Splunk ES Engineer
Openkyber
OpenKyber is a Service Disable Veteran-Owned IT staffing firm, ISO 9001 and ISO 27001 certified, working with federal agencies, state governments, and Fortune 500 enterprise clients across the US. What makes us different isn t a tagline; it s the way we work. We don t forward resumes and hope for the best. We take the time to understand where a professional like you is headed and only reach out when we genuinely believe there s a fit worth exploring Title- Senior Splunk Security Engineer
Location- Remote
Duration- 6 months with possible extension
Job Description:
Must haves: 4-5 years Splunk experience, 4-5 years IAM experience, monitoring-preferred (previous analyst work)-PLEASE SHOW ON RESUME
You will serve as a Senior Splunk Security Engineer responsible for designing, building, testing, and documenting a privilege access event monitoring solution within the organization's security operations environment. This resource will support the enhancement of security alerting capabilities by improving privileged access visibility, reducing false positives, and implementing intelligent alert routing and automation using SIEM and SOAR technologies. The resource will work closely with the security operations and engineering teams to implement advanced Splunk correlation searches, risk-based alerting logic, SOAR playbooks, alert enrichment workflows, and operational dashboards. The engagement will focus on delivering a production-ready monitoring capability that enables more accurate detection, prioritization, and handling of privileged access-related events.
Key ResponsibilitiesThe contingent worker will be responsible for the following activities:
- Design and implement privilege access event monitoring logic to identify security-relevant privileged access activity.
- Develop intelligent alert routing and correlation logic to distinguish true security threats from routine operational events.
- Build and optimize Splunk correlation searches, custom alert rules, and risk-based alerting logic.
- Configure filtering, suppression, and enrichment rules to reduce alert noise and improve alert quality.
- Design and develop SOAR workflows and playbooks to automate incident handling and alert consolidation.
- Integrate SIEM, SOAR, and ticketing processes to support consistent incident routing and management.
- Create enrichment logic that adds relevant context to alerts, including user, asset, access, and threat-level information.
- Build dashboards and reports to monitor alert health, performance, volume, and operational effectiveness.
- Test the implementation against historical datasets of at least 60 days to validate alert accuracy and volume reduction.
- Document all implemented searches, workflows, logic, playbooks, dashboards, edge cases, and operating procedures.
- Create runbooks and operational guides for ongoing support and maintenance.
- Provide knowledge transfer and training to security operations and engineering teams prior to engagement completion.
The requested resource must have the following skills and experience:
- Minimum of 5 years of experience in security operations, SIEM engineering, security engineering, or a related cybersecurity function.
- At least 3 years of hands-on Splunk experience in production environments.
- Advanced proficiency developing Splunk correlation searches, custom alert rules, dashboards, and reports.
- Experience configuring and implementing Splunk Risk-Based Alerting for security use cases.
- Strong understanding of Splunk data pipelines, search performance optimization, indexing, field extraction, and alert tuning.
- At least 2 years of hands-on experience with SOAR platforms such as Cortex XSOAR, Demisto, or comparable orchestration platforms.
- Experience designing and implementing complex SOAR playbooks, workflows, automation logic, and incident handling processes.
- Experience integrating SOAR platforms with SIEM tools, ticketing systems, and other security operations technologies.
- At least 2 years of experience with privilege access monitoring, identity and access management security, privileged access management, or related security operations use cases.
- Understanding of privilege escalation detection methodologies, authorization frameworks, access control models, and IAM-related security monitoring.
- Proven experience reducing false positives and improving alert fidelity in high-volume security .
For applications and inquiries, contact:View email address on us.fitly.work
- ...AI/ML Platform Engineer Location: Brazil Employment Type: Contract Work Model: Remote Role Overview We are seeking an experienced AI/ML Platform Engineer to design, build, and maintain scalable AI/ML infrastructure and delivery platforms. The ideal candidate will...SuggestedContract workRemote work
- This is a contract-to-hire opportunity, ideally hybrid in Central NJ, with some flexibility for local remote. The organization is a large, heavily regulated financial services enterprise operating a fully isolated Azure cloud environment with no reliance on shared services...SuggestedPermanent employmentContract workLocal areaRemote work
- ...Job Description: A large enterprise company in the aviation space is looking for a Cloud Security Engineer to help secure complex, high-visibility cloud environments used across the organization. This is a hands-on security role for someone who enjoys solving real...SuggestedContract work3 days per week
- Required Qualifications 12+ years of IT experience with 6+ years in Cloud Security Architecture. Hands-on expertise in AWS and Microsoft Azure security services. Strong knowledge of Identity & Access Management (IAM), SSO, MFA, RBAC, and PAM. Experience designing...Suggested
- Job Title: NCDOT - Cloud Security Architect - Expert (809185) in Raleigh, NC - Onsite Duration: 12 Months Interview: In Person Last date: 08/26/2026 Job description: OpenKyber is needed to support the NCDOT Microsoft Azure cloud tenant build and configuration, specifically...SuggestedLocal areaRemote work
- ...Zone & Cyber Resilience/Remote Remote Duration: Long term Required: Alternates depending on seniority/framing: Sr. Cloud Security Engineer IRE/Clean Room, Principal Security Architect AWS Multi-Account, or Cloud Infrastructure Security Architect (EKS + Governance)....Remote work
- ...platforms. Experience with Salesforce Agentforce and/or AI technologies , including AI-powered agents, generative AI, prompt engineering, AI automation, or integration of AI services with Salesforce. Understanding of responsible AI practices, AI security, data...Full timeImmediate startRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Splunk ES Engineer. Be the first to apply!

