Enable job alerts via email!

Sr. Splunk Enterprise Security App Developer (Remote) (BHJOB22048_761)

ITmPowered

Denver (CO)

Remote

USD 90,000 - 150,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Sr. Splunk Enterprise Security App Developer to join their remote team. This role involves creating and integrating advanced Splunk applications to enhance security monitoring and compliance across critical enterprise systems. You will leverage your expertise in Splunk development, Python programming, and data modeling to deliver impactful solutions. Collaborating with a talented team using Agile methodologies, you will play a key role in identifying and mitigating cyber threats while ensuring data integrity. If you are passionate about cybersecurity and want to make a difference, this opportunity is perfect for you.

Qualifications

  • Active Splunk certification required with proficiency in Python.
  • Experience in developing Splunk applications and dashboards.

Responsibilities

  • Develop and support advanced Splunk Security applications.
  • Create custom Splunk apps for monitoring and compliance.

Skills

Splunk Enterprise Certified Architect
Python programming
Splunk development
Agile methodologies
JavaScript
CSS
Data modeling
Cyber security data analytics

Tools

Splunk SPL
Splunk SimpleXML

Job description

Sr. Splunk Enterprise Security App Developer (Remote) – ITmPowered

The Sr. Splunk Enterprise Security App Developer will develop, create, integrate, and support a highly advanced Splunk Security application (eSAR) developed internally to detect improper access to protected data by employees and malicious user activity. Develop Splunk Apps and add-ons in support of Security Access cyber threat monitoring, threat management, and data compliance across numerous business-critical enterprise applications. Work with Splunk Developers using Agile development methodologies.

RESPONSIBILITIES:

  • Advanced Splunk analytics and the development of custom Splunk applications.
  • Splunk data integrations with business-critical enterprise applications and systems.
  • Translating feedback from the business to Splunk technical requirements and solutions.
  • Develop specialized Splunk Security and Compliance applications, add-ons, data models, dashboards, and content using Python, Splunk SPL, Splunk SimpleXML (or JavaScript, CSS), and Bash.
  • Develop custom Splunk applications and Add-Ons for inclusion of access events per use case criteria.
  • Leverage modular design to onboard access/security logging applications and include in incident scoring.
  • Onboard access logging applications via modular design.
  • Develop Splunk risk scoring based on compliance conditions to determine suspicious access events.
  • Develop custom risk scoring to filter out white noise and show actionable incidents to SOC Analysts.
  • Develop dashboards for Security Analysts with detailed drill-down capability for incident response.
  • Develop triage workflows for analysts to assign and track ongoing investigations.
  • Develop summary indexing enrichment of access events with IAM data, application data, and Break-the-Glass logs.
  • Aggregate access event data for specific criteria.
  • Enable fast searching across fully enriched access events over long periods of time.
  • Develop Break-the-Glass correlations in Splunk for contextual user access/app data mapping and monitoring.

Skills and Experience:

  • Active Splunk Enterprise Certified Architect or Splunk Certified Developer – Required.
  • Splunk Core Certified Consultant – strongly preferred.

Required Experience: In addition to active Splunk certification(s), must also have practical experience with the following:

  • Proficiency in Python programming language.
  • Splunk SimpleXML or web development (JavaScript, CSS).
  • Splunk app & add-on development.
  • Splunk data modeling.
  • Strong experience in Splunk development, building dashboards, reports, and lookup tables.
  • Working knowledge of Splunk including SPL, indexers, forwarders, search heads.
  • Experience in OOAD, agile processes, and design patterns.
  • Expertise in large-scale cyber security data analytics, identifying data-driven threat collection opportunities.
  • Prior information security analysis experience in a Cyber Security Operations Center (CSOC).

Soft Skills:

  • Ability to collaborate with others, leveraging various project approaches (Agile/Scrum, Waterfall, Gantt Charts).
  • Comfortable working remotely with team members around the country. Self-starter with intellectual curiosity.
  • Development of technical documents or presentations – IR/SOC threat runbooks.

LOGISTICS:

  • Work remotely anywhere in the Domestic US. Preferred locations: Colorado or Georgia.
  • Contract role through the end of the year with potential for extension and/or conversion to permanent.
  • COVID-19 Vaccine and Booster Required – OR must provide valid medical exemption from a doctor in advance.
  • Must be able to successfully pass a 12-panel drug screen, 10-year background check, and employment verification.
  • You must be a current US Citizen or valid Green Card holder. No need for visa now or in the future. This role is not able to offer visa transfer or sponsorship now or in the future.
  • W2 only – No sub vendors. Sponsorship NOT available.
  • Must have direct contact information on resume (phone/email) to be considered.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Sr. Splunk Enterprise Security App Developer (Remote) (BHJOB22048_761)

ITmPowered Consulting

Atlanta

Remote

USD 80’000 - 120’000

10 days ago

Sr. Splunk Enterprise Security App Developer (Remote) (BHJOB22048_761)

ITmPowered Consulting

San Francisco

Remote

USD 80’000 - 130’000

9 days ago

Sr. Splunk Enterprise Security App Developer (Remote) (BHJOB22048_761)

ITmPowered

Atlanta

Remote

USD 90’000 - 150’000

30+ days ago

Sr. Splunk Enterprise Security App Developer (Remote) (BHJOB22048_761)

ITmPowered

San Francisco

Remote

USD 90’000 - 150’000

30+ days ago

Sr. Splunk Enterprise Security App Developer (Remote) (BHJOB22048_761)

ITmPowered

Remote

USD 90’000 - 150’000

30+ days ago