
Senior SIEM Engineer - Splunk
Tyto Athene, LLC7 days ago
Washington, DC, USASenior
Base Salary
$145k - $155k/yr
Responsibilities
- Own Splunk architecture, including indexer and search head clustering, forwarder tiering, storage, retention, and SmartStore strategy.
- Lead Splunk Enterprise Security detection engineering, correlation search development, threat hunting, and coverage strategy.
- Establish standards for data onboarding, CIM normalization, field extraction, search performance, and platform scalability.
- Drive Splunk upgrades, app and add-on management, integrations, and optimization of licensing and infrastructure costs.
- Mentor SIEM engineers and SOC analysts on SPL, use-case design, investigations, and Splunk best practices.
- Serve as the escalation point for complex investigations, distributed-environment issues, and major security incidents.
- Own Splunk metrics and leadership reporting covering detection coverage, detection time, platform performance, and license efficiency.
- Support audit, compliance, security architecture, and incident-response planning.
Requirements
- Bachelor’s degree required, with equivalent experience and education permitted as a substitute.
- Eight years of general work experience, including six years of relevant experience in security operations or detection engineering.
- Substantial hands-on Splunk ownership, including experience with distributed or clustered environments.
- Advanced SPL proficiency and deep knowledge of Splunk architecture and Splunk Enterprise Security.
- Strong understanding of MITRE ATT&CK, the cyber kill chain, threat modeling, and detection strategy design.
- Strong Python and PowerShell scripting or automation skills and familiarity with SOAR integrations.
- Experience monitoring cloud security logs from AWS, Azure, or GCP and using Splunk cloud-specific add-ons.
- Experience leading or significantly contributing to incident-response investigations and familiarity with relevant compliance frameworks.
- Preferred certifications include Splunk Core Certified Advanced Power User, Splunk Certified Architect, Splunk Enterprise Security Certified Admin, GCIA, GCIH, GCFA, or CISSP.
- Experience with Splunk in VMware ESXi and vCenter environments or with comparable SIEM tools is desired.
- Active Top Secret clearance with SCI eligibility is required.
Benefits
- Health, dental, and vision insurance.
- 401(k) match, paid time off, short-term and long-term disability, and life insurance.
- Referral bonuses, professional development reimbursement, and parental leave.
- Onsite at the customer location in Washington, DC, five days per week, with some scheduling flexibility; core business hours are 8am–4pm.