Cyber Security Analyst - Splunk & Threat Alerts

Stefanini, Inc

Atlanta (GA)

Hybrid

USD 143,270,000 - 171,924,000

Full time

21 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Stefanini, Inc. in Atlanta, GA, is seeking a Cyber Security Analyst with strong Splunk experience to monitor, investigate, and respond to cyber threats in a banking environment.

The role emphasizes threat-alert triage, incident investigation, threat hunting, and security monitoring across critical financial systems. The candidate should bring 5+ years in cybersecurity operations, hands-on Splunk ES and SPL development, and familiarity with Windows/Linux, IAM, EDR, cloud security, and

Qualifications

  • 5+ years of experience in cybersecurity operations, SOC monitoring, or incident response.
  • Hands-on Splunk and SPL query development experience.
  • Experience in banking, financial services, payments, fintech, or regulated environments.
  • Knowledge of financial-sector risks, including fraud and data protection.
  • Familiarity with Windows/Linux, network security, IAM, EDR, cloud security, and incident-response processes.

Responsibilities

  • Monitor and triage Splunk notable events, correlation searches, dashboards, and risk-based alerts.
  • Investigate suspicious authentication, privileged-account activity, malware, phishing, ransomware, data exfiltration, and unauthorized transactions or system access.
  • Write and optimize SPL queries for alert investigation, event correlation, and threat hunting.
  • Analyze logs from SIEM, EDR, firewalls, VPN, identity platforms, cloud services, applications, and banking systems.
  • Validate true and false positives, prioritize alerts by risk, and elevate confirmed incidents according to SOC procedures.
  • Develop and tune Splunk correlation searches, dashboards, reports, and detection rules to reduce false positives and improve coverage.
  • Support incident response, root-cause analysis, evidence preservation, and post-incident reporting.
  • Map threats and detections to MITRE ATT&CK and relevant financial-sector security controls.

Skills

Cybersecurity operations
Incident response
Threat detection
Threat hunting
Analytical thinking

Tools

Splunk Enterprise Security
Splunk SPL

Job description

Join us to co-create solutions for a better future!
Cyber Security Engineer

Cyber Security Analyst - Splunk & Threat Alerts Atlanta, GA

Position Type: Full Time

Position Summary

We are seeking a Cyber Security Analyst with strong Splunk Enterprise / Splunk Enterprise Security experience to monitor, investigate, and respond to cyber threats within a banking and financial services environment. The role will focus on threat-alert triage, incident investigation, threat hunting, and security monitoring across critical financial systems.

Key Responsibilities
  • Monitor and triage Splunk notable events, correlation searches, dashboards, and risk-based alerts.
  • Investigate suspicious authentication, privileged-account activity, malware, phishing, ransomware, data exfiltration, and unauthorized transactions or system access.
  • Write and optimize SPL queries for alert investigation, event correlation, and threat hunting.
  • Analyze logs from SIEM, EDR, firewalls, VPN, identity platforms, cloud services, applications, and banking systems.
  • Validate true and false positives, prioritize alerts by risk, and elevate confirmed incidents according to SOC procedures.
  • Develop and tune Splunk correlation searches, dashboards, reports, and detection rules to reduce false positives and improve coverage.
  • Support incident response, root-cause analysis, evidence preservation, and post-incident reporting.
  • Map threats and detections to MITRE ATT&CK and relevant financial-sector security controls.
Required Qualifications
  • 5+ years of experience in cybersecurity operations, SOC monitoring, or incident response.
  • Strong hands-on experience with Splunk and SPL query development.
  • Experience in banking, financial services, payments, fintech, or regulated environments.
  • Knowledge of financial-sector risks, including fraud, account takeover, payment-system threats, insider risk, and protection of sensitive customer data.
  • Strong hands-on experience with Splunk Enterprise Security.
  • Strong experience developing and troubleshooting SPL searches.
  • Familiarity with Windows/Linux, network security, identity and access management, EDR, cloud security, and incident-response processes.
  • Strong analytical, documentation, communication, and alert-prioritization skills.

*Listed salary ranges may vary based on experience, qualifications, and local market. Also, some positions may include bonuses or other incentives*

Pay Range

$ 50.00 - $ 60.00

About Stefanini Group

The Stefanini Group is a global provider of offshore, onshore and near shore outsourcing, IT digital consulting, systems integration, application and strategic staffing services to Fortune 1000 enterprises around the world. Our presence is in countries like Americas, Europe, Africa and Asia, and more than 400 clients across a broad spectrum of markets, including financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. Stefanini is a CMM level 5, IT consulting, company with global presence. We are CMM Level 5 company.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst - Splunk & Threat Hunting
Cyber Security Analyst - Splunk & Threat Hunting

Stefanini Group • Atlanta (GA)

On-site
USD 110,000 - 150,000
Splunk & Threat Alerts Cyber Security Analyst
Splunk & Threat Alerts Cyber Security Analyst

Stefanini, Inc • Atlanta (GA)

Hybrid
USD 143,270,000 - 171,924,000
SOC Analyst
SOC Analyst

Stefanini North America and APAC • Dover (DE)

Hybrid
USD 75,000 - 110,000
Cyber Intelligence Analyst
Cyber Intelligence Analyst

SECU • United States

On-site
USD 120,000 - 180,000
Cybersecurity Engineer
Cybersecurity Engineer

Global Sumi Technologies Inc., • Richmond (VA)

On-site
USD 110,000 - 170,000
Splunk SIEM Security Engineer
Splunk SIEM Security Engineer

Matlen Silver • Chandler (AZ)

Hybrid
USD 90,000 - 96,000
Cyber Security Analyst
Cyber Security Analyst

James Search Group • United States

On-site
USD 85,000 - 120,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Astyra Corporation • Richmond (VA)

On-site
USD 120,000 - 180,000
Principal Splunk-Threat Detection & Integration Engineer
Principal Splunk-Threat Detection & Integration Engineer

Quzara LLC • United States

On-site
USD 120,000 - 160,000
Security Engineer - SIEM (Splunk) Platform & Operations
Security Engineer - SIEM (Splunk) Platform & Operations

Samsung SDS America • San Jose (CA)

On-site
USD 125,000 - 175,000
Top-notch medical, dental, vision and prescription coverage
401K match and savings plan
Paid Time Off