Splunk Enterprise Security Expert
Apptad Inc
Job Title: Splunk Enterprise Security Expert
Location: REMOTE
Mode : Contract (6+ Months)
Knowledge Object Governance & Lifecycle Management
- Provide centralized oversight and authoritative governance of all Splunk knowledge objects across the enterprise SIEM environment, including saved searches, correlation searches, field extractions, tags, aliases, event types, lookups, macros, data models, workflow actions, and KV store collections.
- Establish, publish, and enforce enterprise-wide naming conventions for all knowledge object types - ensuring consistent, parseable, and discoverable naming across teams, apps, and deployments.
- Conduct regular audits of knowledge object libraries to identify duplicate, orphaned, deprecated, or conflicting objects - retiring obsolete content and consolidating redundant objects across teams and deployments.
- Create custom automations to track the ingest of data, the consistent flow of the data, drift of data away from the normalization standards, etc.
- Define and maintain a knowledge object registry/catalog that documents ownership, scope, purpose, permissions, and lifecycle stage for each object in the environment.
- Collaborate enterprise Splunk platform teams on permission structures and sharing models - ensuring objects are accessible to the correct roles (read/write/execute) across apps, environments, and user tiers without overexposure.
- Lead the promotion pipeline for knowledge objects from development through testing, staging, and production - establishing change control workflows aligned to CI/CD and GitOps practices (GitHub, GitHub Actions).
CIM Normalization & Data Model management
- Serve as the CIM (Common Information Model) authority for the enterprise - defining and maintaining CIM-compliant field mappings across all ingested data sources including endpoints (EDR/AV), network (firewall, proxy, DNS), identity (IAM, AD), cloud (AWS CloudTrail, Azure Monitor, GCP Logging), and application layers.
- Design, build, and maintain Splunk data models for Pivot users, ES correlation searches, and accelerated reporting - ensuring alignment to CIM schemas and ES asset/identity frameworks.
- Manage data model acceleration strategies (TSIDX, tstats, summary indexing) across all production data models, monitoring for search load, acceleration lag, and coverage gaps.
- Define and enforce source-type and index taxonomy standards - establishing lexicographic naming conventions that optimize search performance, configuration priority, and multi-team usability.
- Ensure entity zone enrichment (asset zones, network zones, identity tiers) is properly incorporated into data models and asset/identity lookups, supporting tiered risk scoring in Enterprise Security.
- Maintain CIM coverage matrices across all logging domains, mapping data model fields to MITRE ATT&CK techniques, detection use cases, and compliance controls.
Knowledge Architecture & Standards Program
- Design and own the enterprise Splunk knowledge architecture - defining taxonomy hierarchies, content type standards, metadata schemas, and classification frameworks that enable findability, scalability, and governance across all teams.
- Develop and maintain a Knowledge Management Standards document (published to internal wiki/SharePoint) covering naming conventions, object lifecycle stages, ownership models, permission templates, CIM mapping standards, and change control procedures.
- Establish and chair a Knowledge Governance Working Group composed of representatives from Detection Engineering, SOC Operations, Platform Engineering, Compliance, and key application teams - meeting regularly to review standards, resolve conflicts, and prioritize improvements.
- Define content type templates for correlation searches, dashboards, reports, lookups, and macros - providing reusable, pre-approved scaffolding that accelerates new content development while enforcing standards compliance.
Required Technical Skills & Technologies
Splunk Core
- Splunk Enterprise (distributed, multi-site, clustered) deep administrative and engineering proficiency
- Splunk Enterprise Security (ES) correlation searches, notable events, risk rules, threat intelligence, asset/identity frameworks
- Splunk Common Information Model (CIM) - advanced normalization across all major data model domains
- SPL (Search Processing Language) - advanced query authoring including tstats, macros, sub-searches, eval functions, streaming/non-streaming commands
- Data Models - design, acceleration management (TSIDX), Pivot support, ES data model dependencies
- Knowledge Objects - full lifecycle mastery: field extractions, lookups (CSV, KV Store), macros, tags, aliases, event types, workflow actions, saved searches, correlation searches
- Splunk Apps & Add-ons - TA development/review, app packaging, deployment via Deployment Server and Deployer
- Splunk Admin Config Service (ACS) and configuration file management (conf files, btool, precedence rules)
- Splunk Edge Processor / Ingest Processor - pipeline-level routing and data transformation awareness
Platform & Infrastructure
- Multi-cloud environments: AWS, Azure, GCP - log source integration, cloud-native telemetry normalization
- Linux and Windows system administration
- Python and Bash/Shell scripting - automation of knowledge object management, API-driven content deployment
- GitHub / GitHub Actions / CI-CD pipelines - knowledge object version control, automated testing, promotion workflows
Frameworks & Standards
- MITRE ATT&CK - technique mapping for detection content governance
- NIST CSF / 800-53, CIS Benchmarks - compliance-driven knowledge requirements
- Agile / Scrum methodology for iterative content development
Required Qualifications
- Bachelor's degree in computer science, Information Systems, Cybersecurity, or equivalent professional experience
- 8+ years of hands-on Splunk experience in enterprise environments
- 3+ years of direct experience with Splunk knowledge management, CIM normalization, or SIEM content engineering in a large-scale deployment (20+ TB/day)
- Deep expertise in Splunk Enterprise Security - correlation search authoring, ES data models, risk-based alerting
- Demonstrated experience managing knowledge object governance at scale across multi-team, multi-app Splunk environments
- Strong proficiency in SPL including complex statistical pipelines, accelerated searches, and macro development
- Experience developing and enforcing enterprise naming conventions and taxonomy standards for Splunk deployments
- Proven ability to create and maintain technical documentation - runbooks, standards guides, architecture documentation
- Background in detection engineering, threat hunting, or SOC operations - understanding of how knowledge objects serve analysts in practice
Preferred Qualifications
- Splunk Certifications: Splunk Core Certified Consultant, Splunk Enterprise Security Certified Admin (SPLK-3001), Splunk Certified Architect - one or more strongly preferred
- Security Certifications: GIAC (GCIA, GCIH, GCED), or equivalent
- Experience with Splunk SOAR (Phantom) playbook development, orchestration, and knowledge integration
- Familiarity with Splunk UBA and behavioral analytics model management
- Experience in healthcare or highly regulated industries (HIPAA, Federal (NIST), NYDFS, PCI)
- Experience with infrastructure-as-code tools (Ansible, Terraform) for Splunk configuration management
- Proficiency with LLM-powered tooling and AI-assisted automation for knowledge retrieval and content management
- Experience supporting Splunk deployments in environments with 10,000+ users and multi-petabyte data retention
- Familiarity with Kafka, streaming data pipelines, and real-time telemetry routing
- ...Our partner is looking for a Senior Security Subject Matter Expert (AI/ML, Cloud & Security) based in United... ...activities using platforms such as Splunk, Security Onion, Tenable, or... ...architectures. Practical experience with enterprise security technologies such as Splunk...SplunkFull timeRemote work
$1,000 per month
...Account Manager - Security Solutions (Enterprise) Location : Chicago, IL (remote office) Company : Global Leader in Security Solutions (OEM;... ...from Palo Alto, A10, FireEye, RSA, Fortinet, ExtraHop, F5, Splunk, NetScout, Akamai, HP, Imperva, Proofpoint, Zscaler, Cloudflare...SplunkPermanent employmentFull timeWork at officeRemote workWork from home$130k - $140k
...motivated Senior ServiceNow and Enterprise Tools Support Specialist to... ...our USSS Network Operations and Security Center (NOSC) proposal. This role... ...level IT tools (e.g., SolarWinds, Splunk, SCCM, AppDynamics).Serve as a subject matter expert (SME) for the ServiceNow...SplunkRemote work- ...design, implementation, and evolution of its enterprise-wide log management platforms. This role... ...complex challenges and deliver scalable security monitoring across a global enterprise.... ...and expertise with major platforms like Splunk, CrowdStrike, #J-18808-Ljbffr DanaherSplunkRemote job
$96.9k - $136.8k
...identify possible threats, risks or security control gaps to the enterprise and produce detection & mitigation recommendations... ...role is considered a subject matter expert for hunting via host-based and... ...Detection & Response tooling; Splunk ES, CrowdStrike, Logscale, Defender...SplunkFull timeWork from home$180k - $195k
...missions. Our staff include experts in astronomy, engineering, education... ...space.STScI is seeking an Enterprise Technology Lead to set the... ...running enterprise IT.Identity, Security & AI GovernanceGovern... ...platform experience (Datadog, Splunk, or CrowdStrike) preferred.Experience...SplunkPermanent employmentFull timeRemote workFlexible hours3 days per week- Software Engineer: Enterprise Tools Engineering Architect - APM, Infrastructure, and Observability PlatformsWork Location: Onsite, Framingham... ...health.Proven experience with log analytics platforms (e.g., Splunk, Elastic), including data ingestion, routing, indexing...SplunkLocal area
- ...of successful mission support to improve security, streamline logistics, and enhance... ...while operating, maintaining, and deploying enterprise cyber tools.ResponsibilitiesResponsiblities... ...Federal GovernmentHands-on with: ACAS, Splunk, ESS, Cisco ASA Firewalls & Firepower...SplunkRemote work
$90 per hour
...Jack Dorsey . Position: Cybersecurity Expert Type: Contract Compensation: $... ...Construct cybersecurity scenarios for security operations center monitoring , incident... ...scenarios using tools like SIEM platforms ( Splunk , Microsoft Sentinel ), EDR tools (...SplunkContract workSummer workRemote work- Executive Director of Enterprise Platform ArchitectureLocation: Chicago, ILTravel: 0%Job Categories... ...architecture patterns for networking, security, identity, and compute are consistent,... ...— OpenTelemetry, Prometheus, Grafana, Splunk, or equivalent Familiarity with low-...SplunkPermanent employmentWork experience placement
$174.5k - $240k
...ours.Help keep Faire's AI adoption moving fast, safely:The Enterprise Security team at Faire owns the tools and policies that keep our people... ...with observability or SIEM tooling (e.g., Datadog, Splunk) and building data pipelines for monitoring and compliance.A...SplunkWork experience placementWork at officeLocal areaRemote workMonday to FridayFlexible hours3 days per week$86.8k - $198k
Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton... ...externally facing vulnerabilities and security misconfigurations across the Booz Allen... ...including QualysExperience with Splunk, including building search queriesKnowledge...SplunkFull timeContract workPart timeWork at officeLocal areaRemote work$100k - $135k
...galaxy beyond our planet. About the RoleThe Enterprise Security Engineer is responsible for designing,... ...as a cybersecurity subject matter expert for technical and business stakeholders... ...Security OperationsSIEM Platforms (Elastic,Splunk)Endpoint Detection & Response (EDR/XDR)...SplunkFull timeWork at office- ...We are currently seeking a Security Analysis Specialist Advisor to... ...Monitor user behaviour across enterprise systems, applications, endpoints... ...SIEM platforms (Splunk, Microsoft Sentinel, QRadar,... ...Global Top Employer, we have experts in more than 50 countries. We...SplunkWork experience placementWork at officeRemote workFlexible hours
$170k - $190k
...technical leader responsible for protecting enterprise through advanced monitoring, threat... ...architectural hardening, and Zero Trust‑aligned security engineering. The ideal candidate will... ..., and on‑premise environments using Splunk, firewall telemetry, endpoint security...SplunkFull timePart timeFor contractorsRemote work$86.8k - $198k
Enterprise Cybersecurity Automation EngineerThe Opportunity:Cyber threats are everywhere,... ...clients? The answer is you, help us develop security automation solutions that provide... ...including security management tools such as Splunk, Carbon Black, CrowdStrike, Nitro, or ArcSight...SplunkFull timeContract workPart timeWork at officeLocal areaRemote work$85k - $90k
...are seeking an experienced Information Security Analyst to support security operations,... ...and security automation within a complex enterprise environment.This is a hands-on technical... ...SIEM and log-analysis platforms such as Splunk, Elastic/OpenSearch, Kibana, and Microsoft...SplunkRemote workVisa sponsorshipFree visa$139.1k - $188.2k
...just work - through fast, reliable, secure connectivity. As eero expands into the enterprise space, serving corporate offices,... ..., you will:- Serve as an expert on enterprise networking, fleet monitoring... ..., Datadog, New Relic and Splunk- CCNA or equivalent level networking...SplunkWork experience placementLocal areaWork from homeFlexible hours- Enterprise Monitoring Systems Administrator CI Infrastructure Services (CIS) is looking for... ..., resilience, and efficiency Implement secure configuration baselines, system hardening... ...monitoring platforms (SolarWinds, Splunk, Elastic/ELK, Dynatrace, AppDynamics, Nagios...SplunkRemote work
- ...L2 Security Analyst Full‑Time, on‑site We are looking for a Senior Security Analyst (L2)... ...a SIEM (RSA NetWitness, Azure Sentinel, Splunk, etc.) Strong understanding of incident... ...performing triage/incident response in enterprise environments Minimum of 3+ years of experience...SplunkFull time
- ...is a minority and women-owned business enterprise (MWBE) committed to maximizing global workforce... ...and insightful market intelligence has secured long-term partnerships with Fortune 500... ...knowledge of analyzing events from SPLUNK SIEM. • Ability to work shift work in a...SplunkWork experience placementLocal areaRemote workAll shiftsShift work
- ...generation of predictive and agentic AI for enterprise IT operations. We’re hiring a hands‑on... ...and adopt. You do not need to be an AI expert on day one. What matters most is strong... ...ecosystems (e.g., Datadog, Dynatrace, Splunk, ServiceNow, Jira, Ansible). 4. Go to Market...SplunkRemote work
$129.3k - $177.8k
...a part of our caring communityWhy Join Enterprise Observability Engineering?The Enterprise... .... While familiarity with platforms like Splunk or Dynatrace is a plus, we value platform... ...challenges. You’ll work closely with SRE, Security, Networking, Platform Engineering, and...SplunkFull timeTemporary workApprenticeshipWork at officeRemote workWork from homeHome office- ...Description OverviewThe Senior Information Security Analyst is a senior individual... ...hunting, and the continuous improvement of enterprise security operations. The role works across... ...including EDR and/or Identity Protection• Splunk Enterprise Security, CrowdStrike Next-Gen...SplunkRemote work2 days per week
- ...Confiz is seeking a Security Analyst to join one of our largest clients on our Cybersecurity... ...) ~ Security Tools: ~ SIEM: Splunk (basic search), IBM QRadar (offense monitoring... ...working on highly innovative enterprise projects & products. Our customer base includes...SplunkInternshipRemote workShift work
- ...Management, or Site Reliability Engineering within a large-scale enterprise environment, preferably in the financial services industry.... ...Remedy, ServiceNow, PagerDuty) and monitoring tools (e.g., Grafana, Splunk, Dynatrace, Elk). Experience with scripting and automation (...SplunkFull timeWork at officeLocal area
$3,000 per month
...supporting the U.S. Department of State. As a Security Analyst, you will support day-to-day... ..., you will help maintain a secure enterprise environment while supporting modernization... ...Microsoft Defender, Microsoft Sentinel, Splunk, ServiceNow, Tenable Nessus, Qualys, or...SplunkContract workWork from home$98.23k - $123.77k
Role: Information Security Analyst (VTM/Vulnerability Management)Location: Dallas, TX (Must... ...& ScanningSIEM/EDR/XDR (CrowdStrike, Splunk, Elastic etc.)Defender for Endpoint, Defender... ...'s security posture across cloud and enterprise environmentsWhat We’re Looking For:...SplunkFull timeFor contractorsWork at officeLocal areaWork from homeFlexible hours- ...welfare, and unemployment insurance. Our enterprise-grade SaaS platforms power mission-... ...deliver vital public benefits efficiently, securely, and at scale. At Vimo, we create... ...alerts and events using SIEM tools (SPLUNK, Wazuh) and other security monitoring systems...SplunkRemote work
- ...to detect malicious behavior, suspicious activity, and security anomalies across the enterprise. This role is part Information Security team focused on... ...QualificationsExperience with SIEM platforms such as Microsoft Sentinel, Splunk, Exabeam, Securonix, or similar tools.Experience...SplunkLocal areaRemote workFlexible hours2 days per week3 days per week1 day per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Splunk Enterprise Security Expert. Be the first to apply!
- security consultant Remote
- security advisor Remote
- senior information security analyst Remote
- cloud security analyst Remote
- entry level security analyst Remote
- senior security consultant Remote
- aws security specialist Remote
- security analyst remote Remote
- security analyst intern Remote
- senior security specialist Remote


