Sr Splunk Detection Engineer

Cherokee Federal

Almont (CO)

On-site

USD 150,000 - 160,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical
Dental
Vision
401(k)

Job summary

Criterion Systems, a Cherokee Federal company, seeks a Senior Splunk Detection Engineer to enhance SOC effectiveness through high-fidelity detections and Risk-Based Alerting. You will collaborate across SOC, Cloud, and IR teams to build scalable detection capabilities, reduce false positives, and improve analyst efficiency.

The role emphasizes hands-on design of Splunk ES content, cloud detections, and strong knowledge of MITRE ATT&CK, with opportunities to contribute to future SOAR automation

Qualifications

  • 7+ years cybersecurity experience, incl. 4+ years in Detection Engineering/SEC.
  • Experience building and tuning Splunk Enterprise Security correlation searches.
  • Hands-on Risk-Based Alerting (RBA) implementation experience.
  • Incident Response experience or close IR partnership.
  • Strong knowledge of MITRE ATT&CK.
  • Experience improving detection fidelity and reducing false positives.
  • Strong AWS security knowledge (GuardDuty, CloudTrail, Security Hub, IAM, EC2, S3, VPC logs).
  • Proficiency with SPL, Python, REST APIs, and Git.
  • Experience developing Splunk dashboards, reports, and investigations.
  • Excellent written and verbal communication skills.

Responsibilities

  • Design, build, test, and improve Splunk ES detection content.
  • Develop and tune correlation searches, notable events, dashboards, and investigation workflows.
  • Implement and optimize Risk-Based Alerting (RBA) strategies.
  • Improve detection quality while reducing false positives/negatives.
  • Map detections to MITRE ATT&CK and maintain coverage metrics.
  • Collaborate with Incident Response to translate incidents into better content.
  • Engage in threat hunting, investigations, tabletop exercises, and purple team activities.
  • Develop cloud detections using AWS telemetry (GuardDuty, CloudTrail, Security Hub, IAM, EC2, S3, VPC logs).
  • Maintain CIM compliance and data normalization.
  • Measure detection quality via precision, recall, MTTR, workload reduction.
  • Support Splunk SOAR automation initiatives and integrations with ServiceNow.

Skills

SPL
Python
REST APIs
Git
MITRE ATT&CK
Incident Response
Threat Detection
Cloud Security

Tools

Splunk Enterprise Security
Splunk SOAR (Phantom)
ServiceNow Incident Response
AWS GuardDuty
CloudTrail

Job description

Senior Splunk Detection Engineer

Criterion Systems, a Cherokee Federal company, is seeking a Senior Splunk Detection Engineer to support the National Science Foundation (NSF) Cybersecurity & Privacy Program. This hands-on Detection Engineering role is responsible for improving Security Operations Center (SOC) effectiveness through high-fidelity detections, Risk-Based Alerting (RBA), alert tuning, incident response collaboration, and future security automation initiatives. The successful candidate will partner closely with Security Operations, Incident Response, Cloud Engineering, and Vulnerability Management teams to build scalable detection capabilities that reduce false positives, improve analyst efficiency, and strengthen NSF's cybersecurity posture.


Compensation & Benefits

Estimated Starting Salary Range for Senior Splunk Detection Engineer: $150,000–$160,000. Pay commensurate with experience. Full-time benefits include Medical, Dental, Vision, 401(k), and other possible benefits as provided. Benefits are subject to change with or without notice.


Senior Splunk Detection Engineer Responsibilities Include


  • Design, build, test, and continuously improve Splunk Enterprise Security detection content.

  • Develop and tune correlation searches, notable events, adaptive response actions, dashboards, and investigation workflows.

  • Implement and optimize Risk-Based Alerting (RBA) strategies.

  • Improve detection quality while reducing false positives and minimizing false negatives.

  • Map detections to the MITRE ATT&CK Framework and maintain coverage metrics.

  • Partner with Incident Response teams to convert real-world incidents into improved detection content.

  • Participate in threat hunting, incident investigations, tabletop exercises, and purple team activities.

  • Develop cloud detections leveraging AWS GuardDuty, CloudTrail, Security Hub, IAM, EC2, S3, VPC Flow Logs, and related telemetry.

  • Maintain Common Information Model (CIM) compliance and improve data normalization.

  • Measure detection quality through precision, recall, MTTR, and analyst workload reduction.

  • Support future Splunk SOAR (Phantom) automation initiatives.

  • Integrate Splunk Enterprise Security with ServiceNow Incident Response and other security technologies.

  • Collaborate with Security Operations, Cloud Engineering, Vulnerability Management, and Incident Response teams.

  • Performs other job-related duties as assigned.


Senior Splunk Detection Engineer Experience, Education, Skills, Abilities Requested


  • Active Public Trust clearance or the ability to obtain one.

  • Minimum seven (7) years of cybersecurity experience, including four (4) years in Detection Engineering, Security Operations, Incident Response, or Splunk Enterprise Security.

  • Experience building and tuning Splunk Enterprise Security correlation searches.

  • Hands-on Risk-Based Alerting (RBA) implementation experience.

  • Practical Incident Response experience or close partnership with IR teams.

  • Strong understanding of MITRE ATT&CK.

  • Experience improving detection fidelity and reducing false positives.

  • Strong AWS security knowledge including GuardDuty, CloudTrail, Security Hub, IAM, EC2, S3, and VPC Flow Logs.

  • Proficiency with SPL, Python, REST APIs, and Git.

  • Experience developing Splunk dashboards, reports, and investigations.

  • Excellent written and verbal communication skills.

  • Preferred:

    • Splunk Enterprise Security certifications

    • Splunk SOAR (Phantom)

    • Detection-as-Code

    • Sigma and YARA

    • CrowdStrike or Microsoft Defender for Endpoint

    • ServiceNow Incident Response

    • Knowledge of FISMA, NIST RMF, FedRAMP, and CMMC



  • Must pass pre-employment qualifications of Cherokee Federal.


Company Information

Criterion Systems, a Cherokee Federal company, provides innovative cybersecurity, cloud, digital transformation, and IT solutions supporting federal government customers. As part of Cherokee Federal, Criterion Systems delivers mission-focused technology services while providing employees with opportunities for professional growth and meaningful impact.


#CherokeeFederal # AppC


Cherokee Federal is a military-friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.


Similar Searchable Job Titles


  • Senior Detection Engineer

  • Splunk Detection Engineer

  • Splunk Enterprise Security Engineer

  • Cyber Detection Engineer

  • Security Operations Engineer

  • SIEM Engineer

  • Threat Detection Engineer

  • SOC Detection Engineer

  • Cybersecurity Engineer

  • Security Analytics Engineer


Keywords


  • Splunk Enterprise Security

  • Splunk ES

  • Detection Engineering

  • Risk-Based Alerting

  • RBA

  • SIEM

  • MITRE ATT&CK

  • Incident Response

  • Threat Hunting

  • AWS Security

  • GuardDuty

  • CloudTrail

  • Security Hub

  • Python

  • SPL

  • SOAR

  • Phantom

  • ServiceNow

  • Sigma

  • YARA

  • CrowdStrike

  • Microsoft Defender

  • FedRAMP

  • NIST RMF

  • FISMA

  • CMMC

  • Public Trust


Legal Disclaimer

Cherokee Federal is an equal opportunity employer. Please visit cherokee-federal.com/careers for information regarding our Aff... Many positions require access to government facilities or military installations.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Splunk Detection Engineer
Sr Splunk Detection Engineer

Cherokee Federal • Glenpool (OK)

On-site
USD 150,000 - 160,000
Medical benefits
Dental benefits
Vision benefits
+1
Sr Splunk Detection Engineer
Sr Splunk Detection Engineer

Cherokee Federal • United States

On-site
USD 150,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+1
Senior Splunk Detection Engineer Threat Detection & RBA Lead
Senior Splunk Detection Engineer Threat Detection & RBA Lead

Cherokee Federal • Almont (CO)

On-site
USD 150,000 - 160,000
Medical
Dental
Vision
+1
Principal Splunk-Threat Detection & Integration Engineer
Principal Splunk-Threat Detection & Integration Engineer

Quzara LLC • United States

On-site
USD 120,000 - 160,000
Cyber Security Engineer (Cyber Implementation)
Cyber Security Engineer (Cyber Implementation)

Cherokee Federal • Springfield (VA)

On-site
USD 150,000 - 155,000
Medical
Dental
Vision
+1
Detection Engineer / Splunk Content Developer
Detection Engineer / Splunk Content Developer

TopClearedRecruiting • McLean (VA)

On-site
USD 100,000 - 130,000
Full Medical Coverage
Quarterly Performance Bonuses
Education Reimbursement
+3
Cyber Security Engineer
Cyber Security Engineer

Career Listings • Columbus (OH)

On-site
USD 130,000 - 170,000
Senior Splunk Detection Engineer: RBA & Threat Hunting
Senior Splunk Detection Engineer: RBA & Threat Hunting

Cherokee Federal • United States

On-site
USD 150,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+1
TS/SCI Splunk Engineer — Mission-Critical Analytics
TS/SCI Splunk Engineer — Mission-Critical Analytics

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Attractive bonus plan
Senior Software Engineer, Information Security
Senior Software Engineer, Information Security

COMMURE Incorporated • Mountain View (CA)

On-site
USD 130,000 - 160,000