1d ago
Principal Splunk Threat Detection & Integration Engineer
US
โจ $160k-$200k / yearest.
full-timelead Remotecybersecurity
๐ Tech Stack
๐ผ About This Role
You'll lead the design and optimization of advanced threat detection capabilities within a Splunk Enterprise Security environment. Your work will strengthen cybersecurity posture through sophisticated detection logic, data integration, and risk-based alerting. This high-impact role offers deep technical ownership in a fast-moving security operations environment.
๐ฏ What You'll Do
- Own Splunk ES detection content lifecycle: design, development, validation, tuning.
- Architect and optimize Risk-Based Alerting (RBA) frameworks and risk scoring models.
- Design and optimize complex SPL queries for performance and accuracy.
- Lead cross-domain detection engineering across identity, cloud, network, and endpoint.
๐ Requirements
- 8+ years in security engineering, SOC/IR, or detection engineering.
- 5+ years with Splunk Enterprise Security in production environments.
- Deep expertise in SPL including advanced search optimization and REST API workflows.
- Proven experience designing Risk-Based Alerting (RBA) models in enterprise environments.
โจ Nice to Have
- Experience with SOAR platforms and automation.
- Exposure to threat intelligence feeds and TAXII/STIX.
- Previous mentorship or team leadership experience.
๐ Benefits & Perks
- ๐ต Competitive salary aligned with senior-level expertise.
- ๐ Fully remote work environment with flexibility.
- ๐ High-impact role with ownership over core detection engineering strategy.
- ๐ Professional growth including certifications and advanced development.
๐จ Hiring Process
Estimated timeline: 2-4 weeks ยท AI estimate
- 1Recruiter Screenยท 30 min
- 2Technical Interviewยท 60 min
- 3Hiring Manager Interviewยท 45 min
0 0 0