Splunk Detection Engineer – On-site Idaho Falls

United Global Technologies

Idaho Falls (ID)

On-site

USD 90,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

United Global Technologies is seeking a skilled security data scientist to design, build, and tune detections using Splunk SPL and ES across diverse data sources. You will apply ML-based approaches with the AI Toolkit and DSDL to identify anomalies and threats.

The role requires collaboration with threat intel, incident response, and SOC teams to translate evolving threats into actionable detections, reduce false positives, and maintain detection-as-code workflows.

Qualifications

  • Deep expertise in Splunk SPL: advanced search, data models, performance tuning.
  • Hands-on Splunk ES experience: correlation searches, risk-based alerting, notable events, ES framework.
  • Experience with Splunk AI Toolkit (AITK) for ML-based detections.
  • Experience with Splunk App for Data Science and Deep Learning (DSDL) for custom models.
  • Strong MITRE ATT&CK framework knowledge and mapping of detections.
  • Familiarity with attack techniques and security data (EDR, network, cloud, identity).

Responsibilities

  • Design, develop, and maintain detection content using SPL to identify threats across diverse data sources.
  • Build and tune correlation searches, notable events, and risk-based alerting within Splunk Enterprise Security.
  • Leverage the DSDL app to develop machine learning models for anomaly detection and threat identification.
  • Apply the AITK and DSDL to create ML-driven detections beyond signatures.
  • Map detection coverage to MITRE ATT&CK and identify visibility gaps.
  • Collaborate with threat intelligence, IR, and SOC teams to translate threats into detections.
  • Reduce false positives and alert fatigue through tuning and lifecycle management.
  • Develop and maintain detection-as-code workflows with version control, testing, and CI/CD.
  • Create documentation, runbooks, and detection specifications for downstream analysts.

Skills

Splunk SPL
Splunk ES
AI Toolkit
DSDL
MITRE ATT&CK
EDR data
Network data
Cloud data
Identity data

Tools

Git
CI/CD

Job description

United Global Technologies is seeking a skilled security data scientist to design, build, and tune detections using Splunk SPL and ES across diverse data sources. You will apply ML-based approaches with the AI Toolkit and DSDL to identify anomalies and threats.

The role requires collaboration with threat intel, incident response, and SOC teams to translate evolving threats into actionable detections, reduce false positives, and maintain detection-as-code workflows.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Threat Detection Engineer (Onsite Idaho Falls)
Splunk Threat Detection Engineer (Onsite Idaho Falls)

Gilder Search Group • Idaho Falls (ID), Northern (KY)

Hybrid
USD 120,000 - 180,000
Senior Cyber Analyst: Splunk & ML Threat Detection
Senior Cyber Analyst: Splunk & ML Threat Detection

CRI Advantage • Idaho Falls (ID)

On-site
USD 110,000 - 124,000
Senior Splunk Cyber Threat Detection Engineer (ML)
Senior Splunk Cyber Threat Detection Engineer (ML)

CRI Advantage, Inc. • Idaho Falls (ID)

On-site
USD 110,000 - 170,000
Cyber Analyst current L, Q or TS mandatory
Cyber Analyst current L, Q or TS mandatory

Gilder Search Group • Idaho Falls (ID), Northern (KY)

Hybrid
USD 120,000 - 180,000
Cyber Analyst ISSO current L Q or TS mandatory
Cyber Analyst ISSO current L Q or TS mandatory

United Global Technologies • Idaho Falls (ID)

On-site
USD 90,000 - 150,000
Cyber Analyst- Level 3
Cyber Analyst- Level 3

CRI Advantage, Inc. • Idaho Falls (ID)

On-site
USD 110,000 - 170,000
Splunk SIEM Engineer: Detections & Dashboards (Hybrid)
Splunk SIEM Engineer: Detections & Dashboards (Hybrid)

Insight Global • Fulton (MD)

Hybrid
USD 120,000 - 180,000
Benefits from Day 1
Splunk Detection Engineer
Splunk Detection Engineer

DivIHN Integration Inc • United States

Remote
USD 100,000 - 130,000
Splunk SIEM Architect — Cybersecurity Ops Technologist
Splunk SIEM Architect — Cybersecurity Ops Technologist

Travelers • Atlanta (GA)

On-site
USD 99,000 - 163,000
Health Insurance
401(k) match
Paid Time Off
+1
Splunk Detection Engineer – SIEM Threat Analytics
Splunk Detection Engineer – SIEM Threat Analytics

Boston Government Services • Los Alamos (NM)

Hybrid
USD 120,000 - 180,000
Health Insurance
401K
Paid Vacation
+1