Contract W2 Only || Security Platform Engineer (SOC, Splunk, Cribl) || Remote
Quick Overview
Job Description
Role: Security Platform Engineer
Location: Remote
In USA
Mandatory: Splunk, Cribl
Preferred: Automation
Job Summary
We are seeking an experienced Security Platform Engineer with strong expertise in Splunk Enterprise/Enterprise Security, Cribl Stream, and Security Automation platforms. The ideal candidate will be responsible for designing, implementing, optimizing, and supporting enterprise-scale SIEM and log management platforms while enabling automation across SOC operations.
Key Responsibilities
- Design, implement, and maintain Splunk Enterprise and Splunk Enterprise Security environments.
- Deploy, configure, and manage Cribl Stream for log routing, filtering, masking, enrichment, and optimization.
- Develop and maintain data onboarding pipelines from various security and infrastructure sources.
- Configure and troubleshoot log ingestion, parsing, normalization, CIM mapping, and data models.
- Optimize Splunk searches, dashboards, reports, and correlation searches for performance and scalability.
- Build and maintain detection use cases, alerts, and security monitoring content.
- Develop automation workflows using SOAR platforms such as Tines, Splunk SOAR, Cortex XSOAR, or similar automation tools.
- Integrate security tools including Microsoft Defender, CrowdStrike, Palo Alto, Zscaler, Okta, Azure, AWS, and other enterprise technologies.
- Perform troubleshooting of ingestion issues, parsing problems, search performance, and distributed architecture.
- Work closely with SOC analysts, security engineers, architects, and infrastructure teams.
- Implement best practices for platform monitoring, health checks, capacity planning, and upgrades.
- Create technical documentation, SOPs, and operational runbooks.
Required Skills
- 5+ years of hands-on experience with Splunk Enterprise.
- Strong experience administering and supporting Splunk Enterprise Security (ES).
- Hands-on experience with Cribl Stream administration and pipeline development.
- Strong understanding of log onboarding, parsing, field extraction, normalization, and CIM.
- Experience with Splunk Search Processing Language (SPL).
- Experience with index management, forwarders, deployment server, search heads, indexers, and clustered environments.
- Experience integrating cloud and security products with Splunk.
- Knowledge of Linux administration and troubleshooting.
- Experience with REST APIs and JSON.
- Scripting experience using Python, PowerShell, or Bash.
- Strong troubleshooting and analytical skills.
Preferred Skills
- Experience with security automation platforms such as Tines, Splunk SOAR, Cortex XSOAR, Swimlane, or Torq.
- Experience with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto, AWS, Azure, or Google Cloud Platform.
- Knowledge of MITRE ATT&CK framework.
- Familiarity with security operations and incident response workflows.
- Experience with Git, CI/CD, and Infrastructure as Code.
- Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Cribl Certified User/Admin, or security certifications such as CISSP or GIAC.
Nice to Have
- Experience designing enterprise SIEM architectures.
- Experience with threat detection engineering.
- Experience implementing SOC automation and orchestration workflows.
- Exposure to cloud-native security monitoring and observability platforms.
Skills
Similar jobs
Senior Data Platform Engineer
NuAxis LLC · Washington, United States
9 minutes ago.NET Application Support / DevOps
BCforward · Charlotte, United States
9 minutes ago$65/hrCloud/DevOps Engineer - III
SGS Consulting · San Francisco, United States
10 minutes agoL2 Operations Support Engineer (Cloud & DevOps)
KONNECTINGTREE INC · United States
10 minutes agoSr. DevSecOps Engineer (Hybrid Remote/On-site) with Security Clearance
TEKsystems c/o Allegis Group · Raleigh, United States
31 minutes agoSRE Engineer
UnivEdge Consulting LLC · United States
32 minutes ago