Splunk Security Detection Engineer

United Global Technologies

Idaho Falls (ID)

Remote

USD 120,000 - 190,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

United Global Technologies is seeking a highly skilled Splunk Security Engineer for an onsite role in Idaho Falls, ID. The candidate must hold current L, Q, or TS clearance and be willing to relocate.

You will design, build, and tune detections across diverse data sources using SPL, ES, DSDL, and AITK, aligning coverage to MITRE ATT&CK. Collaborating with threat intel, IR, and SOC teams, you will reduce alert fatigue, implement detection-as-code with Git/CI/CD, and develop runbooks and

Qualifications

  • Must have current, not active, DOE L, Q or TS clearance.
  • Willingness to relocate to Idaho Falls, ID and work onsite with no remote option.
  • Deep expertise in Splunk SPL, ES, DSDL, AITK, and MITRE ATT&CK mapping.
  • Experience with detection-as-code practices and CI/CD.
  • Prior SOC, threat hunting, or incident response experience preferred.

Responsibilities

  • Design, develop, and maintain detection content using Splunk SPL to identify threats across diverse data sources.
  • Build and tune correlation searches, notable events, and risk-based alerting within Splunk ES.
  • Leverage DSDL to develop ML models for anomaly detection and threat identification.
  • Use AITK to develop ML-driven detections beyond signatures.
  • Map detection coverage to MITRE ATT&CK and identify visibility gaps.
  • Collaborate with threat intel, IR, and SOC to translate threats into detections.
  • Reduce false positives through lifecycle management and tuning.
  • Develop and maintain detection-as-code workflows with Git/CI/CD.
  • Create runbooks, documentation, and detection specifications.

Skills

Splunk SPL
Splunk Enterprise Security
Splunk AI Toolkit
DSDL (Deep Learning)
MITRE ATT&CK
Threat hunting
Incident response
Threat detection

Education

Splunk certifications (Power User/Admin, ES Certified Admin)
GIAC certification

Tools

Git
CI/CD pipelines
SOAR platforms
Python

Job description

United Global Technologies is seeking a highly skilled Splunk Security Engineer for an onsite role in Idaho Falls, ID. The candidate must hold current L, Q, or TS clearance and be willing to relocate.

You will design, build, and tune detections across diverse data sources using SPL, ES, DSDL, and AITK, aligning coverage to MITRE ATT&CK. Collaborating with threat intel, IR, and SOC teams, you will reduce alert fatigue, implement detection-as-code with Git/CI/CD, and develop runbooks and

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk Threat Detection Engineer (Onsite Idaho Falls)
Splunk Threat Detection Engineer (Onsite Idaho Falls)

Gilder Search Group • Idaho Falls (ID), Northern (KY)

Hybrid
USD 120,000 - 180,000
Cyber Analyst current L, Q or TS mandatory
Cyber Analyst current L, Q or TS mandatory

Gilder Search Group • Idaho Falls (ID), Northern (KY)

Hybrid
USD 120,000 - 180,000
Senior Splunk Cyber Threat Detection Engineer (ML)
Senior Splunk Cyber Threat Detection Engineer (ML)

CRI Advantage, Inc. • Idaho Falls (ID)

On-site
USD 110,000 - 170,000
Cyber Analyst- Level 3
Cyber Analyst- Level 3

CRI Advantage, Inc. • Idaho Falls (ID)

On-site
USD 110,000 - 170,000
Telemetry Engineer
Telemetry Engineer

Openkyber • Alaska

On-site
USD 130,000 - 180,000
Splunk Detection Engineer
Splunk Detection Engineer

DivIHN Integration Inc • United States

Remote
USD 100,000 - 130,000
Senior Splunk Security Engineer — SIEM, Threat Intel & IR
Senior Splunk Security Engineer — SIEM, Threat Intel & IR

Unity Technologies Corporation • Columbus (OH)

On-site
USD 110,000 - 160,000
Senior Splunk SIEM Engineer — Threat Detection & Response
Senior Splunk SIEM Engineer — Threat Detection & Response

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Senior Splunk Engineer - On-site SIEM & Threat Detection
Senior Splunk Engineer - On-site SIEM & Threat Detection

Piper Companies • Newington (VA)

On-site
USD 175,000 - 195,000
PTO
Medical
Dental
+2
Remote Splunk Threat Detection Engineer
Remote Splunk Threat Detection Engineer

Openkyber • Alaska

On-site
USD 130,000 - 180,000