Telemetry Engineer

Openkyber

Alaska

On-site

USD 130,000 - 180,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Openkyber is seeking a highly skilled security data scientist to design and tune Splunk-based detections across diverse data sources. You will build correlation searches, notable events, and risk-based alerts within Splunk Enterprise Security, while applying ML techniques via the DSDL and AI Toolkit to detect anomalies and threats.

The ideal candidate holds current security clearance and has hands-on SOC, threat hunting, and incident response experience, with a strong focus on reducing false

Qualifications

  • Requires current security clearance (L/UQ/Top Secret)
  • Deep Splunk SPL expertise with advanced searches and data models
  • Hands-on ES experience with correlation searches, risk-based alerting, notable events
  • Experience with Splunk AI Toolkit for ML-based detections
  • Experience with Splunk DSDL for model development and deployment
  • Strong MITRE ATT&CK mapping and detection coverage awareness
  • Familiarity with attack techniques, security data sources (EDR, cloud, identity)
  • Nice-to-have: SOAR platforms, detection automation, and related certifications

Responsibilities

  • Design, build, and tune detections using Splunk SPL across diverse data sources
  • Develop and optimize correlation searches, notable events, and risk-based alerts in ES
  • Leverage DSDL and AI Toolkit to create ML-based anomaly detections
  • Develop detections via the DSDL/DSDL app for model deployment
  • Map detection coverage to MITRE ATT&CK and identify visibility gaps
  • Collaborate with threat intel, IR, and SOC to translate threats into detections
  • Reduce false positives and alert fatigue through lifecycle management
  • Maintain detection-as-code workflows with versioning, testing, and CI/CD
  • Create documentation, runbooks, and specs for downstream analysts

Skills

Splunk SPL
Splunk ES
MITRE ATT&CK
Threat hunting
Anomaly detection
Detection engineering
Security analytics
Data modeling

Education

Splunk certification(s)
SIEM experience
GIAc/SOC applicable certs

Tools

DSDL
AITK
Splunk Enterprise Security
Git
CI/CD

Job description

Qualifying individual must have a current \"L\" or \"Q\" clearance OR Top Secret 100% REMOTE 3.

Qualifying individual \"MUST\" have the following skillsets :

  • Deep expertise in Splunk SPL, including advanced search commands, statistical functions, data models, and performance optimization
  • Hands-on experience with Splunk Enterprise Security, including correlation searches, risk-based alerting (RBA), notable events, and the ES framework
  • Working knowledge of the Splunk AI Toolkit (AITK) for building and applying ML-based detections
  • Experience with the Splunk App for Data Science and Deep Learning (DSDL), including custom model development and deployment
  • Strong understanding of the MITRE ATT&CK framework and detection engineering methodology
  • Familiarity with common attack techniques, log sources, and security data (EDR, network, cloud, identity, etc.)

Qualifying individual \"NICE\" to have the following skillsets :

  • Experience with detection-as-code practices and tools (Git, CI/CD pipelines)
  • Proficiency in Python for data processing and model development
  • Knowledge of SOAR platforms and detection automation
  • Relevant certifications (Splunk Certified Power User/Admin, Splunk Enterprise Security Certified Admin, GIAC, etc.)
  • Prior experience in a SOC, threat hunting, or incident response role

In this role, the selected candidate will design, build, and tune detections that identify malicious activity across our environment, working at the intersection of security analysis, data engineering, and machine learning. We're looking for a candidate that lives and breathes Splunk and gets excited about turning raw telemetry into high-fidelity alerts, we want to hear from you.

What the candidate is expected to perform:

  • Design, develop, and maintain detection content using Splunk Search Processing Language (SPL) to identify threats across diverse data sources
  • Build and tune correlation searches, notable events, and risk-based alerting within Splunk Enterprise Security (ES)
  • Leverage the Splunk App for Data Science and Deep Learning (DSDL) to develop machine learning models for anomaly detection and advanced threat identification
  • Apply the Splunk App for Anomaly Detection and the Splunk AI Toolkit (AITK) to develop statistical and ML-driven detections that go beyond signature-based approaches
  • Map detection coverage to the MITRE ATT&CK framework and identify gaps in visibility
  • Collaborate with threat intelligence, incident response, and SOC teams to translate emerging threats into actionable detections
  • Reduce false positives and alert fatigue through continuous tuning and detection lifecycle management
  • Develop and maintain detection-as-code workflows, including version control, testing, and CI/CD for detection content
  • Create documentation, runbooks, and detection specifications to support downstream analysts
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Analyst current L, Q or TS mandatory
Cyber Analyst current L, Q or TS mandatory

Gilder Search Group • Idaho Falls (ID), Northern (KY)

Hybrid
USD 120,000 - 180,000
Cyber Analyst- Level 3
Cyber Analyst- Level 3

CRI Advantage, Inc. • Idaho Falls (ID)

On-site
USD 110,000 - 170,000
Principal Splunk-Threat Detection & Integration Engineer
Principal Splunk-Threat Detection & Integration Engineer

Quzara LLC • United States

On-site
USD 120,000 - 160,000
Splunk Detection Engineer
Splunk Detection Engineer

DivIHN Integration Inc • United States

Remote
USD 100,000 - 130,000
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Senior SIEM Engineer (Splunk)
Senior SIEM Engineer (Splunk)

Quantum Sky • Washington

On-site
USD 140,000 - 210,000
Senior Software Engineer, Information Security
Senior Software Engineer, Information Security

COMMURE Incorporated • Mountain View (CA)

On-site
USD 130,000 - 160,000
SIEM/Detection Engineer
SIEM/Detection Engineer

Mantis Security Corporation • Reston (VA)

On-site
USD 140,000 - 190,000
Senior SIEM Engineer - Splunk
Senior SIEM Engineer - Splunk

Quantum Sky • Washington

On-site
USD 145,000 - 155,000
SITEC - Cyber Threat Detection Engineer - MacDill AFB
SITEC - Cyber Threat Detection Engineer - MacDill AFB

Peraton • Tampa (FL)

On-site
USD 110,000 - 170,000