Senior Cyber Analyst: Splunk & ML Threat Detection

CRI Advantage

Idaho Falls (ID)

On-site

USD 110,000 - 124,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

CRI Advantage in Idaho Falls is seeking a security detections engineer who will design, build, and tune detections that identify malicious activity across our environment, blending security analysis, data engineering, and machine learning.

You will live and breathe Splunk, turning raw telemetry into high-fidelity alerts. The role requires deep SPL expertise, ES experience, and ML-driven detection development, with collaboration across threat intel, incident response, and SOC teams.

Qualifications

  • Current clearance: L, Q, or TS.
  • Deep expertise in Splunk SPL, advanced search, data models, performance optimization.
  • Hands-on with Splunk Enterprise Security: correlation searches, risk-based alerting, notable events.
  • Experience with the Splunk AI Toolkit (AITK) for ML-based detections.
  • Experience with the Splunk App for Data Science and Deep Learning (DSDL).
  • Strong understanding of MITRE ATT&CK and detection engineering.

Responsibilities

  • Design, develop, and maintain detection content using Splunk SPL to identify threats across diverse data sources.
  • Build and tune correlation searches, notable events, and risk-based alerting within Splunk Enterprise Security (ES).
  • Leverage the Splunk App for Data Science and Deep Learning (DSDL) to operationalize machine learning models for anomaly detection and advanced threat identification.
  • Apply the Splunk App for Anomaly Detection and the Splunk AI Toolkit (AITK) to develop statistical and ML-driven detections.
  • Map detection coverage to the MITRE ATT&CK framework and identify gaps in visibility.
  • Collaborate with threat intelligence, incident response, and SOC teams to translate emerging threats into actionable detections.
  • Reduce false positives and alert fatigue through continuous tuning and detection lifecycle management.
  • Develop and maintain detection-as-code workflows, including version control, testing, and CI/CD for detection content.
  • Create documentation, runbooks, and detection specifications to support downstream analysts.

Skills

Splunk SPL
Splunk ES
MITRE ATT&CK
DSDL ML
AITK
Python

Tools

Git
CI/CD pipelines
Python

Job description

CRI Advantage in Idaho Falls is seeking a security detections engineer who will design, build, and tune detections that identify malicious activity across our environment, blending security analysis, data engineering, and machine learning.

You will live and breathe Splunk, turning raw telemetry into high-fidelity alerts. The role requires deep SPL expertise, ES experience, and ML-driven detection development, with collaboration across threat intel, incident response, and SOC teams.

Get your free, confidential resume review.
or drag and drop your file here.