

United Global Technologies • Idaho Falls (ID)

Remote
USD 120,000 - 190,000
Splunk Threat Detection Engineer (Onsite Idaho Falls)
Splunk Threat Detection Engineer (Onsite Idaho Falls)

Gilder Search Group • Idaho Falls (ID), Northern (KY)

Hybrid
USD 120,000 - 180,000
Splunk Detection Engineer
Splunk Detection Engineer

DivIHN Integration Inc • United States

Remote
USD 100,000 - 130,000
Senior Software Engineer, Information Security
Senior Software Engineer, Information Security

COMMURE Incorporated • Mountain View (CA)

On-site
USD 130,000 - 160,000
SITEC - Cyber Threat Detection Engineer - MacDill AFB
SITEC - Cyber Threat Detection Engineer - MacDill AFB

Peraton • Tampa (FL)

On-site
USD 110,000 - 170,000
Senior SIEM Engineer (Splunk)
Senior SIEM Engineer (Splunk)

Quantum Sky • Washington

On-site
USD 140,000 - 210,000
Senior Splunk Cyber Threat Detection Engineer (ML)
Senior Splunk Cyber Threat Detection Engineer (ML)

CRI Advantage, Inc. • Idaho Falls (ID)

On-site
USD 110,000 - 170,000