Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Splunk Enterprise Security Expert

Apptad Inc

Job Title: Splunk Enterprise Security Expert

Location: REMOTE

Mode : Contract (6+ Months)

Knowledge Object Governance & Lifecycle Management

  • Provide centralized oversight and authoritative governance of all Splunk knowledge objects across the enterprise SIEM environment, including saved searches, correlation searches, field extractions, tags, aliases, event types, lookups, macros, data models, workflow actions, and KV store collections.
  • Establish, publish, and enforce enterprise-wide naming conventions for all knowledge object types - ensuring consistent, parseable, and discoverable naming across teams, apps, and deployments.
  • Conduct regular audits of knowledge object libraries to identify duplicate, orphaned, deprecated, or conflicting objects - retiring obsolete content and consolidating redundant objects across teams and deployments.
  • Create custom automations to track the ingest of data, the consistent flow of the data, drift of data away from the normalization standards, etc.
  • Define and maintain a knowledge object registry/catalog that documents ownership, scope, purpose, permissions, and lifecycle stage for each object in the environment.
  • Collaborate enterprise Splunk platform teams on permission structures and sharing models - ensuring objects are accessible to the correct roles (read/write/execute) across apps, environments, and user tiers without overexposure.
  • Lead the promotion pipeline for knowledge objects from development through testing, staging, and production - establishing change control workflows aligned to CI/CD and GitOps practices (GitHub, GitHub Actions).

CIM Normalization & Data Model management

  • Serve as the CIM (Common Information Model) authority for the enterprise - defining and maintaining CIM-compliant field mappings across all ingested data sources including endpoints (EDR/AV), network (firewall, proxy, DNS), identity (IAM, AD), cloud (AWS CloudTrail, Azure Monitor, GCP Logging), and application layers.
  • Design, build, and maintain Splunk data models for Pivot users, ES correlation searches, and accelerated reporting - ensuring alignment to CIM schemas and ES asset/identity frameworks.
  • Manage data model acceleration strategies (TSIDX, tstats, summary indexing) across all production data models, monitoring for search load, acceleration lag, and coverage gaps.
  • Define and enforce source-type and index taxonomy standards - establishing lexicographic naming conventions that optimize search performance, configuration priority, and multi-team usability.
  • Ensure entity zone enrichment (asset zones, network zones, identity tiers) is properly incorporated into data models and asset/identity lookups, supporting tiered risk scoring in Enterprise Security.
  • Maintain CIM coverage matrices across all logging domains, mapping data model fields to MITRE ATT&CK techniques, detection use cases, and compliance controls.

Knowledge Architecture & Standards Program

  • Design and own the enterprise Splunk knowledge architecture - defining taxonomy hierarchies, content type standards, metadata schemas, and classification frameworks that enable findability, scalability, and governance across all teams.
  • Develop and maintain a Knowledge Management Standards document (published to internal wiki/SharePoint) covering naming conventions, object lifecycle stages, ownership models, permission templates, CIM mapping standards, and change control procedures.
  • Establish and chair a Knowledge Governance Working Group composed of representatives from Detection Engineering, SOC Operations, Platform Engineering, Compliance, and key application teams - meeting regularly to review standards, resolve conflicts, and prioritize improvements.
  • Define content type templates for correlation searches, dashboards, reports, lookups, and macros - providing reusable, pre-approved scaffolding that accelerates new content development while enforcing standards compliance.

Required Technical Skills & Technologies

Splunk Core

  • Splunk Enterprise (distributed, multi-site, clustered) deep administrative and engineering proficiency
  • Splunk Enterprise Security (ES) correlation searches, notable events, risk rules, threat intelligence, asset/identity frameworks
  • Splunk Common Information Model (CIM) - advanced normalization across all major data model domains
  • SPL (Search Processing Language) - advanced query authoring including tstats, macros, sub-searches, eval functions, streaming/non-streaming commands
  • Data Models - design, acceleration management (TSIDX), Pivot support, ES data model dependencies
  • Knowledge Objects - full lifecycle mastery: field extractions, lookups (CSV, KV Store), macros, tags, aliases, event types, workflow actions, saved searches, correlation searches
  • Splunk Apps & Add-ons - TA development/review, app packaging, deployment via Deployment Server and Deployer
  • Splunk Admin Config Service (ACS) and configuration file management (conf files, btool, precedence rules)
  • Splunk Edge Processor / Ingest Processor - pipeline-level routing and data transformation awareness

Platform & Infrastructure

  • Multi-cloud environments: AWS, Azure, GCP - log source integration, cloud-native telemetry normalization
  • Linux and Windows system administration
  • Python and Bash/Shell scripting - automation of knowledge object management, API-driven content deployment
  • GitHub / GitHub Actions / CI-CD pipelines - knowledge object version control, automated testing, promotion workflows

Frameworks & Standards

  • MITRE ATT&CK - technique mapping for detection content governance
  • NIST CSF / 800-53, CIS Benchmarks - compliance-driven knowledge requirements
  • Agile / Scrum methodology for iterative content development

Required Qualifications

  • Bachelor's degree in computer science, Information Systems, Cybersecurity, or equivalent professional experience
  • 8+ years of hands-on Splunk experience in enterprise environments
  • 3+ years of direct experience with Splunk knowledge management, CIM normalization, or SIEM content engineering in a large-scale deployment (20+ TB/day)
  • Deep expertise in Splunk Enterprise Security - correlation search authoring, ES data models, risk-based alerting
  • Demonstrated experience managing knowledge object governance at scale across multi-team, multi-app Splunk environments
  • Strong proficiency in SPL including complex statistical pipelines, accelerated searches, and macro development
  • Experience developing and enforcing enterprise naming conventions and taxonomy standards for Splunk deployments
  • Proven ability to create and maintain technical documentation - runbooks, standards guides, architecture documentation
  • Background in detection engineering, threat hunting, or SOC operations - understanding of how knowledge objects serve analysts in practice

Preferred Qualifications

  • Splunk Certifications: Splunk Core Certified Consultant, Splunk Enterprise Security Certified Admin (SPLK-3001), Splunk Certified Architect - one or more strongly preferred
  • Security Certifications: GIAC (GCIA, GCIH, GCED), or equivalent
  • Experience with Splunk SOAR (Phantom) playbook development, orchestration, and knowledge integration
  • Familiarity with Splunk UBA and behavioral analytics model management
  • Experience in healthcare or highly regulated industries (HIPAA, Federal (NIST), NYDFS, PCI)
  • Experience with infrastructure-as-code tools (Ansible, Terraform) for Splunk configuration management
  • Proficiency with LLM-powered tooling and AI-assisted automation for knowledge retrieval and content management
  • Experience supporting Splunk deployments in environments with 10,000+ users and multi-petabyte data retention
  • Familiarity with Kafka, streaming data pipelines, and real-time telemetry routing
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Splunk Enterprise Security Expert in Remote vacancy
  •  ...Our partner is looking for a Senior Security Subject Matter Expert (AI/ML, Cloud & Security) based in United...  ...activities using platforms such as Splunk, Security Onion, Tenable, or...  ...architectures. Practical experience with enterprise security technologies such as Splunk... 
    Splunk
    Full time
    Remote work

    jobgether

    United States
    7 days ago
  • $1,000 per month

     ...Account Manager - Security Solutions (Enterprise) Location : Chicago, IL (remote office) Company : Global Leader in Security Solutions (OEM;...  ...from Palo Alto, A10, FireEye, RSA, Fortinet, ExtraHop, F5, Splunk, NetScout, Akamai, HP, Imperva, Proofpoint, Zscaler, Cloudflare... 
    Splunk
    Permanent employment
    Full time
    Work at office
    Remote work
    Work from home

    MRINetwork Jobs

    West Chicago, IL
    a month ago
  • $130k - $140k

     ...motivated Senior ServiceNow and Enterprise Tools Support Specialist to...  ...our USSS Network Operations and Security Center (NOSC) proposal. This role...  ...level IT tools (e.g., SolarWinds, Splunk, SCCM, AppDynamics).Serve as a subject matter expert (SME) for the ServiceNow... 
    Splunk
    Remote work

    Govcio

    Washington DC
    11 hours ago
  •  ...design, implementation, and evolution of its enterprise-wide log management platforms. This role...  ...complex challenges and deliver scalable security monitoring across a global enterprise....  ...and expertise with major platforms like Splunk, CrowdStrike, #J-18808-Ljbffr Danaher
    Splunk
    Remote job

    Danaher

    New York, NY
    5 days ago
  • $96.9k - $136.8k

     ...identify possible threats, risks or security control gaps to the enterprise and produce detection & mitigation recommendations...  ...role is considered a subject matter expert for hunting via host-based and...  ...Detection & Response tooling; Splunk ES, CrowdStrike, Logscale, Defender... 
    Splunk
    Full time
    Work from home

    TD Bank

    Mount Laurel, NJ
    2 days ago
  • $180k - $195k

     ...missions. Our staff include experts in astronomy, engineering, education...  ...space.STScI is seeking an Enterprise Technology Lead to set the...  ...running enterprise IT.Identity, Security & AI GovernanceGovern...  ...platform experience (Datadog, Splunk, or CrowdStrike) preferred.Experience... 
    Splunk
    Permanent employment
    Full time
    Remote work
    Flexible hours
    3 days per week

    Space Telescope Science Institute

    Baltimore, MD
    1 day ago
  • Software Engineer: Enterprise Tools Engineering Architect - APM, Infrastructure, and Observability PlatformsWork Location: Onsite, Framingham...  ...health.Proven experience with log analytics platforms (e.g., Splunk, Elastic), including data ingestion, routing, indexing... 
    Splunk
    Local area

    Staples

    Framingham, MA
    3 days ago
  •  ...of successful mission support to improve security, streamline logistics, and enhance...  ...while operating, maintaining, and deploying enterprise cyber tools.ResponsibilitiesResponsiblities...  ...Federal GovernmentHands-on with: ACAS, Splunk, ESS, Cisco ASA Firewalls & Firepower... 
    Splunk
    Remote work

    V2X

    Orlando, FL
    2 days ago
  • $90 per hour

     ...Jack Dorsey . Position: Cybersecurity Expert Type: Contract Compensation: $...  ...Construct cybersecurity scenarios for security operations center monitoring , incident...  ...scenarios using tools like SIEM platforms ( Splunk , Microsoft Sentinel ), EDR tools (... 
    Splunk
    Contract work
    Summer work
    Remote work

    Mercor

    San Francisco, CA
    10 days ago
  • Executive Director of Enterprise Platform ArchitectureLocation: Chicago, ILTravel: 0%Job Categories...  ...architecture patterns for networking, security, identity, and compute are consistent,...  ...— OpenTelemetry, Prometheus, Grafana, Splunk, or equivalent Familiarity with low-... 
    Splunk
    Permanent employment
    Work experience placement

    Request Technology

    Chicago, IL
    7 hours ago
  • $174.5k - $240k

     ...ours.Help keep Faire's AI adoption moving fast, safely:The Enterprise Security team at Faire owns the tools and policies that keep our people...  ...with observability or SIEM tooling (e.g., Datadog, Splunk) and building data pipelines for monitoring and compliance.A... 
    Splunk
    Work experience placement
    Work at office
    Local area
    Remote work
    Monday to Friday
    Flexible hours
    3 days per week

    Faire

    San Francisco, CA
    1 day ago
  • $86.8k - $198k

    Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton...  ...externally facing vulnerabilities and security misconfigurations across the Booz Allen...  ...including QualysExperience with Splunk, including building search queriesKnowledge... 
    Splunk
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    1 day ago
  • $100k - $135k

     ...galaxy beyond our planet. About the RoleThe Enterprise Security Engineer is responsible for designing,...  ...as a cybersecurity subject matter expert for technical and business stakeholders...  ...Security OperationsSIEM Platforms (Elastic,Splunk)Endpoint Detection & Response (EDR/XDR)... 
    Splunk
    Full time
    Work at office

    Apex Technology

    Los Angeles, CA
    2 days ago
  •  ...We are currently seeking a Security Analysis Specialist Advisor to...  ...Monitor user behaviour across enterprise systems, applications, endpoints...  ...SIEM platforms (Splunk, Microsoft Sentinel, QRadar,...  ...Global Top Employer, we have experts in more than 50 countries. We... 
    Splunk
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    NTT DATA Services

    Dallas, TX
    20 days ago
  • $170k - $190k

     ...technical leader responsible for protecting enterprise through advanced monitoring, threat...  ...architectural hardening, and Zero Trust‑aligned security engineering. The ideal candidate will...  ..., and on‑premise environments using Splunk, firewall telemetry, endpoint security... 
    Splunk
    Full time
    Part time
    For contractors
    Remote work

    Akima

    Alexandria, VA
    2 days ago
  • $86.8k - $198k

    Enterprise Cybersecurity Automation EngineerThe Opportunity:​Cyber threats are everywhere,...  ...clients? The answer is you, help us develop security automation solutions that provide...  ...including security management tools such as Splunk, Carbon Black, CrowdStrike, Nitro, or ArcSight... 
    Splunk
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  • $85k - $90k

     ...are seeking an experienced Information Security Analyst to support security operations,...  ...and security automation within a complex enterprise environment.This is a hands-on technical...  ...SIEM and log-analysis platforms such as Splunk, Elastic/OpenSearch, Kibana, and Microsoft... 
    Splunk
    Remote work
    Visa sponsorship
    Free visa

    NPAworldwide

    Syracuse, NY
    3 days ago
  • $139.1k - $188.2k

     ...just work - through fast, reliable, secure connectivity. As eero expands into the enterprise space, serving corporate offices,...  ..., you will:- Serve as an expert on enterprise networking, fleet monitoring...  ..., Datadog, New Relic and Splunk- CCNA or equivalent level networking... 
    Splunk
    Work experience placement
    Local area
    Work from home
    Flexible hours

    Amazon

    San Francisco, CA
    4 days ago
  • Enterprise Monitoring Systems Administrator CI Infrastructure Services (CIS) is looking for...  ..., resilience, and efficiency Implement secure configuration baselines, system hardening...  ...monitoring platforms (SolarWinds, Splunk, Elastic/ELK, Dynatrace, AppDynamics, Nagios... 
    Splunk
    Remote work

    General Dynamics Information Technology

    Annapolis, MD
    4 days ago
  •  ...L2 Security Analyst Full‑Time, on‑site We are looking for a Senior Security Analyst (L2)...  ...a SIEM (RSA NetWitness, Azure Sentinel, Splunk, etc.) Strong understanding of incident...  ...performing triage/incident response in enterprise environments Minimum of 3+ years of experience... 
    Splunk
    Full time

    LumiFi

    Scottsdale, AZ
    2 days ago
  •  ...is a minority and women-owned business enterprise (MWBE) committed to maximizing global workforce...  ...and insightful market intelligence has secured long-term partnerships with Fortune 500...  ...knowledge of analyzing events from SPLUNK SIEM. • Ability to work shift work in a... 
    Splunk
    Work experience placement
    Local area
    Remote work
    All shifts
    Shift work

    Artech

    Plano, TX
    2 days ago
  •  ...generation of predictive and agentic AI for enterprise IT operations. We’re hiring a hands‑on...  ...and adopt. You do not need to be an AI expert on day one. What matters most is strong...  ...ecosystems (e.g., Datadog, Dynatrace, Splunk, ServiceNow, Jira, Ansible). 4. Go to Market... 
    Splunk
    Remote work

    Grokstream LLC

    New York, NY
    2 days ago
  • $129.3k - $177.8k

     ...a part of our caring communityWhy Join Enterprise Observability Engineering?The Enterprise...  .... While familiarity with platforms like Splunk or Dynatrace is a plus, we value platform...  ...challenges. You’ll work closely with SRE, Security, Networking, Platform Engineering, and... 
    Splunk
    Full time
    Temporary work
    Apprenticeship
    Work at office
    Remote work
    Work from home
    Home office

    Humana

    Boston, MA
    3 days ago
  •  ...Description OverviewThe Senior Information Security Analyst is a senior individual...  ...hunting, and the continuous improvement of enterprise security operations. The role works across...  ...including EDR and/or Identity Protection• Splunk Enterprise Security, CrowdStrike Next-Gen... 
    Splunk
    Remote work
    2 days per week

    Perrigo

    Allegan, MI
    2 days ago
  •  ...Confiz is seeking a Security Analyst to join one of our largest clients on our Cybersecurity...  ...)  ~ Security Tools:  ~ SIEM: Splunk (basic search), IBM QRadar (offense monitoring...  ...working on highly innovative enterprise projects & products. Our customer base includes... 
    Splunk
    Internship
    Remote work
    Shift work

    Confiz

    United States
    2 days ago
  •  ...Management, or Site Reliability Engineering within a large-scale enterprise environment, preferably in the financial services industry....  ...Remedy, ServiceNow, PagerDuty) and monitoring tools (e.g., Grafana, Splunk, Dynatrace, Elk). Experience with scripting and automation (... 
    Splunk
    Full time
    Work at office
    Local area

    DBS Bank Ltd

    Remote
    6 days ago
  • $3,000 per month

     ...supporting the U.S. Department of State. As a Security Analyst, you will support day-to-day...  ..., you will help maintain a secure enterprise environment while supporting modernization...  ...Microsoft Defender, Microsoft Sentinel, Splunk, ServiceNow, Tenable Nessus, Qualys, or... 
    Splunk
    Contract work
    Work from home

    Acuity

    Washington DC
    5 days ago
  • $98.23k - $123.77k

    Role: Information Security Analyst (VTM/Vulnerability Management)Location: Dallas, TX (Must...  ...& ScanningSIEM/EDR/XDR (CrowdStrike, Splunk, Elastic etc.)Defender for Endpoint, Defender...  ...'s security posture across cloud and enterprise environmentsWhat We’re Looking For:... 
    Splunk
    Full time
    For contractors
    Work at office
    Local area
    Work from home
    Flexible hours

    Blue Yonder

    Dallas, TX
    3 days ago
  •  ...welfare, and unemployment insurance. Our enterprise-grade SaaS platforms power mission-...  ...deliver vital public benefits efficiently, securely, and at scale. At Vimo, we create...  ...alerts and events using SIEM tools (SPLUNK, Wazuh) and other security monitoring systems... 
    Splunk
    Remote work

    VIMO INC

    United States
    5 days ago
  •  ...to detect malicious behavior, suspicious activity, and security anomalies across the enterprise. This role is part Information Security team focused on...  ...QualificationsExperience with SIEM platforms such as Microsoft Sentinel, Splunk, Exabeam, Securonix, or similar tools.Experience... 
    Splunk
    Local area
    Remote work
    Flexible hours
    2 days per week
    3 days per week
    1 day per week

    Lam Research Corporation

    Tualatin, OR
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Splunk Enterprise Security Expert. Be the first to apply!