Splunk / SOC Engineer

Zachary Piper Solutions

Northern (KY)

Hybrid

USD 100,000 - 120,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
401k
Paid Time Off
Holidays
Sick Leave

Job summary

Piper Companies is seeking a highly capable Splunk Engineer / SOC Engineer to advance enterprise security monitoring and analytics. This full-time role works with SOC analysts, cloud teams, and engineering stakeholders in a hybrid model with 2 days on-site per week.

The position requires a Secret clearance to be eligible, and candidates should bring 5+ years of SIEM engineering or incident response experience, strong Splunk expertise, and a track record of optimizing detections and dashboards.

Qualifications

  • 5+ years in SIEM engineering, security operations, or incident response environments.
  • Strong proficiency with Splunk, including writing complex SPL queries and dashboards.
  • Hands-on experience with data normalization, ingestion, and troubleshooting within Splunk Enterprise or Splunk ES.
  • Experience onboarding security data sources into a centralized SIEM.
  • Familiarity with cloud security services (AWS/Azure) integration.

Responsibilities

  • Develop and optimize Splunk detections, dashboards, and correlation searches.
  • Onboard, parse, normalize, and enrich security data into Splunk.
  • Troubleshoot ingestion, forwarder connectivity, indexing, and search performance issues.
  • Configure and maintain distributed Splunk environments.
  • Leverage data models to improve detection performance and reporting.
  • Collaborate with SOC and engineering teams to enhance threat detection and response workflows.
  • Participate in incident response investigations.

Skills

Splunk
SPL queries
SIEM engineering
Dashboarding
Incident response
Data normalization

Tools

Splunk ES

Job description

Piper Companies is seeking a highly Splunk Engineer / SOC Engineer to support the development and optimization of enterprise security monitoring and analytics within a fast-paced environment. This role plays a critical part in enhancing detection capabilities, improving security visibility, and driving operational efficiency through Splunk engineering and automation. This is a full-time opportunity working closely with SOC analysts, cloud teams, and engineering stakeholders hybrid 2 days a week onsite. This position requires a Secret clearance in order to be eligible.

Responsibilities for the Splunk Engineer include:
  • Developing, maintaining, and optimizing Splunk Security detections, dashboards, and correlation searches.
  • Onboarding, parsing, normalizing, and enriching diverse security data sources into Splunk.
  • Troubleshooting ingestion pipelines, forwarder connectivity, indexing issues, and search performance challenges.
  • Assisting with configuration, maintenance, and troubleshooting across distributed Splunk environments.
  • Leveraging data models and accelerated searches to improve detection performance and reporting efficiency.
  • Collaborating with SOC analysts and engineering teams to enhance threat detection, visibility, and response workflows.
  • Participating in incident response activities, including deep-dive investigations into security alerts.
Qualifications for the Splunk Engineer include:
  • Minimum of 5+ years of experience in SIEM engineering, security operations, or incident response environments.
  • Strong proficiency with Splunk, including writing complex SPL queries and building production-grade dashboards.
  • Hands-on experience with data normalization, ingestion, and troubleshooting within Splunk Enterprise or Splunk ES.
  • Experience integrating and onboarding security data sources into a centralized SIEM platform.
  • Familiarity with integrating tools such as AWS Security Hub or similar cloud-native security services.
  • Strong understanding of Splunk knowledge objects, field extractions, lookups, and CIM normalization.
  • Ability to perform effectively in high-pressure incident response situations and a willingness to participate in on-call rotations.
Compensation for the Splunk Engineer includes:
  • Salary range: $100,000 - $120,000
  • Comprehensive benefits package including Medical, Dental, Vision, 401k, PTO, holidays, and sick leave as required by law.

Keywords: Splunk Enterprise, Splunk Enterprise Security (ES), Splunk SOAR, SIEM Engineering, Security Information and Event Management, SIEM, SPL, Search Processing Language, Correlation Searches, detection engineering, security analytics, Data ingestion, data onboarding, data normalization, CIM, log parsing, field extractions, pipeline troubleshooting, Security operations center, SOC, incident response, threat detection, alert investigation, AWS, AWS security, AWS security hub, Azure security, Entra ID, Azure AD, distributed splunk environment, forwarders

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk / SOC Engineer
Splunk / SOC Engineer

Zachary Piper Solutions • North Carolina

Hybrid
USD 100,000 - 120,000
Comprehensive benefits package
Hybrid Splunk & SOC Engineer — Detection & Analytics
Hybrid Splunk & SOC Engineer — Detection & Analytics

Zachary Piper Solutions • Northern (KY)

Hybrid
USD 100,000 - 120,000
Medical Insurance
Dental Insurance
Vision Insurance
+4
Senior Splunk & SOC Engineer (Hybrid, Secret Clearance)
Senior Splunk & SOC Engineer (Hybrid, Secret Clearance)

Zachary Piper Solutions • North Carolina

Hybrid
USD 100,000 - 120,000
Comprehensive benefits package
SIEM Engineer
SIEM Engineer

Piper Companies • Raleigh (NC)

Hybrid
USD 115,000 - 135,000
Splunk Engineer
Splunk Engineer

Piper Companies • Durham (NC)

On-site
USD 150,000 - 170,000
Comprehensive benefits package
401(k)
PTO
+1
Security Engineer (Splunk & Automation)
Security Engineer (Splunk & Automation)

Piper Companies • Durham (NC)

On-site
USD 83,000 - 91,000
Splunk SIEM Engineer - Hybrid (RTP) with SOC & AWS
Splunk SIEM Engineer - Hybrid (RTP) with SOC & AWS

Zachary Piper Solutions • Raleigh (NC)

Hybrid
USD 105,000 - 120,000
Health benefits
Dental
Vision
+2
SIEM Engineer
SIEM Engineer

Zachary Piper Solutions • Raleigh (NC), Northern (KY)

On-site
USD 105,000 - 120,000
Health benefits
Dental
Vision
+2
SOC Engineer
SOC Engineer

Piper Companies • Raleigh (NC)

On-site
USD 120,000 - 145,000
Medical, dental, and vision insurance
401K
Paid time off
Splunk Engineer/Architect
Splunk Engineer/Architect

Piper Companies • Morrisville (NC)

On-site
USD 140,000 - 180,000
Comprehensive benefits