Splunk Enterprise Security (ES) Consultant - remote

System One Holdings, LLC

$90K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Several years of hands-on experience with Splunk, specifically in Enterprise Security (ES) implementation and content development.
  • Strong proficiency in SPL (Search Processing Language) and regular expressions for data manipulation.
  • Experience with scripting languages like Python, Perl, or Bash for automation tasks.
  • In-depth understanding of the Common Information Model (CIM) and data onboarding processes at scale.
  • Familiarity with supporting clustered Splunk environments in Security Operations Center (SOC) or Network Operations Center (NOC) settings.
  • Experience in SIEM data modeling on a large scale.
  • Linux proficiency including editing and maintaining Splunk configuration files.

Responsibilities

  • Develop custom detection content including correlation searches and alerts to identify security threats.
  • Build and maintain Splunk Apps and Technology Add-ons (TAs) to enhance functionality.
  • Onboard and normalize new data sources according to the Common Information Model (CIM).
  • Optimize data flow and ingestion processes through aggregation and filtering techniques.
  • Configure notable event actions and adaptive responses for efficient incident management.
  • Tune detection mechanisms to reduce unnecessary noise and enhance alert relevance.
  • Create dashboards to visualize anomalies, trends, and key security metrics.

Benefits

  • Remote work flexibility, enabling a work-from-home lifestyle.
  • Opportunity to work on cutting-edge security technology and platforms.
  • Collaborative environment partnering with client security and SOC teams.
  • Opportunity to sharpen skills in a rapidly evolving field of cybersecurity.
Full Job Description
Splunk Enterprise Security (ES) Consultant - remote

Remote - offsite
Responsibilities
  • Develop custom detection content: correlation searches, notable events, alerts, reports, and visualizations to surface threat activity
  • Build and maintain Splunk Apps and Technology Add-ons (TAs)
  • Onboard new data sources and normalize them to the Common Information Model (CIM)
  • Optimize data flow and ingestion using aggregation, filtering, and pipeline tuning
  • Configure notable event actions, action menus, and Adaptive Responses
  • Tune detections to cut noise and surface what matters, including risk-based alerting where applicable
  • Build dashboards that highlight anomalies, trends, and security and operational metrics
  • Support and optimize large distributed clustered Splunk environments (search heads, indexers, forwarders, deployment servers)
  • Partner with the client's security and SOC teams, debug complex integration and configuration issues
  • Document processes, procedures, and key engineering decisions

Requirements
  • Several years of hands-on Splunk experience, with real ES implementation, content development, and tuning
  • Strong SPL and regular expressions
  • Scripting in Python, Perl, or Bash
  • Solid grasp of CIM and data onboarding and normalization at scale
  • Experience supporting clustered Splunk environments in SOC or NOC settings
  • SIEM data modeling experience on a platform at scale
  • Proficiency in Linux, including editing and maintaining Splunk config files and apps
  • Comfortable working consultatively with client teams and explaining the why behind the work
  • Splunk certifications (Core Certified Consultant, ES Certified Admin, Architect) are a plus but not required
  • Demonstrated ES delivery experience carries more weight than paper

#LI-KA1
#M1

Ref: #856-Baltimore-S1

Similar Jobs

More Jobs at System One Holdings, LLC

More Information Technology Jobs

Find similar Splunk Enterprise Security (ES) Consultant - remote jobs: