We are seeking a highly experienced Principal Security Engineer to lead Splunk engineering and onboarding efforts across acquired entities. This role will serve as the Splunk Subject Matter Expert (SME) and play a critical leadership role in integrating newly acquired environments into the enterprise security monitoring ecosystem.
The ideal candidate blends deep technical expertise in Splunk infrastructure with strong program leadership, ensuring scalable log ingestion, normalization, and operational excellence across diverse environments.
You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.
Primary Responsibilities:- Splunk Engineering & SME Leadership
- Serve as the primary Splunk SME, providing architecture guidance, troubleshooting support, and strategic direction
- Design, build, and optimize enterprise-scale Splunk infrastructure (indexers, search heads, forwarders, clustering, and cloud/hybrid deployments)
- Define standards, best practices, and governance for Splunk usage, data onboarding, and content development
- Lead performance tuning, capacity planning, and cost optimization initiatives
- Acquisition Integration & Log Onboarding
- Lead onboarding of logs from newly acquired entities into Splunk, including:
- Log source identification and prioritization
- Data ingestion architecture design
- Field extraction, parsing, and normalization
- Partner with acquisition teams, IT, and security stakeholders to ensure timely and complete visibility
- Develop repeatable onboarding playbooks and integration frameworks for rapid scaling
- Ensure alignment with enterprise security use cases, compliance requirements, and detection strategies
- Security Data Engineering & Operations
- Implement and maintain secure, reliable log pipelines across cloud, on-prem, and SaaS environments
- Ensure high availability and resilience of Splunk services
- Oversee data quality, integrity, and retention policies
- Support SOC operations by enabling efficient search, dashboards, alerts, and detection content
- Collaboration & Leadership
- Act as a technical leader and mentor to security engineers and analysts
- Collaborate with cross-functional teams (Cloud, Infrastructure, DevOps, Security Operations)
- Influence and drive adoption of standardized logging and monitoring practices
- Communicate technical strategies and risks to senior leadership
You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required Qualifications:- 4+ years of experience in security engineering, SIEM, or data platform engineering
- 3+ years of experience with Splunk Enterprise and/or Splunk Cloud
- Experience managing and scaling Splunk infrastructure
- Solid experience onboarding logs across:
- Cloud platforms (AWS, Azure, GCP)
- Network/security devices
- Endpoints, SaaS, and custom applications
- Data ingestion (UF/HF, APIs, syslog, cloud-native integrations)
- Parsing, CIM normalization, and knowledge objects
- Proven solid scripting skills (Python, Bash, or similar)
Preferred Qualifications:- Experience with Security Operations (SOC) and detection engineering
- Experience supporting M&A / acquisition integrations
- Knowledge of SOAR platforms and automation
- Familiarity with frameworks such as MITRE ATT&CK
*All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy
Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $112,700 - $193,200 annually based on full-time employment. We comply with all minimum wage laws as applicable.
Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.