Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Splunk Enterprise Security Expert

Apptad Inc

Job Title: Splunk Enterprise Security Expert

Location: REMOTE

Mode : Contract (6+ Months)

Knowledge Object Governance & Lifecycle Management

  • Provide centralized oversight and authoritative governance of all Splunk knowledge objects across the enterprise SIEM environment, including saved searches, correlation searches, field extractions, tags, aliases, event types, lookups, macros, data models, workflow actions, and KV store collections.
  • Establish, publish, and enforce enterprise-wide naming conventions for all knowledge object types - ensuring consistent, parseable, and discoverable naming across teams, apps, and deployments.
  • Conduct regular audits of knowledge object libraries to identify duplicate, orphaned, deprecated, or conflicting objects - retiring obsolete content and consolidating redundant objects across teams and deployments.
  • Create custom automations to track the ingest of data, the consistent flow of the data, drift of data away from the normalization standards, etc.
  • Define and maintain a knowledge object registry/catalog that documents ownership, scope, purpose, permissions, and lifecycle stage for each object in the environment.
  • Collaborate enterprise Splunk platform teams on permission structures and sharing models - ensuring objects are accessible to the correct roles (read/write/execute) across apps, environments, and user tiers without overexposure.
  • Lead the promotion pipeline for knowledge objects from development through testing, staging, and production - establishing change control workflows aligned to CI/CD and GitOps practices (GitHub, GitHub Actions).

CIM Normalization & Data Model management

  • Serve as the CIM (Common Information Model) authority for the enterprise - defining and maintaining CIM-compliant field mappings across all ingested data sources including endpoints (EDR/AV), network (firewall, proxy, DNS), identity (IAM, AD), cloud (AWS CloudTrail, Azure Monitor, GCP Logging), and application layers.
  • Design, build, and maintain Splunk data models for Pivot users, ES correlation searches, and accelerated reporting - ensuring alignment to CIM schemas and ES asset/identity frameworks.
  • Manage data model acceleration strategies (TSIDX, tstats, summary indexing) across all production data models, monitoring for search load, acceleration lag, and coverage gaps.
  • Define and enforce source-type and index taxonomy standards - establishing lexicographic naming conventions that optimize search performance, configuration priority, and multi-team usability.
  • Ensure entity zone enrichment (asset zones, network zones, identity tiers) is properly incorporated into data models and asset/identity lookups, supporting tiered risk scoring in Enterprise Security.
  • Maintain CIM coverage matrices across all logging domains, mapping data model fields to MITRE ATT&CK techniques, detection use cases, and compliance controls.

Knowledge Architecture & Standards Program

  • Design and own the enterprise Splunk knowledge architecture - defining taxonomy hierarchies, content type standards, metadata schemas, and classification frameworks that enable findability, scalability, and governance across all teams.
  • Develop and maintain a Knowledge Management Standards document (published to internal wiki/SharePoint) covering naming conventions, object lifecycle stages, ownership models, permission templates, CIM mapping standards, and change control procedures.
  • Establish and chair a Knowledge Governance Working Group composed of representatives from Detection Engineering, SOC Operations, Platform Engineering, Compliance, and key application teams - meeting regularly to review standards, resolve conflicts, and prioritize improvements.
  • Define content type templates for correlation searches, dashboards, reports, lookups, and macros - providing reusable, pre-approved scaffolding that accelerates new content development while enforcing standards compliance.

Required Technical Skills & Technologies

Splunk Core

  • Splunk Enterprise (distributed, multi-site, clustered) deep administrative and engineering proficiency
  • Splunk Enterprise Security (ES) correlation searches, notable events, risk rules, threat intelligence, asset/identity frameworks
  • Splunk Common Information Model (CIM) - advanced normalization across all major data model domains
  • SPL (Search Processing Language) - advanced query authoring including tstats, macros, sub-searches, eval functions, streaming/non-streaming commands
  • Data Models - design, acceleration management (TSIDX), Pivot support, ES data model dependencies
  • Knowledge Objects - full lifecycle mastery: field extractions, lookups (CSV, KV Store), macros, tags, aliases, event types, workflow actions, saved searches, correlation searches
  • Splunk Apps & Add-ons - TA development/review, app packaging, deployment via Deployment Server and Deployer
  • Splunk Admin Config Service (ACS) and configuration file management (conf files, btool, precedence rules)
  • Splunk Edge Processor / Ingest Processor - pipeline-level routing and data transformation awareness

Platform & Infrastructure

  • Multi-cloud environments: AWS, Azure, GCP - log source integration, cloud-native telemetry normalization
  • Linux and Windows system administration
  • Python and Bash/Shell scripting - automation of knowledge object management, API-driven content deployment
  • GitHub / GitHub Actions / CI-CD pipelines - knowledge object version control, automated testing, promotion workflows

Frameworks & Standards

  • MITRE ATT&CK - technique mapping for detection content governance
  • NIST CSF / 800-53, CIS Benchmarks - compliance-driven knowledge requirements
  • Agile / Scrum methodology for iterative content development

Required Qualifications

  • Bachelor's degree in computer science, Information Systems, Cybersecurity, or equivalent professional experience
  • 8+ years of hands-on Splunk experience in enterprise environments
  • 3+ years of direct experience with Splunk knowledge management, CIM normalization, or SIEM content engineering in a large-scale deployment (20+ TB/day)
  • Deep expertise in Splunk Enterprise Security - correlation search authoring, ES data models, risk-based alerting
  • Demonstrated experience managing knowledge object governance at scale across multi-team, multi-app Splunk environments
  • Strong proficiency in SPL including complex statistical pipelines, accelerated searches, and macro development
  • Experience developing and enforcing enterprise naming conventions and taxonomy standards for Splunk deployments
  • Proven ability to create and maintain technical documentation - runbooks, standards guides, architecture documentation
  • Background in detection engineering, threat hunting, or SOC operations - understanding of how knowledge objects serve analysts in practice

Preferred Qualifications

  • Splunk Certifications: Splunk Core Certified Consultant, Splunk Enterprise Security Certified Admin (SPLK-3001), Splunk Certified Architect - one or more strongly preferred
  • Security Certifications: GIAC (GCIA, GCIH, GCED), or equivalent
  • Experience with Splunk SOAR (Phantom) playbook development, orchestration, and knowledge integration
  • Familiarity with Splunk UBA and behavioral analytics model management
  • Experience in healthcare or highly regulated industries (HIPAA, Federal (NIST), NYDFS, PCI)
  • Experience with infrastructure-as-code tools (Ansible, Terraform) for Splunk configuration management
  • Proficiency with LLM-powered tooling and AI-assisted automation for knowledge retrieval and content management
  • Experience supporting Splunk deployments in environments with 10,000+ users and multi-petabyte data retention
  • Familiarity with Kafka, streaming data pipelines, and real-time telemetry routing
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Splunk Enterprise Security Expert in Remote vacancy
  •  ...Splunk Enterprise Security (ES) Consultant - remote Remote – offsite Responsibilities Develop custom detection content: correlation searches, notable events, alerts, reports, and visualizations to surface threat activity Build and maintain Splunk Apps and... 
    Splunk
    Temporary work
    Local area
    Remote work
    Night shift

    System One

    Arlington, WI
    a month ago
  • $90 per hour

     ...Position: Cybersecurity Expert Type: Contract Compensation...  ...scenarios spanning security operations center monitoring...  ...tools such as SIEM platforms ( Splunk , Microsoft Sentinel ), EDR...  ...GRC platforms used at major enterprises. Apply cybersecurity methodologies... 
    Splunk
    Contract work
    Summer work
    Remote work

    Mercor

    San Francisco, CA
    7 days ago
  •  ...Our partner is looking for a Senior Security Subject Matter Expert (AI/ML, Cloud & Security) based in United...  ...activities using platforms such as Splunk, Security Onion, Tenable, or...  ...architectures. Practical experience with enterprise security technologies such as Splunk... 
    Splunk
    Full time
    Remote work

    jobgether

    United States
    4 days ago
  •  ...Description About Workato Workato delivers enterprise infrastructure for the agentic era,...  ...orchestration at scale. With enterprise-grade security and continuous innovation at its core,...  ...integrations to SIEM tools such as Splunk, Datadog, and cloud storage platforms.... 
    Splunk
    Remote work
    Flexible hours

    Workato

    Palo Alto, CA
    2 days ago
  • $1,000 per month

     ...Account Manager - Security Solutions (Enterprise) Location : Chicago, IL (remote office) Company : Global Leader in Security Solutions (OEM;...  ...from Palo Alto, A10, FireEye, RSA, Fortinet, ExtraHop, F5, Splunk, NetScout, Akamai, HP, Imperva, Proofpoint, Zscaler, Cloudflare... 
    Splunk
    Permanent employment
    Full time
    Work at office
    Remote work
    Work from home

    MRINetwork Jobs

    West Chicago, IL
    a month ago
  • $130k - $140k

     ...motivated Senior ServiceNow and Enterprise Tools Support Specialist to...  ...our USSS Network Operations and Security Center (NOSC) proposal. This role...  ...level IT tools (e.g., SolarWinds, Splunk, SCCM, AppDynamics).Serve as a subject matter expert (SME) for the ServiceNow... 
    Splunk
    Remote work

    Govcio

    Washington DC
    2 days ago
  •  ...well, Please find the job description given below and let me know your interest. Position: SOC Consultant with Splunk Enterprise Security (ES) (Remote) Location: Remote Duration : 6+ months Job Description: ~6 7+ years of experience... 
    Splunk
    Remote work

    DMS Vision Inc

    Frisco, TX
    4 days ago
  • $96.9k - $136.8k

     ...identify possible threats, risks or security control gaps to the enterprise and produce detection & mitigation recommendations...  ...role is considered a subject matter expert for hunting via host-based and...  ...Detection & Response tooling; Splunk ES, CrowdStrike, Logscale, Defender... 
    Splunk
    Full time
    Work from home

    TD Bank

    Mount Laurel, NJ
    3 days ago
  • $180k - $195k

     ...missions. Our staff include experts in astronomy, engineering, education...  ...space.STScI is seeking an Enterprise Technology Lead to set the...  ...running enterprise IT.Identity, Security & AI GovernanceGovern...  ...platform experience (Datadog, Splunk, or CrowdStrike) preferred.Experience... 
    Splunk
    Permanent employment
    Full time
    Remote work
    Flexible hours
    3 days per week

    Space Telescope Science Institute

    Baltimore, MD
    3 days ago
  • Software Engineer: Enterprise Tools Engineering Architect - APM, Infrastructure, and Observability PlatformsWork Location: Onsite, Framingham...  ...health.Proven experience with log analytics platforms (e.g., Splunk, Elastic), including data ingestion, routing, indexing... 
    Splunk
    Local area

    Staples

    Framingham, MA
    5 days ago
  •  ...of successful mission support to improve security, streamline logistics, and enhance...  ...while operating, maintaining, and deploying enterprise cyber tools.ResponsibilitiesResponsiblities...  ...Federal GovernmentHands-on with: ACAS, Splunk, ESS, Cisco ASA Firewalls & Firepower... 
    Splunk
    Remote work

    V2X

    Orlando, FL
    3 days ago
  • $86.8k - $198k

    Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton...  ...externally facing vulnerabilities and security misconfigurations across the Booz Allen...  ...including QualysExperience with Splunk, including building search queriesKnowledge... 
    Splunk
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    2 days ago
  • $100k - $135k

     ...galaxy beyond our planet. About the RoleThe Enterprise Security Engineer is responsible for designing,...  ...as a cybersecurity subject matter expert for technical and business stakeholders...  ...Security OperationsSIEM Platforms (Elastic,Splunk)Endpoint Detection & Response (EDR/XDR)... 
    Splunk
    Full time
    Work at office

    Apex Technology

    Los Angeles, CA
    1 day ago
  •  ...We are currently seeking a Security Analysis Specialist Advisor to...  ...Monitor user behaviour across enterprise systems, applications, endpoints...  ...SIEM platforms (Splunk, Microsoft Sentinel, QRadar,...  ...Global Top Employer, we have experts in more than 50 countries. We... 
    Splunk
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    NTT DATA, Inc.

    Dallas, TX
    17 days ago
  • $86.8k - $198k

    Enterprise Cybersecurity Automation EngineerThe Opportunity:​Cyber threats are everywhere,...  ...clients? The answer is you, help us develop security automation solutions that provide...  ...including security management tools such as Splunk, Carbon Black, CrowdStrike, Nitro, or ArcSight... 
    Splunk
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    10 hours ago
  • $85k - $90k

     ...are seeking an experienced Information Security Analyst to support security operations,...  ...and security automation within a complex enterprise environment.This is a hands-on technical...  ...SIEM and log-analysis platforms such as Splunk, Elastic/OpenSearch, Kibana, and Microsoft... 
    Splunk
    Remote work
    Visa sponsorship
    Free visa

    NPAworldwide

    Syracuse, NY
    4 hours ago
  • $139.1k - $188.2k

     ...just work - through fast, reliable, secure connectivity. As eero expands into the enterprise space, serving corporate offices,...  ..., you will:- Serve as an expert on enterprise networking, fleet monitoring...  ..., Datadog, New Relic and Splunk- CCNA or equivalent level networking... 
    Splunk
    Work experience placement
    Local area
    Work from home
    Flexible hours

    Amazon

    San Francisco, CA
    1 day ago
  •  ...is a minority and women-owned business enterprise (MWBE) committed to maximizing global workforce...  ...and insightful market intelligence has secured long-term partnerships with Fortune 500...  ...knowledge of analyzing events from SPLUNK SIEM. • Ability to work shift work in a... 
    Splunk
    Work experience placement
    Local area
    Remote work
    All shifts
    Shift work

    Artech

    Plano, TX
    4 days ago
  • Enterprise Monitoring Systems Administrator CI Infrastructure Services (CIS) is looking for...  ..., resilience, and efficiency Implement secure configuration baselines, system hardening...  ...monitoring platforms (SolarWinds, Splunk, Elastic/ELK, Dynatrace, AppDynamics, Nagios... 
    Splunk
    Remote work

    General Dynamics Information Technology

    Annapolis, MD
    1 day ago
  •  ...L2 Security Analyst Full‑Time, on‑site We are looking for a Senior Security Analyst (L2)...  ...a SIEM (RSA NetWitness, Azure Sentinel, Splunk, etc.) Strong understanding of incident...  ...performing triage/incident response in enterprise environments Minimum of 3+ years of experience... 
    Splunk
    Full time

    LumiFi

    Scottsdale, AZ
    4 days ago
  • $3,600 per month

     ...Are you a seasoned security professional passionate about protecting organizations from...  ...threat detection initiatives across the enterprise. You’ll also help shape our approach to...  ...CrowdStrike Next Gen SIEM, Microsoft Sentinel, Splunk, or QRadar). ~ Strong analytical,... 
    Splunk
    Full time
    Immediate start

    Kinsale Management, Inc

    Remote
    1 day ago
  •  ...generation of predictive and agentic AI for enterprise IT operations. We’re hiring a hands‑on...  ...and adopt. You do not need to be an AI expert on day one. What matters most is strong...  ...ecosystems (e.g., Datadog, Dynatrace, Splunk, ServiceNow, Jira, Ansible). 4. Go to Market... 
    Splunk
    Remote work

    Grokstream LLC

    New York, NY
    4 days ago
  •  ...Confiz is seeking a Security Analyst to join one of our largest clients on our Cybersecurity...  ...)  ~ Security Tools:  ~ SIEM: Splunk (basic search), IBM QRadar (offense monitoring...  ...working on highly innovative enterprise projects & products. Our customer base includes... 
    Splunk
    Internship
    Remote work
    Shift work

    Confiz

    United States
    4 days ago
  • $129.3k - $177.8k

     ...a part of our caring communityWhy Join Enterprise Observability Engineering?The Enterprise...  .... While familiarity with platforms like Splunk or Dynatrace is a plus, we value platform...  ...challenges. You’ll work closely with SRE, Security, Networking, Platform Engineering, and... 
    Splunk
    Full time
    Temporary work
    Apprenticeship
    Work at office
    Remote work
    Work from home
    Home office

    Humana

    Boston, MA
    4 hours ago
  • $125k

     ...a highly skilled and strategic Senior Information Security Analyst to spearhead the protection of our enterprise data, systems, and hybrid infrastructure (On-Premise...  ...security scorecards, SIEM tools and dashboards (Splunk, QRadar, Rapid7, Wazhu)  ~ Experience with OneTrust... 
    Splunk
    Full time
    Work at office
    Immediate start
    Night shift

    Vesync

    Remote
    1 day ago
  •  ...CITIZEN ONLY. SECRET CLEARANCE REQUIRED. MUST HAVE IT-II CERT (IE SECURITY+) SIEM/Elastic Specialist will: • Be responsible for...  ...years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts... 
    Splunk
    Full time

    Diligent Consulting

    Remote
    1 day ago
  •  ...Description OverviewThe Senior Information Security Analyst is a senior individual...  ...hunting, and the continuous improvement of enterprise security operations. The role works across...  ...including EDR and/or Identity Protection• Splunk Enterprise Security, CrowdStrike Next-Gen... 
    Splunk
    Remote work
    2 days per week

    Perrigo

    Allegan, MI
    3 days ago
  •  ...Management, or Site Reliability Engineering within a large-scale enterprise environment, preferably in the financial services industry....  ...Remedy, ServiceNow, PagerDuty) and monitoring tools (e.g., Grafana, Splunk, Dynatrace, Elk). Experience with scripting and automation (... 
    Splunk
    Full time
    Work at office
    Local area

    DBS Bank Ltd

    Remote
    3 days ago
  •  ...Security Analyst (Tier 2) Security Operations Center Analyst Location: Remote Duration...  ...hunting activities. Experience with Devo, Splunk, Azure Sentinel or other SIEM technology...  ...alerts from various sources within the enterprise and determine possible causes of such... 
    Splunk
    Immediate start
    Remote work
    Night shift
    Rotating shift

    TriOptus LLC

    United States
    3 days ago
  • $60 - $65 per hour

     ...60.00/hr - $65.00/hr Title: Information Security Analyst Duration: 12+ months contract Hybrid...  ...and deploy capabilities that protect enterprise systems and data with the necessary...  ...Azure AD, AWS IAM), and event management (Splunk). Expertise in using Microsoft Office suite... 
    Splunk
    Contract work
    Work at office
    Local area
    Work from home

    iSpace

    Los Angeles, CA
    6 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Splunk Enterprise Security Expert. Be the first to apply!