Tyto Athene, LLC

Senior SIEM Engineer - Splunk

Tyto Athene, LLC
Apply
7 days ago
Washington, DC, USASenior

Base Salary

$145k - $155k/yr

Responsibilities

  • Own Splunk architecture, including indexer and search head clustering, forwarder tiering, storage, retention, and SmartStore strategy.
  • Lead Splunk Enterprise Security detection engineering, correlation search development, threat hunting, and coverage strategy.
  • Establish standards for data onboarding, CIM normalization, field extraction, search performance, and platform scalability.
  • Drive Splunk upgrades, app and add-on management, integrations, and optimization of licensing and infrastructure costs.
  • Mentor SIEM engineers and SOC analysts on SPL, use-case design, investigations, and Splunk best practices.
  • Serve as the escalation point for complex investigations, distributed-environment issues, and major security incidents.
  • Own Splunk metrics and leadership reporting covering detection coverage, detection time, platform performance, and license efficiency.
  • Support audit, compliance, security architecture, and incident-response planning.

Requirements

  • Bachelor’s degree required, with equivalent experience and education permitted as a substitute.
  • Eight years of general work experience, including six years of relevant experience in security operations or detection engineering.
  • Substantial hands-on Splunk ownership, including experience with distributed or clustered environments.
  • Advanced SPL proficiency and deep knowledge of Splunk architecture and Splunk Enterprise Security.
  • Strong understanding of MITRE ATT&CK, the cyber kill chain, threat modeling, and detection strategy design.
  • Strong Python and PowerShell scripting or automation skills and familiarity with SOAR integrations.
  • Experience monitoring cloud security logs from AWS, Azure, or GCP and using Splunk cloud-specific add-ons.
  • Experience leading or significantly contributing to incident-response investigations and familiarity with relevant compliance frameworks.
  • Preferred certifications include Splunk Core Certified Advanced Power User, Splunk Certified Architect, Splunk Enterprise Security Certified Admin, GCIA, GCIH, GCFA, or CISSP.
  • Experience with Splunk in VMware ESXi and vCenter environments or with comparable SIEM tools is desired.
  • Active Top Secret clearance with SCI eligibility is required.

Benefits

  • Health, dental, and vision insurance.
  • 401(k) match, paid time off, short-term and long-term disability, and life insurance.
  • Referral bonuses, professional development reimbursement, and parental leave.
  • Onsite at the customer location in Washington, DC, five days per week, with some scheduling flexibility; core business hours are 8am–4pm.

Tech Stack

Categories

Tyto Athene, LLC

About Tyto Athene, LLC

501-1,000 employees
Contact me