Enable job alerts via email!

Security Content Engineer – Splunk

BlueVoyant

College Park (MD)

Remote

USD 80,000 - 120,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Security Operations Center Security Content Engineer to join a dynamic team focused on enhancing security insights through Splunk cloud solutions. This fully remote role offers the chance to work closely with clients, developing detection logic and visualizations to improve their security posture. You will play a vital role in analyzing event logs, mentoring junior engineers, and advancing security policies. If you are passionate about cybersecurity and eager to make a significant impact in a fast-paced environment, this opportunity is perfect for you.

Qualifications

  • 7+ years in IT/security with 4 years in SIEM solutions.
  • Strong experience in digital forensics and detection engineering.

Responsibilities

  • Create detections for security and IT operations concerns.
  • Collaborate with clients on visualizations for security posture.

Skills

Teamwork
Signature writing
Event log analysis
Microsoft Azure Sentinel
Microsoft Threat Protection
Kusto Query Language (KQL)
Scripting languages (Python, PowerShell)
Digital forensic analysis
Network protocols understanding
Customer communication

Education

Bachelor’s degree in Information Security
Equivalent experience in IT-related field

Tools

Wireshark
TCP Dump
Security Onion
Splunk

Job description

Summary
BlueVoyant is looking for a Security Operations Center Security Content Engineer to help our global customers manage their Splunk cloud security solutions. You will be part of a fast-paced team that helps customers to efficiently and effectively derive security insights through generating detection logic, automation, and visualizations. This position is fully remote.

Security Content Engineer – Splunk
Location: Remote in the United States
US Citizenship Required

Key Responsibilities

  • Ideate and create client-facing detections to surface security and IT operations concerns
  • Collaborate with clients to design and implement visualizations to assist clients with understanding security posture, interesting events, and operations metrics
  • Assist clients with testing and tuning detection logic to minimize false positives, alert duplication, and whitelisting
  • Identify opportunities for client-specific needs to become base content for all MSS, including rules, automations, and dashboards
  • Assist integration teams in identifying opportunities for log content reduction and removal of irrelevant events
  • Deliver functional value resulting from research in the form of queries, signatures, rules, and contextual information (knowledge base articles)
  • Serve as a Technical SOC SME in support to customers (customer facing) and support to sales and marketing
  • Supplemental in-depth research of exploits and vulnerabilities which have a high likelihood of occurring within BlueVoyant customer environments
  • Assist in the advancement of security policies, procedures, and automation
  • Serve as the technical escalation point and mentor for junior detection engineers and Sentinel support staff
  • Regularly communicate with customer IT teams to inform them of issues, help them remediate, and ensure that they continue to operate business as usual
  • Assist with advancing security standard operating procedures and incident response reporting

Qualifications

  • Excellent teamwork skills
  • Previous signature writing / algorithm creation experience
  • Ability to analyze event logs and recognize signs of cyber intrusions/attacks
  • Hands-on experience with Microsoft Azure Sentinel, Defender ATP, O365 ATP, and other Microsoft security suites
  • Hands-on experience with Microsoft Threat Protection suite of security solutions (Defender ATP, Azure ATP, Office 365 ATP, Microsoft Cloud Application Security), Azure Active Directory, Azure Security Center, Azure Log Analytics, and M365 suite of solutions
  • Hands-on experience for the following:
    • Develop, automate, and orchestrate tasks (playbooks) with logic apps based on certain events
    • Configure Sentinel Incidents, Workbooks, Hunt queries, Notebooks
    • Ability to advise customers on the Microsoft Cloud Security capabilities across the Azure platform
    • Kusto Query Language (KQL)
  • Strong experience with scripting languages (Python, PowerShell, others)
  • Strong experience with digital forensic analysis (host, network, other) and blue team operations
  • Strong knowledge and understanding of network protocols and devices
  • Ability to work directly with customers to understand requirements for and feedback on security services
  • Advanced written and verbal communication skills and the ability to present complex technical topics in clear and easy-to-understand language
  • Strong teamwork and interpersonal skills, including the ability to work effectively with a globally distributed team
  • Skilled in the creation of signatures for security tools
  • Familiarity with tools such as Wireshark, TCP Dump, Security Onion, and Splunk
  • Strong knowledge of the following:
    • SIEM
    • Packet Analysis
    • SSL Decryption
    • Malware Detection
    • HIDS/NIDS
    • Network Monitoring Tools
    • Case Management System
    • Knowledge Base
    • Web Security Gateway
    • Email Security
    • Data Loss Prevention
    • Anti-Virus
    • Network Access Control
    • Encryption
    • Vulnerability Identification

Preferred Qualifications

  • Experience in intrusion analysis, digital forensics, penetration testing, detection engineering, or related areas
  • 7+ years of experience in information technology or information security, 4 of which were spent dealing directly with SIEM solutions and detection content creation
  • Microsoft 365 Certified: Security Administrator Associate and GCFA, GCFE, or OSCP preferred
  • Familiarity with Azure, .Net programming, Jupyter notebooks, and scripting/development using web APIs

Education

  • Minimum bachelor’s degree in Information Security, Computer Science, or other IT-related field or equivalent experience

About BlueVoyant
At BlueVoyant, we recognize that effective cyber security requires active prevention and defense across both your organization and supply chain. Our proprietary data, analytics, and technology, coupled with deep expertise, works as a force multiplier to secure your full ecosystem. Accuracy! Actionability! Timeliness! Scalability!

Led by CEO, Jim Rosenthal, BlueVoyant’s highly skilled team includes former government cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency, Federal Bureau of Investigation, Unit 8200, and GCHQ, together with private sector experts. BlueVoyant services utilize large real-time datasets with industry leading analytics and technologies.

Founded in 2017 by Fortune 500 executives, including Executive Chairman, Tom Glocer, and former Government cyber officials, BlueVoyant is headquartered in New York City and has offices in Maryland, Tel Aviv, San Francisco, London, Budapest, and Latin America.

All employees must be authorized to work in the United States. BlueVoyant provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, BlueVoyant complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities.

Disclaimer: Please note that pursuant to contractual requirements and applicable law, in order for employees to perform work on some of the company’s federal contracts, U.S. citizenship is required. Accordingly, an employee’s ability to perform work on such contracts is contingent upon the company’s verification of the employee’s citizenship status. Furthermore, individuals may be subject to additional background checks and fingerprinting.

BlueVoyant Candidate Privacy Notice
To understand how we secure and manage your personal data upon submitting a job application, please see our Candidate Privacy Notice, which can be found here - Candidate Privacy Notice

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior ServiceNow Developer with Public Trust or Secret (Remote)

ICF

Great Falls Crossing

Remote

USD 98,000 - 167,000

Yesterday
Be an early applicant

AWS Cloud Engineer - Splunk

Peraton

Herndon

Remote

USD 80,000 - 120,000

4 days ago
Be an early applicant

Senior ServiceNow Developer with SECRET (Remote DC MD VA area)

Lensa

Great Falls Crossing

Remote

USD 90,000 - 130,000

2 days ago
Be an early applicant

ServiceNow Developer with DHS Public Trust or Secret (Remote)

Via Logic LLC

Great Falls Crossing

Remote

USD 80,000 - 110,000

6 days ago
Be an early applicant

Security Content Engineer – Splunk

BlueVoyant

Maryland

Remote

USD 80,000 - 130,000

30+ days ago

Sr Data Platform Architect

General Electric

Baltimore

Remote

USD 110,000 - 185,000

12 days ago

ServiceNow Developer (Hybrid)

Latitude Inc

Washington

Remote

USD 110,000 - 135,000

15 days ago

Security Content Engineer – Splunk

BlueVoyant

Remote

USD 80,000 - 140,000

30+ days ago

Splunk Engineer

TEKsystems

Raleigh

Remote

USD 80,000 - 100,000

Yesterday
Be an early applicant