Hybrid Splunk SOC Engineer: Detection & IR

ZP Group

North Carolina

Hybrid

USD 100,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
401k
PTO holidays

Job summary

Piper Companies is seeking a highly skilled Splunk Engineer / SOC Engineer to support enterprise security monitoring and analytics in a fast-paced environment. This full-time role is hybrid (2 days on-site) and requires a Secret clearance to be eligible.

You will develop detections, dashboards, and ingestion pipelines while collaborating with SOC analysts and cloud teams to enhance threat detection and response workflows.

Qualifications

  • Minimum of 5+ years of experience in SIEM engineering, security operations, or incident response environments.
  • Strong proficiency with Splunk, including writing complex SPL queries and building production-grade dashboards.
  • Hands-on experience with data normalization, ingestion, and troubleshooting within Splunk Enterprise or Splunk ES.
  • Experience integrating and onboarding security data sources into a centralized SIEM platform.
  • Familiarity with integrating tools such as AWS Security Hub or similar cloud-native security services.
  • Strong understanding of Splunk knowledge objects, field extractions, lookups, and CIM normalization.
  • Ability to perform effectively in high-pressure incident response situations and a willingness to participate in on-call rotations.

Responsibilities

  • Developing, maintaining, and optimizing Splunk Security detections, dashboards, and correlation searches.
  • Onboarding, parsing, normalizing, and enriching diverse security data sources into Splunk.
  • Troubleshooting ingestion pipelines, forwarder connectivity, indexing issues, and search performance challenges.
  • Assisting with configuration, maintenance, and troubleshooting across distributed Splunk environments.
  • Leveraging data models and accelerated searches to improve detection performance and reporting efficiency.
  • Collaborating with SOC analysts and engineering teams to enhance threat detection, visibility, and response workflows.
  • Participating in incident response activities, including deep-dive investigations into security alerts.

Skills

SIEM engineering
Incident response
Threat detection
Splunk
SPL queries
Dashboards
On-call readiness

Tools

Splunk Enterprise
Splunk ES
Splunk forwarders
AWS Security Hub

Job description

Piper Companies is seeking a highly skilled Splunk Engineer / SOC Engineer to support enterprise security monitoring and analytics in a fast-paced environment. This full-time role is hybrid (2 days on-site) and requires a Secret clearance to be eligible.

You will develop detections, dashboards, and ingestion pipelines while collaborating with SOC analysts and cloud teams to enhance threat detection and response workflows.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Hybrid Splunk SOC Engineer — Detection & Analytics
Hybrid Splunk SOC Engineer — Detection & Analytics

Piper Companies • United States

Hybrid
USD 100,000 - 120,000
Medical benefits
Dental benefits
Vision benefits
+1
Hybrid Splunk Engineer for SOC & Security Analytics
Hybrid Splunk Engineer for SOC & Security Analytics

Zachary Piper Solutions • North Carolina

Hybrid
USD 100,000 - 120,000
Hybrid Splunk Security Engineer — SIEM & Detection
Hybrid Splunk Security Engineer — SIEM & Detection

Zachary Piper Solutions • Northern (KY)

Hybrid
USD 100,000 - 120,000
Hybrid Splunk & SOC Engineer - Secret Clearance
Hybrid Splunk & SOC Engineer - Secret Clearance

Piper Companies • North Carolina

Hybrid
USD 100,000 - 120,000
Splunk / SOC Engineer - 174235 - 174717 - 175230
Splunk / SOC Engineer - 174235 - 174717 - 175230

Piper Companies • North Carolina

Hybrid
USD 100,000 - 120,000
Splunk / SOC Engineer - 174235 - 174717 - 175230
Splunk / SOC Engineer - 174235 - 174717 - 175230

Zachary Piper Solutions • North Carolina

Hybrid
USD 100,000 - 120,000
Splunk / SOC Engineer - 174235 - 174717 - 175230
Splunk / SOC Engineer - 174235 - 174717 - 175230

ZP Group • North Carolina

Hybrid
USD 100,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+2
Splunk / SOC Engineer - 174235 - 174717
Splunk / SOC Engineer - 174235 - 174717

Piper Companies • United States

Hybrid
USD 100,000 - 120,000
Medical benefits
Dental benefits
Vision benefits
+1
Splunk / SOC Engineer - 174235 - 174717
Splunk / SOC Engineer - 174235 - 174717

Zachary Piper Solutions • Northern (KY)

Hybrid
USD 100,000 - 120,000
Secret-Cleared SOC Engineer: SIEM & Incident Response
Secret-Cleared SOC Engineer: SIEM & Incident Response

ZP Group • Raleigh (NC)

On-site
USD 120,000 - 145,000
Medical, dental, vision benefits
401K + PTO
Sick leave as required by law