Haystack
← Back to Jobs
Technology
AI

Splunk SIEM Engineer

ARK Infotech SpectrumSan Jose, CA🇺🇸United StatesPosted Sep 22, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
San Jose, CA, United States
Posted
21 hours ago

Job Description

Role: Splunk SIEM Engineer

Location - San Jose, CA

Role Summary: Client is seeking a SIEM Migration & Implementation Lead to drive the implementation and migration to a modern SaaS-based SIEM platform, including log onboarding, detection engineering, operational readiness, and SOC transition.

 

Key Responsibilities

·         Lead Splunk SIEM implementation and migration activities.

·         Design log collection, parsing, normalisation, and correlation architectures.

·         Migrate log sources, detections, dashboards, reports, and integrations.

·         Develop detection content, correlation rules, dashboards, and security analytics.

·         Write complex SIEM queries for investigations, detections, reporting, and threat hunting.

·         Onboard endpoint, firewall, DNS, identity, cloud, DLP, proxy, email, and application logs.

·         Support testing, cutover, go-live, and operational transition activities.

 

Required Experience

·         8–10 years of experience in SIEM Engineering, Security Monitoring, Detection Engineering, or Security Operations.

·         Proven experience leading enterprise SIEM migrations or greenfield deployments.

·         Strong hands-on experience with one or more SIEM platforms.

·         Strong expertise in SIEM query writing, dashboard development, correlation rule creation, and detection engineering.

·         Experience integrating and onboarding diverse enterprise security telemetry sources.

·         Strong scripting and automation experience (Python, PowerShell, APIs).

·         Strong understanding of MITRE ATT&CK and threat detection methodologies.

 

Success Criteria

·         Successful migration of log sources, detections, dashboards, and reporting.

·         Improved security visibility and detection coverage.

·         Smooth transition into steady-state SOC operations.

·         Splunk Experience is Must 

Similar jobs