Haystack
← Back to Jobs
Technology
SG

Splunk Security Engineer

Skywalk GlobalRichmond, VA🇺🇸United StatesPosted Sep 24, 2026

Why This Role Stands Out

This Splunk Security Engineer role offers a fantastic opportunity to build and optimize cutting-edge security solutions within a reputable company, with hybrid flexibility enhancing your work-life balance. If you thrive on technical challenges, possess a strong understanding of Splunk Enterprise Security, and enjoy developing robust detection mechanisms, you'll find this position both rewarding and instrumental in advancing your career. Apply today to join a collaborative team and make a significant impact on global security.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Richmond, VA, United States
Posted
20 hours ago
Splunk

Job Description

ey Responsibilities

  • Design, implement, configure, and maintain Splunk Enterprise and Splunk Enterprise Security (ES) environments.
  • Onboard and integrate security logs and events from servers, applications, network devices, firewalls, endpoints, cloud platforms, and security tools.
  • Develop and maintain Splunk data models, indexes, sourcetypes, field extractions, CIM mappings, and ingestion pipelines.
  • Create and tune correlation searches, detection rules, notable events, risk-based alerts, and security use cases.
  • Develop security dashboards, reports, alerts, and operational monitoring solutions.
  • Develop and maintain Splunk ES security content supporting SOC monitoring and threat detection.
  • Analyze security events and identify suspicious activity, anomalies, and potential threats.
  • Work with SOC analysts to investigate and troubleshoot security incidents.
  • Tune alerts to reduce false positives while maintaining effective threat detection.
  • Integrate Splunk with security technologies such as EDR, firewalls, IDS/IPS, IAM, vulnerability management, cloud security, and threat intelligence platforms.
  • Develop automated workflows and integrations using Splunk SOAR where applicable.
  • Monitor Splunk infrastructure, troubleshoot indexing/search performance, and optimize system performance.
  • Configure and manage Universal Forwarders, Heavy Forwarders, indexers, and search heads.
  • Troubleshoot data ingestion, parsing, field extraction, search, and correlation issues.
  • Support Splunk upgrades, configuration changes, deployments, and production releases.
  • Develop and maintain technical documentation, architecture diagrams, runbooks, and operational procedures.
  • Collaborate with security architects, SOC teams, incident responders, and infrastructure teams to improve security monitoring capabilities.
  • Participate in incident response, threat hunting, and security investigations as required.
  • Ensure Splunk implementations follow organizational security, compliance, and logging standards.

Similar jobs