Splunk Enterprise Security Expert
Apptad Inc
Job Title: Splunk Enterprise Security Expert
Location: REMOTE
Mode : Contract (6+ Months)
Knowledge Object Governance & Lifecycle Management
- Provide centralized oversight and authoritative governance of all Splunk knowledge objects across the enterprise SIEM environment, including saved searches, correlation searches, field extractions, tags, aliases, event types, lookups, macros, data models, workflow actions, and KV store collections.
- Establish, publish, and enforce enterprise-wide naming conventions for all knowledge object types - ensuring consistent, parseable, and discoverable naming across teams, apps, and deployments.
- Conduct regular audits of knowledge object libraries to identify duplicate, orphaned, deprecated, or conflicting objects - retiring obsolete content and consolidating redundant objects across teams and deployments.
- Create custom automations to track the ingest of data, the consistent flow of the data, drift of data away from the normalization standards, etc.
- Define and maintain a knowledge object registry/catalog that documents ownership, scope, purpose, permissions, and lifecycle stage for each object in the environment.
- Collaborate enterprise Splunk platform teams on permission structures and sharing models - ensuring objects are accessible to the correct roles (read/write/execute) across apps, environments, and user tiers without overexposure.
- Lead the promotion pipeline for knowledge objects from development through testing, staging, and production - establishing change control workflows aligned to CI/CD and GitOps practices (GitHub, GitHub Actions).
CIM Normalization & Data Model management
- Serve as the CIM (Common Information Model) authority for the enterprise - defining and maintaining CIM-compliant field mappings across all ingested data sources including endpoints (EDR/AV), network (firewall, proxy, DNS), identity (IAM, AD), cloud (AWS CloudTrail, Azure Monitor, GCP Logging), and application layers.
- Design, build, and maintain Splunk data models for Pivot users, ES correlation searches, and accelerated reporting - ensuring alignment to CIM schemas and ES asset/identity frameworks.
- Manage data model acceleration strategies (TSIDX, tstats, summary indexing) across all production data models, monitoring for search load, acceleration lag, and coverage gaps.
- Define and enforce source-type and index taxonomy standards - establishing lexicographic naming conventions that optimize search performance, configuration priority, and multi-team usability.
- Ensure entity zone enrichment (asset zones, network zones, identity tiers) is properly incorporated into data models and asset/identity lookups, supporting tiered risk scoring in Enterprise Security.
- Maintain CIM coverage matrices across all logging domains, mapping data model fields to MITRE ATT&CK techniques, detection use cases, and compliance controls.
Knowledge Architecture & Standards Program
- Design and own the enterprise Splunk knowledge architecture - defining taxonomy hierarchies, content type standards, metadata schemas, and classification frameworks that enable findability, scalability, and governance across all teams.
- Develop and maintain a Knowledge Management Standards document (published to internal wiki/SharePoint) covering naming conventions, object lifecycle stages, ownership models, permission templates, CIM mapping standards, and change control procedures.
- Establish and chair a Knowledge Governance Working Group composed of representatives from Detection Engineering, SOC Operations, Platform Engineering, Compliance, and key application teams - meeting regularly to review standards, resolve conflicts, and prioritize improvements.
- Define content type templates for correlation searches, dashboards, reports, lookups, and macros - providing reusable, pre-approved scaffolding that accelerates new content development while enforcing standards compliance.
Required Technical Skills & Technologies
Splunk Core
- Splunk Enterprise (distributed, multi-site, clustered) deep administrative and engineering proficiency
- Splunk Enterprise Security (ES) correlation searches, notable events, risk rules, threat intelligence, asset/identity frameworks
- Splunk Common Information Model (CIM) - advanced normalization across all major data model domains
- SPL (Search Processing Language) - advanced query authoring including tstats, macros, sub-searches, eval functions, streaming/non-streaming commands
- Data Models - design, acceleration management (TSIDX), Pivot support, ES data model dependencies
- Knowledge Objects - full lifecycle mastery: field extractions, lookups (CSV, KV Store), macros, tags, aliases, event types, workflow actions, saved searches, correlation searches
- Splunk Apps & Add-ons - TA development/review, app packaging, deployment via Deployment Server and Deployer
- Splunk Admin Config Service (ACS) and configuration file management (conf files, btool, precedence rules)
- Splunk Edge Processor / Ingest Processor - pipeline-level routing and data transformation awareness
Platform & Infrastructure
- Multi-cloud environments: AWS, Azure, GCP - log source integration, cloud-native telemetry normalization
- Linux and Windows system administration
- Python and Bash/Shell scripting - automation of knowledge object management, API-driven content deployment
- GitHub / GitHub Actions / CI-CD pipelines - knowledge object version control, automated testing, promotion workflows
Frameworks & Standards
- MITRE ATT&CK - technique mapping for detection content governance
- NIST CSF / 800-53, CIS Benchmarks - compliance-driven knowledge requirements
- Agile / Scrum methodology for iterative content development
Required Qualifications
- Bachelor's degree in computer science, Information Systems, Cybersecurity, or equivalent professional experience
- 8+ years of hands-on Splunk experience in enterprise environments
- 3+ years of direct experience with Splunk knowledge management, CIM normalization, or SIEM content engineering in a large-scale deployment (20+ TB/day)
- Deep expertise in Splunk Enterprise Security - correlation search authoring, ES data models, risk-based alerting
- Demonstrated experience managing knowledge object governance at scale across multi-team, multi-app Splunk environments
- Strong proficiency in SPL including complex statistical pipelines, accelerated searches, and macro development
- Experience developing and enforcing enterprise naming conventions and taxonomy standards for Splunk deployments
- Proven ability to create and maintain technical documentation - runbooks, standards guides, architecture documentation
- Background in detection engineering, threat hunting, or SOC operations - understanding of how knowledge objects serve analysts in practice
Preferred Qualifications
- Splunk Certifications: Splunk Core Certified Consultant, Splunk Enterprise Security Certified Admin (SPLK-3001), Splunk Certified Architect - one or more strongly preferred
- Security Certifications: GIAC (GCIA, GCIH, GCED), or equivalent
- Experience with Splunk SOAR (Phantom) playbook development, orchestration, and knowledge integration
- Familiarity with Splunk UBA and behavioral analytics model management
- Experience in healthcare or highly regulated industries (HIPAA, Federal (NIST), NYDFS, PCI)
- Experience with infrastructure-as-code tools (Ansible, Terraform) for Splunk configuration management
- Proficiency with LLM-powered tooling and AI-assisted automation for knowledge retrieval and content management
- Experience supporting Splunk deployments in environments with 10,000+ users and multi-petabyte data retention
- Familiarity with Kafka, streaming data pipelines, and real-time telemetry routing
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Splunk Enterprise Security Expert in Remote vacancy
- ...Splunk Enterprise Security (ES) Consultant - remote Remote – offsite Responsibilities Develop custom detection content: correlation searches, notable events, alerts, reports, and visualizations to surface threat activity Build and maintain Splunk Apps and...SplunkTemporary workLocal areaRemote workNight shift
$90 per hour
...Position: Cybersecurity Expert Type: Contract Compensation... ...scenarios spanning security operations center monitoring... ...tools such as SIEM platforms ( Splunk , Microsoft Sentinel ), EDR... ...GRC platforms used at major enterprises. Apply cybersecurity methodologies...SplunkContract workSummer workRemote work- ...Our partner is looking for a Senior Security Subject Matter Expert (AI/ML, Cloud & Security) based in United... ...activities using platforms such as Splunk, Security Onion, Tenable, or... ...architectures. Practical experience with enterprise security technologies such as Splunk...SplunkFull timeRemote work
- ...Description About Workato Workato delivers enterprise infrastructure for the agentic era,... ...orchestration at scale. With enterprise-grade security and continuous innovation at its core,... ...integrations to SIEM tools such as Splunk, Datadog, and cloud storage platforms....SplunkRemote workFlexible hours
$1,000 per month
...Account Manager - Security Solutions (Enterprise) Location : Chicago, IL (remote office) Company : Global Leader in Security Solutions (OEM;... ...from Palo Alto, A10, FireEye, RSA, Fortinet, ExtraHop, F5, Splunk, NetScout, Akamai, HP, Imperva, Proofpoint, Zscaler, Cloudflare...SplunkPermanent employmentFull timeWork at officeRemote workWork from home$130k - $140k
...motivated Senior ServiceNow and Enterprise Tools Support Specialist to... ...our USSS Network Operations and Security Center (NOSC) proposal. This role... ...level IT tools (e.g., SolarWinds, Splunk, SCCM, AppDynamics).Serve as a subject matter expert (SME) for the ServiceNow...SplunkRemote work- ...well, Please find the job description given below and let me know your interest. Position: SOC Consultant with Splunk Enterprise Security (ES) (Remote) Location: Remote Duration : 6+ months Job Description: ~6 7+ years of experience...SplunkRemote work
$96.9k - $136.8k
...identify possible threats, risks or security control gaps to the enterprise and produce detection & mitigation recommendations... ...role is considered a subject matter expert for hunting via host-based and... ...Detection & Response tooling; Splunk ES, CrowdStrike, Logscale, Defender...SplunkFull timeWork from home$180k - $195k
...missions. Our staff include experts in astronomy, engineering, education... ...space.STScI is seeking an Enterprise Technology Lead to set the... ...running enterprise IT.Identity, Security & AI GovernanceGovern... ...platform experience (Datadog, Splunk, or CrowdStrike) preferred.Experience...SplunkPermanent employmentFull timeRemote workFlexible hours3 days per week- Software Engineer: Enterprise Tools Engineering Architect - APM, Infrastructure, and Observability PlatformsWork Location: Onsite, Framingham... ...health.Proven experience with log analytics platforms (e.g., Splunk, Elastic), including data ingestion, routing, indexing...SplunkLocal area
- ...of successful mission support to improve security, streamline logistics, and enhance... ...while operating, maintaining, and deploying enterprise cyber tools.ResponsibilitiesResponsiblities... ...Federal GovernmentHands-on with: ACAS, Splunk, ESS, Cisco ASA Firewalls & Firepower...SplunkRemote work
$86.8k - $198k
Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton... ...externally facing vulnerabilities and security misconfigurations across the Booz Allen... ...including QualysExperience with Splunk, including building search queriesKnowledge...SplunkFull timeContract workPart timeWork at officeLocal areaRemote work$100k - $135k
...galaxy beyond our planet. About the RoleThe Enterprise Security Engineer is responsible for designing,... ...as a cybersecurity subject matter expert for technical and business stakeholders... ...Security OperationsSIEM Platforms (Elastic,Splunk)Endpoint Detection & Response (EDR/XDR)...SplunkFull timeWork at office- ...We are currently seeking a Security Analysis Specialist Advisor to... ...Monitor user behaviour across enterprise systems, applications, endpoints... ...SIEM platforms (Splunk, Microsoft Sentinel, QRadar,... ...Global Top Employer, we have experts in more than 50 countries. We...SplunkWork experience placementWork at officeRemote workFlexible hours
$86.8k - $198k
Enterprise Cybersecurity Automation EngineerThe Opportunity:Cyber threats are everywhere,... ...clients? The answer is you, help us develop security automation solutions that provide... ...including security management tools such as Splunk, Carbon Black, CrowdStrike, Nitro, or ArcSight...SplunkFull timeContract workPart timeWork at officeLocal areaRemote work$85k - $90k
...are seeking an experienced Information Security Analyst to support security operations,... ...and security automation within a complex enterprise environment.This is a hands-on technical... ...SIEM and log-analysis platforms such as Splunk, Elastic/OpenSearch, Kibana, and Microsoft...SplunkRemote workVisa sponsorshipFree visa$139.1k - $188.2k
...just work - through fast, reliable, secure connectivity. As eero expands into the enterprise space, serving corporate offices,... ..., you will:- Serve as an expert on enterprise networking, fleet monitoring... ..., Datadog, New Relic and Splunk- CCNA or equivalent level networking...SplunkWork experience placementLocal areaWork from homeFlexible hours- ...is a minority and women-owned business enterprise (MWBE) committed to maximizing global workforce... ...and insightful market intelligence has secured long-term partnerships with Fortune 500... ...knowledge of analyzing events from SPLUNK SIEM. • Ability to work shift work in a...SplunkWork experience placementLocal areaRemote workAll shiftsShift work
- Enterprise Monitoring Systems Administrator CI Infrastructure Services (CIS) is looking for... ..., resilience, and efficiency Implement secure configuration baselines, system hardening... ...monitoring platforms (SolarWinds, Splunk, Elastic/ELK, Dynatrace, AppDynamics, Nagios...SplunkRemote work
- ...L2 Security Analyst Full‑Time, on‑site We are looking for a Senior Security Analyst (L2)... ...a SIEM (RSA NetWitness, Azure Sentinel, Splunk, etc.) Strong understanding of incident... ...performing triage/incident response in enterprise environments Minimum of 3+ years of experience...SplunkFull time
$3,600 per month
...Are you a seasoned security professional passionate about protecting organizations from... ...threat detection initiatives across the enterprise. You’ll also help shape our approach to... ...CrowdStrike Next Gen SIEM, Microsoft Sentinel, Splunk, or QRadar). ~ Strong analytical,...SplunkFull timeImmediate start- ...generation of predictive and agentic AI for enterprise IT operations. We’re hiring a hands‑on... ...and adopt. You do not need to be an AI expert on day one. What matters most is strong... ...ecosystems (e.g., Datadog, Dynatrace, Splunk, ServiceNow, Jira, Ansible). 4. Go to Market...SplunkRemote work
- ...Confiz is seeking a Security Analyst to join one of our largest clients on our Cybersecurity... ...) ~ Security Tools: ~ SIEM: Splunk (basic search), IBM QRadar (offense monitoring... ...working on highly innovative enterprise projects & products. Our customer base includes...SplunkInternshipRemote workShift work
$129.3k - $177.8k
...a part of our caring communityWhy Join Enterprise Observability Engineering?The Enterprise... .... While familiarity with platforms like Splunk or Dynatrace is a plus, we value platform... ...challenges. You’ll work closely with SRE, Security, Networking, Platform Engineering, and...SplunkFull timeTemporary workApprenticeshipWork at officeRemote workWork from homeHome office$125k
...a highly skilled and strategic Senior Information Security Analyst to spearhead the protection of our enterprise data, systems, and hybrid infrastructure (On-Premise... ...security scorecards, SIEM tools and dashboards (Splunk, QRadar, Rapid7, Wazhu) ~ Experience with OneTrust...SplunkFull timeWork at officeImmediate startNight shift- ...CITIZEN ONLY. SECRET CLEARANCE REQUIRED. MUST HAVE IT-II CERT (IE SECURITY+) SIEM/Elastic Specialist will: • Be responsible for... ...years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts...SplunkFull time
- ...Description OverviewThe Senior Information Security Analyst is a senior individual... ...hunting, and the continuous improvement of enterprise security operations. The role works across... ...including EDR and/or Identity Protection• Splunk Enterprise Security, CrowdStrike Next-Gen...SplunkRemote work2 days per week
- ...Management, or Site Reliability Engineering within a large-scale enterprise environment, preferably in the financial services industry.... ...Remedy, ServiceNow, PagerDuty) and monitoring tools (e.g., Grafana, Splunk, Dynatrace, Elk). Experience with scripting and automation (...SplunkFull timeWork at officeLocal area
- ...Security Analyst (Tier 2) Security Operations Center Analyst Location: Remote Duration... ...hunting activities. Experience with Devo, Splunk, Azure Sentinel or other SIEM technology... ...alerts from various sources within the enterprise and determine possible causes of such...SplunkImmediate startRemote workNight shiftRotating shift
$60 - $65 per hour
...60.00/hr - $65.00/hr Title: Information Security Analyst Duration: 12+ months contract Hybrid... ...and deploy capabilities that protect enterprise systems and data with the necessary... ...Azure AD, AWS IAM), and event management (Splunk). Expertise in using Microsoft Office suite...SplunkContract workWork at officeLocal areaWork from home
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Splunk Enterprise Security Expert. Be the first to apply!
Related searches
- security consultant Remote
- security advisor Remote
- senior information security analyst Remote
- cloud security analyst Remote
- entry level security analyst Remote
- physical security specialist Remote
- senior security consultant Remote
- aws security specialist Remote
- security analyst remote Remote
- security analyst intern Remote



