CRI Advantage

Cyber Analyst- Level 3

CRI Advantage$95K — $115K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in security analytics and data engineering
  • Current 'L' or 'Q' clearance is required
  • Expertise in Splunk SPL with advanced search and data optimization skills
  • Hands-on experience with Splunk Enterprise Security for risk-based alerting and correlation searches
  • Working knowledge of machine learning tools within the Splunk ecosystem
  • Familiarity with the MITRE ATT&CK framework and security data sources
  • Preferred experience in detection-as-code practices and Python programming

Responsibilities

  • Design and develop detection content in Splunk to identify security threats
  • Build and tune correlation searches and alerts in Splunk Enterprise Security
  • Utilize machine learning models for anomaly detection using Splunk MLTK
  • Map detection coverage to MITRE ATT&CK framework and identify visibility gaps
  • Collaborate with threat intelligence and SOC teams for actionable detection development
  • Manage detection tuning to reduce false positives and alert fatigue
  • Create documentation and runbooks to assist analysts

Benefits

  • Relocation assistance may be available for candidates moving to Idaho Falls, Idaho.
Full Job Description
Description

In this role, the selected candidate will design, build, and tune detections that identify malicious activity across our environment, working at the intersection of security analysis, data engineering, and machine learning.

We are looking for a candidate who lives and breathes Splunk and gets excited about turning raw telemetry into high-fidelity alerts.

Responsibilities
• Design, develop, and maintain detection content using Splunk Search Processing Language (SPL) to identify threats across diverse data sources.
• Build and tune correlation searches, notable events, and risk-based alerting within Splunk Enterprise Security (ES).
• Leverage the Splunk App for Data Science and Deep Learning (DSDL) to operationalize machine learning models for anomaly detection and advanced threat identification.
• Apply the Splunk App for Anomaly Detection and the Splunk AI Toolkit (AITK) to develop statistical and ML-driven detections that go beyond signature-based approaches.
• Map detection coverage to the MITRE ATT&CK framework and identify gaps in visibility.
• Collaborate with threat intelligence, incident response, and SOC teams to translate emerging threats into actionable detections.
• Reduce false positives and alert fatigue through continuous tuning and detection lifecycle management.
• Develop and maintain detection-as-code workflows, including version control, testing, and CI/CD for detection content.
• Create documentation, runbooks, and detection specifications to support downstream analysts.

Requirements
• Be willing to relocate to Idaho Falls, Idaho. (Relocation assistance may be available)
• Have a current "L" or "Q" clearance.
• Have the following required skillsets:

o Deep expertise in Splunk SPL, including advanced search commands, statistical functions, data models, and performance optimization.

o Hands-on experience with Splunk Enterprise Security, including correlation searches, risk-based alerting (RBA), notable events, and the ES framework.

o Working knowledge of the Splunk AI Toolkit (AITK) for building and applying ML-based detections.

o Experience with the Splunk App for Data Science and Deep Learning (DSDL), including custom model development and deployment.

o Strong understanding of the MITRE ATT&CK framework and detection engineering methodology.

o Familiarity with common attack techniques, log sources, and security data (EDR, network, cloud, identity, etc.).

Preferred Qualifications
• Experience with detection-as-code practices and tools (Git, CI/CD pipelines).
• Proficiency in Python for data processing and model development.
• Knowledge of SOAR platforms and detection automation.
• Relevant certifications (Splunk Certified Power User/Admin, Splunk Enterprise Security Certified Admin, GIAC, etc.).
• Prior experience in a SOC, threat hunting, or incident response role.

About CRI Advantage

CRI Advantage is an information technology company that provides IT solutions and services. The company was founded in 1988 and is headquartered in Reston, Virginia. CRI Advantage provides a range of IT services, including software development, data analytics, cloud computing, cybersecurity, and other services. CRI Advantage serves clients in the federal government, state and local government, and commercial sectors. CRI Advantage is a privately held company.
Learn more about CRI Advantage
Size
200 employees
Industry
Founded
1988

Similar Jobs

More Jobs at CRI Advantage

  • CRI Advantage
    Cyber Analyst- Level 3
    $95K — $115K *
    Idaho Falls, ID 83401 (Bonneville County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Cyber Analyst- Level 3 jobs: