Enable job alerts via email!

Splunk Threat Content Developer – Cloud API Threat Detection (BHJOB22048_760)

ITmPowered

Seattle (WA)

Remote

USD 100,000 - 125,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a skilled Splunk Threat Content Developer to enhance their Cloud and API security capabilities. In this dynamic role, you will lead the development of threat detection content, focusing on emerging threats in cloud environments and APIs. Your expertise in Splunk, combined with your knowledge of OWASP and cloud security principles, will play a crucial role in safeguarding sensitive data and ensuring robust security measures. This remote position offers the opportunity to work collaboratively with a talented team across the United States, making a significant impact in the field of cybersecurity.

Qualifications

  • Strong experience in Splunk content development and building dashboards.
  • Familiarity with Cloud Security and Cloud Security Posture Management (CSPM).
  • Experience with automating tasks using various tools.

Responsibilities

  • Lead Splunk content development for Cloud and API Security threat use cases.
  • Engineer Splunk content for monitoring API traffic and remediation.
  • Develop dashboards for threat visibility and awareness.

Skills

Splunk
API Security
Cloud Security
OWASP
Python
Java
C++
Perl
HTML
CSS
Ansible

Education

Security certifications (GIAC/SANS, ISC(2), EC-Council)

Tools

SIEM solutions
Windows tools
Linux tools
CSPM
AD/AAD

Job description

Splunk Threat Content Developer – Cloud and API Threat Detection – Remote

The Splunk Threat Content Developer will develop, implement, and oversee content development for Threat Detection, Threat Analysis, and Threat Investigations focused on Cloud Security and API Security. Bring your Splunk Content Engineering in Threat Detection, Threat Analysis, Threat Investigation, and Splunk Security Analytics for Cloud (Azure, AWS, SaaS, IaaS, PaaS) as well as API Security / OWASP threats.

Responsibilities:

  • Lead Splunk content development focused on Threat (detection, analytics, investigation, and response) for Cloud Security (SaaS / IaaS / PaaS) and API Security (OWASP) threat use cases.
  • Focus on Cloud and API Threat Detection engineering, Content engineering, Splunk Enterprise Security, Cloud and API Security Threat content (OWASP, API Security, Cloud Security, and Healthcare security).
  • Develop and implement Custom Splunk content and dashboards for analysts on emerging Cloud/API threats.
  • Provide threat visibility and awareness for the Cyber Security organization for new security capabilities.
  • Engineer Splunk content for Cloud/API Security Threat Detection, alerting, dashboards, and IR runbooks, automation.
  • Develop Splunk Content for Cloud/API Security threat use cases (cloud, container, or orchestration misconfiguration, OWASP vulnerabilities, Injection Flaws, insecure network policies, logging & monitoring / runtime threats, CI/CD pipeline & supply chain flaws, cloud IAM roles, Account hijacking, Data exfiltration).
  • Cloud Identity Management, privileged access escalation, Key Management threat scenarios.
  • Engineer Splunk content to monitor continuously for anomalous API traffic and remediate threats in near real-time.
  • Engineer Splunk content for API Security Threat use cases (Broken authentication/access controls, security misconfigurations, automated threats, unsafe API consumption, Injection, request forgery, etc.)
  • Engineer cloud threat Splunk correlation searches which provide the alerting mechanisms used by the SOC.
  • Review newly ingested data sources for potential security alerts and create dashboards.

Qualifications, Skills, and Experience:

  • Splunk experience and certifications.
  • Strong experience in Splunk content development, building dashboards, reports, and lookup tables.
  • Experience with API Security, Cloud Security, and OWASP.
  • Familiarity with Cloud Security (Azure) and/or Cloud Security Posture Management (CSPM).
  • Programming experience (Splunk SPL, Python, Java, C++, Perl, HTML, CSS, Ansible, etc.).
  • Expertise in large scale cyber security data analytics, identifying data-driven threat collection opportunities.
  • Implementation, Operation, and/or Management of SIEM solutions.
  • Experience with common enterprise IT tools and logs (AD/AAD, IAM/MFA, CSPM, etc.).
  • Experience with Windows and Linux tools.
  • Security certifications (GIAC/SANS, ISC(2), EC-Council, etc.).
  • Experience with automating common repeatable tasks using a variety of tools and methods.
  • Information security analysis experience in a Cyber Security Operations Center (CSOC).

Soft Skills:

  • Ability to collaborate with others, leveraging many project approaches (Agile/Scrum, Waterfall, Gantt Charts).
  • Comfortable working remotely with team members around the country. Self-starter with intellectual curiosity.
  • Development of technical documents or presentations – IR/SOC threat runbooks.

LOGISTICS:

  • Work remotely anywhere in the Domestic US. Preferred locations: Colorado or Georgia.
  • COVID-19 Vaccine and Booster Required – OR must provide valid medical exemption from a doctor in advance.
  • Must be able to successfully pass a 12-panel drug screen, 10-year background check, and employment verification.
  • You will need to be a current US Citizen or valid Green Card holder. No need for visa now or in the future. This role is not able to offer visa transfer or sponsorship now or in the future.
  • W2 only – No sub vendors. Sponsorship NOT available.
  • Must have direct contact information on resume (phone/email) to be considered.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Splunk Threat Content Developer – Cloud API Threat Detection (BHJOB22048_760)

ITmPowered Consulting

Seattle

On-site

USD 80,000 - 120,000

12 days ago

Splunk Threat Content Developer – Cloud API Threat Detection (BHJOB22048_760)

ITmPowered

Denver

Remote

USD 90,000 - 150,000

30+ days ago

Splunk Threat Content Developer – Cloud API Threat Detection (BHJOB22048_760)

ITmPowered

Atlanta

Remote

USD 80,000 - 120,000

30+ days ago