Senior Splunk Cyber Threat Detection Engineer (ML)

CRI Advantage, Inc.

Idaho Falls (ID)

On-site

USD 110,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CRI Advantage, Inc. seeks a security data engineer to design, build, and tune detections across our environment using Splunk SPL and ES. You will operationalize ML models with the DSDL and AITK to improve anomaly detection and threat identification.

You will map coverage to the MITRE ATT&CK framework, collaborate with threat intel and SOC teams, reduce false positives, and maintain detection-as-code workflows with version control and CI/CD. Relocation to Idaho Falls is required.

Qualifications

  • Deep expertise in Splunk SPL with advanced search, statistics, data models, and performance optimization.
  • Hands-on experience with Splunk Enterprise Security (ES), including correlation searches and risk-based alerting.
  • Experience with Splunk App for Data Science and Deep Learning (DSDL).
  • Experience with Splunk AI Toolkit (AITK) for ML-based detections.
  • Strong understanding of MITRE ATT&CK framework and detection engineering methodology.
  • Familiarity with security data (EDR, network, cloud, identity).

Responsibilities

  • Design, develop, and maintain detection content using Splunk SPL to identify threats across diverse data sources.
  • Build and tune correlation searches, notable events, and risk-based alerting within Splunk Enterprise Security (ES).
  • Leverage the Splunk App for Data Science and Deep Learning (DSDL) to operationalize machine learning models for anomaly detection and advanced threat identification.
  • Apply the Splunk App for Anomaly Detection and the Splunk AI Toolkit (AITK) to develop ML-driven detections that go beyond signature-based approaches.
  • Map detection coverage to the MITRE ATT&CK framework and identify gaps in visibility.
  • Collaborate with threat intelligence, incident response, and SOC teams to translate emerging threats into actionable detections.
  • Reduce false positives and alert fatigue through continuous tuning and detection lifecycle management.
  • Develop and maintain detection-as-code workflows, including version control, testing, and CI/CD for detection content.
  • Create documentation, runbooks, and detection specifications to support downstream analysts.

Skills

Splunk SPL
Splunk ES
AITK (Splunk AI Toolkit)
DSDL
MITRE ATT&CK
Detection engineering
Python

Tools

DSDL
Splunk App for Data Science and Deep Learning
Git
CI/CD pipelines
Splunk AI Toolkit

Job description

CRI Advantage, Inc. seeks a security data engineer to design, build, and tune detections across our environment using Splunk SPL and ES. You will operationalize ML models with the DSDL and AITK to improve anomaly detection and threat identification.

You will map coverage to the MITRE ATT&CK framework, collaborate with threat intel and SOC teams, reduce false positives, and maintain detection-as-code workflows with version control and CI/CD. Relocation to Idaho Falls is required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Detection Engineer – On-site Idaho Falls
Splunk Detection Engineer – On-site Idaho Falls

United Global Technologies • Idaho Falls (ID)

On-site
USD 90,000 - 150,000
Splunk Threat Detection Engineer (Onsite Idaho Falls)
Splunk Threat Detection Engineer (Onsite Idaho Falls)

Gilder Search Group • Idaho Falls (ID), Northern (KY)

Hybrid
USD 120,000 - 180,000
Cyber Analyst- Level 3
Cyber Analyst- Level 3

CRI Advantage, Inc. • Idaho Falls (ID)

On-site
USD 110,000 - 170,000
Cyber Analyst current L, Q or TS mandatory
Cyber Analyst current L, Q or TS mandatory

Gilder Search Group • Idaho Falls (ID), Northern (KY)

Hybrid
USD 120,000 - 180,000
Cyber Analyst ISSO current L Q or TS mandatory
Cyber Analyst ISSO current L Q or TS mandatory

United Global Technologies • Idaho Falls (ID)

On-site
USD 90,000 - 150,000
Senior Splunk SIEM Engineer — Threat Detection & Response
Senior Splunk SIEM Engineer — Threat Detection & Response

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
ML Detection Engineer
ML Detection Engineer

Arcitix Security • United States

On-site
USD 100,000 - 130,000
Senior Splunk Detection Engineer Threat Detection & RBA Lead
Senior Splunk Detection Engineer Threat Detection & RBA Lead

Cherokee Federal • Almont (CO)

On-site
USD 150,000 - 160,000
Medical
Dental
Vision
+1
Senior Software Engineer, Information Security
Senior Software Engineer, Information Security

COMMURE Incorporated • Mountain View (CA)

On-site
USD 130,000 - 160,000
Senior Splunk Security Engineer Threat Detection & Response
Senior Splunk Security Engineer Threat Detection & Response

RICEFW Technologies Inc • United States

On-site
USD 120,000 - 180,000