Haystack
โ† Back to Jobs
Remote
Other
PT

Splunk SME_ Remote

Prudent Technologies and ConsultingUnited States๐Ÿ‡บ๐Ÿ‡ธUnited StatesPosted Sep 15, 2026

Why This Role Stands Out

Leverage your deep Splunk expertise in this remote role where you'll shape knowledge management and drive critical SIEM content engineering for a leading consulting firm. This opportunity is ideal for a seasoned Splunk professional with a strong background in detection engineering and a passion for developing robust, scalable solutions. Apply now to advance your career in a flexible, impactful environment.

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
1 week ago
SplunkAnsibleHIPAAKafkaLLMTerraform

Job Description

Splunk SME_ Remote

Contract

Required Qualifications'

  • Bachelor s degree in computer science, Information Systems, Cybersecurity, or equivalent professional experience
  • 5-8+ years of hands-on Splunk experience in enterprise environments
  • 3+ years of direct experience with Splunk knowledge management, CIM normalization, or SIEM content engineering in a large-scale deployment (20+ TB/day)
  • Deep expertise in Splunk Enterprise Security correlation search authoring, ES data models, risk-based alerting
  • Demonstrated experience managing knowledge object governance at scale across multi-team, multi-app Splunk environments
  • Strong proficiency in SPL including complex statistical pipelines, accelerated searches, and macro development
  • Experience developing and enforcing enterprise naming conventions and taxonomy standards for Splunk deployments
  • Proven ability to create and maintain technical documentation runbooks, standards guides, architecture documentation
  • Background in detection engineering, threat hunting, or SOC operations understanding of how knowledge objects serve analysts in practice

Preferred Qualification's

  • Splunk Certifications: Splunk Core Certified Consultant, Splunk Enterprise Security Certified Admin (SPLK-3001), Splunk Certified Architect one or more strongly preferred
  • Security Certifications: GIAC (GCIA, GCIH, GCED), or equivalent
  • Experience with Splunk SOAR (Phantom) playbook development, orchestration, and knowledge integration
  • Familiarity with Splunk UBA and behavioral analytics model management
  • Experience in healthcare or highly regulated industries (HIPAA, Federal (NIST), NYDFS, PCI)
  • Experience with infrastructure-as-code tools (Ansible, Terraform) for Splunk configuration management
  • Proficiency with LLM-powered tooling and AI-assisted automation for knowledge retrieval and content management
  • Experience supporting Splunk deployments in environments with 10,000+ users and multi-petabyte data retention
  • Familiarity with Kafka, streaming data pipelines, and real-time telemetry routing

Similar jobs