Haystack
← Back to Jobs
Remote
Technology

Contract W2 Only || Security Platform Engineer (SOC, Splunk, Cribl) || Remote

Noblesoft Technologies Inc.Raleigh, NC🇺🇸United StatesPosted 7 Aug 2026

Quick Overview

Work Type
Remote
Level
Mid Senior

Job Description

Role: Security Platform Engineer
Location: Remote

In USA

Mandatory: Splunk, Cribl

Preferred: Automation

 

Job Summary

We are seeking an experienced Security Platform Engineer with strong expertise in Splunk Enterprise/Enterprise Security, Cribl Stream, and Security Automation platforms. The ideal candidate will be responsible for designing, implementing, optimizing, and supporting enterprise-scale SIEM and log management platforms while enabling automation across SOC operations.

Key Responsibilities

  • Design, implement, and maintain Splunk Enterprise and Splunk Enterprise Security environments.
  • Deploy, configure, and manage Cribl Stream for log routing, filtering, masking, enrichment, and optimization.
  • Develop and maintain data onboarding pipelines from various security and infrastructure sources.
  • Configure and troubleshoot log ingestion, parsing, normalization, CIM mapping, and data models.
  • Optimize Splunk searches, dashboards, reports, and correlation searches for performance and scalability.
  • Build and maintain detection use cases, alerts, and security monitoring content.
  • Develop automation workflows using SOAR platforms such as Tines, Splunk SOAR, Cortex XSOAR, or similar automation tools.
  • Integrate security tools including Microsoft Defender, CrowdStrike, Palo Alto, Zscaler, Okta, Azure, AWS, and other enterprise technologies.
  • Perform troubleshooting of ingestion issues, parsing problems, search performance, and distributed architecture.
  • Work closely with SOC analysts, security engineers, architects, and infrastructure teams.
  • Implement best practices for platform monitoring, health checks, capacity planning, and upgrades.
  • Create technical documentation, SOPs, and operational runbooks.

Required Skills

  • 5+ years of hands-on experience with Splunk Enterprise.
  • Strong experience administering and supporting Splunk Enterprise Security (ES).
  • Hands-on experience with Cribl Stream administration and pipeline development.
  • Strong understanding of log onboarding, parsing, field extraction, normalization, and CIM.
  • Experience with Splunk Search Processing Language (SPL).
  • Experience with index management, forwarders, deployment server, search heads, indexers, and clustered environments.
  • Experience integrating cloud and security products with Splunk.
  • Knowledge of Linux administration and troubleshooting.
  • Experience with REST APIs and JSON.
  • Scripting experience using Python, PowerShell, or Bash.
  • Strong troubleshooting and analytical skills.

Preferred Skills

  • Experience with security automation platforms such as Tines, Splunk SOAR, Cortex XSOAR, Swimlane, or Torq.
  • Experience with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto, AWS, Azure, or Google Cloud Platform.
  • Knowledge of MITRE ATT&CK framework.
  • Familiarity with security operations and incident response workflows.
  • Experience with Git, CI/CD, and Infrastructure as Code.
  • Relevant certifications such as Splunk Core Certified Power User, Splunk Enterprise Certified Admin, Splunk Enterprise Security Certified Admin, Cribl Certified User/Admin, or security certifications such as CISSP or GIAC.

Nice to Have

  • Experience designing enterprise SIEM architectures.
  • Experience with threat detection engineering.
  • Experience implementing SOC automation and orchestration workflows.
  • Exposure to cloud-native security monitoring and observability platforms.

Skills

AWS
Splunk
Azure
Bash
Git
Google Cloud
PowerShell
Python
REST

Similar jobs