Haystack
← Back to Jobs
Full time
Engineering
XS

Splunk Engineer

Xpt Software Australia PtyNew South Wales🇦🇺AustraliaPosted 8 Oct 2026

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
New South Wales, Australia

Job Description

Key
Responsibilities

  • Administer and maintain Splunk Enterprise
    Security (ES) environment.
  • Manage index lifecycle, retention policies, and
    storage optimization
  • Develop, optimize, and maintain correlation
    searches and use cases
  • Align detections with frameworks like MITRE
    ATT&CK
  • Create and enhance Splunk dashboards, reports,
    and alerts
  • Integrate new log sources and data inputs (cloud,
    network, endpoint, apps)
  • Normalize and onboard logs using CIM (Common
    Information Model)
  • Tune Data Models, tags, event types
  • Provide advanced support for incident
    investigations escalated from L1/L2
  • Conduct deep forensic analysis using Splunk data
  • Support incident response activities and root
    cause analysis
  • Work closely with SOC analysts to improve
    detection and response workflows
  • Integrate Splunk with SOAR platforms
  • Support API integrations with external security
    tools
  • Investigate issues with Data
    Ingestion/latency/inputs
  • Optimize queries and reduce search execution time
  • Maintain Splunk architecture documentation and
    SOPs
  • Support audits and reporting requirements
  • Conduct knowledge sharing and training for L1/L2
    analysts

Technical
Skills Required

Splunk
Expertise

  • Strong hands -on experience
    with:
    • Splunk Enterprise Security
      (ES)

Similar jobs