Splunk UBA Engineer

Jobs via Dice

Doral (FL)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading provider in technical talent is seeking a Splunk UBA Engineer for an 8-week onsite contract in Doral, FL. This role involves implementing and optimizing a User Behavior Analytics platform to identify and manage potential security threats. The ideal candidate will have strong analytical skills and meaningful experience in security analytics to effectively turn user data into actionable intelligence.

Qualifications

  • 2–4 years of experience in security engineering or analytics.
  • Hands-on experience with Splunk UBA and threat detection.
  • Ability to write documentation and communicate findings effectively.

Responsibilities

  • Deploy, configure, and maintain the Splunk UBA platform.
  • Develop and refine behavioral baselines to identify suspicious activity.
  • Integrate UBA with Splunk Enterprise Security for automated response.

Skills

Security engineering
Threat detection
Log analysis
Behavior-based threat detection
Machine learning
Scripting

Education

Splunk Core Certified Power User
Splunk UBA Certified Admin

Job description

1 week ago Be among the first 25 applicants

Dice is the leading career destination for tech experts at every stage of their careers. Our client, Catapult Solutions Group, is seeking the following. Apply via Dice today!

Splunk UBA Engineer

Onsite | Doral, FL

8 Week Contract

MUST HAVE SECRET CLEARANCE

FOR IMMEDIATE CONSIDERATION, please complete the virtual interview: https://dashboard.catapultsg.com/job/splunk-uba-engineer

We are seeking an experienced and analytical Splunk UBA Engineer to implement, optimize, and maintain our User Behavior Analytics (UBA) platform. In this role, you will use behavioral modeling and machine learning capabilities in Splunk UBA to identify insider threats, compromised accounts, data exfiltration, and other advanced attack techniques. You will work closely with SOC analysts, engineers, and data owners to turn user activity data into actionable intelligence and risk-based threat detections.

Key Responsibilities:

  • Deploy, configure, and maintain the Splunk UBA platform, including data ingestion, normalization, and threat model tuning.
  • Deploy UBA cluster designing the build
  • Ingest and map logs from various sources (e.g., Active Directory, VPN, firewalls, proxy, endpoint, etc.) into UBA.
  • Develop and refine behavioral baselines and anomaly detection models to identify suspicious or malicious activity.
  • Tune and customize threat models to align with organizational risks and reduce false positives.
  • Collaborate with the SOC and threat detection teams to operationalize UBA detections through risk scoring, notable events, and incident response workflows.
  • Build and maintain dashboards, entity timelines, and investigative tools within UBA to support threat hunting and investigations.
  • Integrate UBA output with Splunk Enterprise Security (ES) or SOAR platforms for automated response and triage.
  • Continuously evaluate new data sources, use cases, and detection strategies to enhance UBA capabilities.
  • Document procedures, configurations, and threat model customizations.

Qualifications

  • 2–4 years of experience in security engineering, threat detection, or security analytics.
  • Hands-on experience with Splunk UBA and a strong understanding of behavior-based threat detection.
  • Proficiency in log analysis and understanding of common data sources (AD, EDR, firewalls, VPN, etc.).
  • Knowledge of machine learning basics, anomaly detection, and risk-based scoring concepts.
  • Strong grasp of attack vectors such as lateral movement, privilege escalation, and insider threats.
  • Ability to write clear documentation and communicate findings effectively. Preferred:
  • Experience with Splunk Enterprise Security (ES) and/or SOAR integrations.
  • Familiarity with MITRE ATT&CK and threat detection frameworks.
  • Background in scripting (Python, PowerShell) and API-based data integrations.
  • Splunk certifications such as Splunk Core Certified Power User or Splunk UBA Certified Admin.

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Engineering and Information Technology
  • Industries
    Software Development

Referrals increase your chances of interviewing at Jobs via Dice by 2x

Sign in to set job alerts for “Engineer” roles.
Engineer-General Maintenance-Full Time *$500 Sign-on Bonus
Engineer - Railway Operations & Maintenance (Relocation Offered)
Quality Engineer: Continuous Improvement

Hialeah, FL $80,000.00-$110,000.00 5 days ago

Hialeah, FL $105,000.00-$115,000.00 4 weeks ago

Miami, FL $105,000.00-$115,000.00 4 weeks ago

Hialeah, FL $90,000.00-$110,000.00 1 week ago

Miami, FL $85,196.00-$106,495.00 1 day ago

Development Review Services Engineering Manager - PE

Hialeah, FL $95,000.00-$110,000.00 5 days ago

1st Shift - Part Time - As Needed - Building Engineer

Hollywood, FL $90,000.00-$110,000.00 1 month ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk SOAR Engineer
Splunk SOAR Engineer

Jobs via Dice • Doral (FL)

On-site
USD 80,000 - 110,000
Sr. Security Engineer
Sr. Security Engineer

Restaurant Brands International • Miami (FL)

On-site
USD 104,000 - 190,000
Comprehensive global paid parental leave
Free telemedicine and mental wellness support
Splunk Enterprise Security Engineer
Splunk Enterprise Security Engineer

CBC • Great Falls Crossing (VA)

On-site
USD 122,000 - 140,000
Medical insurance
Vision insurance
ADF Developer
ADF Developer

INSPYR Solutions • Coral Gables (FL)

On-site
Comprehensive medical benefits
401(k) retirement plan
Competitive pay
IBM MDM - Senior Programmer/Developer
IBM MDM - Senior Programmer/Developer

E-Solutions • United States

On-site
USD 100,000 - 720,000
Senior DevOps Engineer (Ref: 184996)
Senior DevOps Engineer (Ref: 184996)

Forsyth Barnes • Miami (FL)

On-site
USD 120,000 - 200,000
Medical insurance
Vision insurance
401(k)
Senior QA Engineer
Senior QA Engineer

ESB Technologies • Doral (FL)

On-site
USD 80,000 - 100,000
Splunk Security Engineer
Splunk Security Engineer

Zotec Partners • Carmel (IN)

On-site
USD 55,000 - 85,000
Splunk Traveling Engineer (Secret) DC, MD, VA
Splunk Traveling Engineer (Secret) DC, MD, VA

August Schell • Rockville (MD)

On-site
USD 75,000 - 160,000
Health insurance
Retirement savings plans
Paid time off
+1
Seasoned Security Engineer | Application Penetration Tester
Seasoned Security Engineer | Application Penetration Tester

Summit Security Group • United States

On-site
USD 100,000 - 720,000
Continuous learning and development opportunities
Collaborative team environment
Contribution to meaningful client success