Senior SIEM Engineer - Splunk

Tyto Athene

$145K — $155K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree required, experience and education equivalents accepted
  • 8 years of general work experience with 6 years in security operations or detection engineering focusing on Splunk
  • Advanced proficiency in SPL for large-scale environments
  • Deep knowledge of Splunk architecture and Splunk Enterprise Security
  • Strong understanding of the MITRE ATT&CK framework and threat modeling
  • Experience in designing detection strategies, not just individual searches
  • Strong scripting skills in Python or PowerShell with SOAR integration familiarity
  • Experience with cloud security monitoring for AWS, Azure, or GCP.

Responsibilities

  • Design and own the Splunk architecture, including indexer and search head clustering
  • Lead detection engineering strategy by prioritizing correlation search development
  • Establish standards for data onboarding and correlation search performance
  • Drive Splunk platform upgrades and integration with other security tools
  • Optimize search performance and manage license usage at scale
  • Mentor mid-level engineers and SOC analysts on best practices
  • Serve as the escalation point for complex investigations and incidents
  • Own Splunk-related metrics and reporting for leadership
  • Lead threat hunting initiatives using advanced SPL functions
  • Ensure compliance with audit requirements for various frameworks
  • Represent SIEM and detection functions in cross-functional planning

Benefits

  • Health/Dental/Vision benefits
  • 401(k) match
  • Paid Time Off
  • Short-Term/Long-Term Disability and Life Insurance
  • Referral Bonuses
  • Professional development reimbursement
  • Parental leave
Full Job Description
Description

Quantum Sky is searching for a Senior SIEM Engineer to own the architecture, strategy, and long-term health of the organization's Splunk deployment, setting standards for detection engineering, data onboarding, and platform scalability. This role operateswith autonomy, mentors mid-level engineers, and partners directly with security leadership to align Splunk's capability with the broader detection and response strategy.Theseniorengineeristhe escalation point for complex platform issues, distributed environment troubleshooting, and high-priority incidents.

Responsibilities

  • Design and own the overall Splunk architecture, including indexer clustering, search head clustering, forwarder tiering, and storage/retention (includingSmartStorewhere applicable) strategy
  • Lead detection engineering strategy within Splunk ES: prioritize correlation search development based on threat intelligence, risk assessments, and gaps in coverage
  • Establish and enforce standards for data onboarding, CIM normalization, field extraction quality, and correlation search performance
  • Drive Splunk platform upgrades, app/add-on management, and integrations with other security tools (SOAR platforms, threat intel feeds, EDR, ticketing systems)
  • Optimizesearch performance and indexing strategy to manage license usage and infrastructure cost at scale
  • Mentor andprovidetechnical guidance to mid-level SIEM engineers and SOC analysts on SPL, use case design, and Splunk best practices
  • Serve as the technical escalation point for complex investigations and major incidents requiring deep Splunkexpertise
  • Evaluate and recommend new Splunk apps, premiumsolutions,or architectural changes
  • Own Splunk-related metrics and reporting for leadership (detection coverage, mean time to detect, platform performance, license/cost efficiency)
  • Lead threat hunting initiatives using advanced SPL, data models, and Splunk's pivot/statistical functions
  • Ensure Splunk configuration and processes support audit and compliance requirements (e.g., PCI-DSS, HIPAA, SOC 2, NIST)
  • Represent the SIEM/detection function in cross-functional security architecture and incident response planning
Qualifications

Required:

  • Bachelors Degreerequired(experience and education equivalents are considered and can be substituted for aBachelors Degree.
  • 8 years of general work experience with 6 years relevant functional experience in security operations or detection engineering, with substantial hands-on Splunk ownership, including at least some experience in distributed/clustered environments
  • Advancedproficiencyin SPL, including complex correlation searches, data models, and search optimization for large-scale environments
  • Deep working knowledge of Splunk architecture (indexer/search head clustering, forwarder management, index design) and Splunk Enterprise Security if deployed
  • Strong understanding of the MITRE ATT&CK framework, cyber kill chain, and threat modeling
  • Demonstrated experience designing detection strategies within Splunk, not just implementing individual searches
  • Strong scripting/automation skills (Python, PowerShell) and familiarity with SOAR platform integration (e.g., Splunk SOAR, if in use)
  • Experience with cloud security monitoring (AWS, Azure, or GCP log sources) and Splunk's cloud-specific add-ons
  • Track recordof leading or significantly contributing to incident response investigations
  • Familiarity with compliance frameworks relevant to the organization's industry
  • Relevant certifications preferred: Splunk Core Certified Advanced Power User, Splunk Certified Architect, Splunk Enterprise Security Certified Admin, GCIA, GCIH, GCFA, or CISSP

Desired:

  • Experience with Splunk in aVMwareESXi, vCenter virtual infrastructure
  • Experience or working knowledge with similar SIEM tools

Clearance:

  • An active Top Secret clearance with SCI eligibility is required.

Location and Schedule:

  • This position is onsite at the customer location in Washington, DC. The environment requires onsite support five days per week, with some flexibility in scheduling based on program and customer requirements. Core business hours are 8am-4pm.
About Quantum Sky

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $145,000-$155,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

Similar Jobs

More Jobs at Tyto Athene

More Information Technology Jobs

Find similar Senior SIEM Engineer - Splunk jobs: