Splunk ES Engineer

Openkyber

Alaska

On-site

USD 85,000 - 120,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Openkyber seeks a security operations professional to monitor networks, endpoints, and cloud events, and to refine detection with Splunk searches and dashboards.

You will develop use cases from threat intel, onboard diverse data sources, and support audit readiness while collaborating with IT and security teams to respond to incidents.

Qualifications

  • Experience configuring and tuning SIEM platforms such as Splunk.
  • Ability to develop detection logic and alerts from threat intel.
  • Familiarity with incident response lifecycle and forensics.

Responsibilities

  • Threat Detection & Monitoring: Continuously monitor network traffic, endpoint logs, and cloud security events for anomalous behavior and potential security incidents.
  • Splunk Management: Create, maintain, and tune Splunk correlation searches, alerts, and dashboards to minimize false positives and improve detection capabilities.
  • Incident Response: Investigate potential security incidents, follow forensic evidence, and collaborate with IT and network teams to remediate threats.
  • Use Case Development: Develop and refine detection and response playbooks based on threat intelligence and frameworks like MITRE ATT&CK.
  • Log Integration: Work with infrastructure teams to onboard new data sources, ensuring log integrity, parsing, and normalization across the SIEM platform.
  • Compliance & Reporting: Support audit readiness by collecting SIEM control evidence and generating compliance reports aligned with internal policies and standards.

Skills

Threat detection
Incident response
Security monitoring
Log analysis
Threat intelligence

Tools

Splunk
SIEM

Job description

Key Responsibilities:
  • Threat Detection & Monitoring: Continuously monitor network traffic, endpoint logs, and cloud security events for anomalous behavior and potential security incidents.
  • Splunk Management: Create, maintain, and tune Splunk correlation searches, alerts, and dashboards to minimize false positives and improve detection capabilities.
  • Incident Response: Investigate potential security incidents, follow forensic evidence, and collaborate with IT and network teams to remediate threats.
  • Use Case Development: Develop and refine detection and response playbooks based on threat intelligence and frameworks like MITRE ATT&CK.
  • Log Integration: Work with infrastructure teams to onboard new data sources, ensuring log integrity, parsing, and normalization across the SIEM platform.
  • Compliance & Reporting: Support audit readiness by collecting SIEM control evidence and generating compliance reports aligned with internal policies and standards.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Engineer With Splunk
Data Engineer With Splunk

Veriipro • Quincy (MA)

On-site
USD 100,000 - 130,000
Splunk Detection Engineer
Splunk Detection Engineer

DivIHN Integration Inc • United States

Remote
USD 100,000 - 130,000
Splunk Dashboard Engineer
Splunk Dashboard Engineer

Veriipro • Morrisville (NC)

On-site
USD 110,000 - 150,000
Splunk SIEM Engineer: Security Monitoring & Automation
Splunk SIEM Engineer: Security Monitoring & Automation

Jobtailor • New York (NY)

On-site
USD 120,000 - 160,000
Cyber Analyst- Level 3
Cyber Analyst- Level 3

CRI Advantage • Idaho Falls (ID)

On-site
USD 110,000 - 170,000
Splunk Enterprise Security (ES) Consultant - remote
Splunk Enterprise Security (ES) Consultant - remote

System One • Town of Arlington (WI)

Remote
USD 100,000 - 140,000
Splunk Engineer
Splunk Engineer

RapidSoft Corp • Reston (VA)

On-site
USD 90,000 - 120,000
Splunk Security Engineer — SIEM & ES Lead
Splunk Security Engineer — SIEM & ES Lead

SOFtact Solutions • Virginia (MN), Fayetteville (NC)

On-site
USD 90,000 - 120,000
Splunk Engineer - Consultant Certified / ES Accreditation Required (R-00062)
Splunk Engineer - Consultant Certified / ES Accreditation Required (R-00062)

Truezerotech • Annapolis (MD)

On-site
USD 100,000 - 130,000
Competitive salary, paid twice per month
100% of medical premiums covered
3 weeks of PTO starting + 11 paid holidays annually
+2
Senior Splunk SIEM Engineer — Threat Detection & Response
Senior Splunk SIEM Engineer — Threat Detection & Response

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000