×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Splunk Enterprise Security Expert

Job in Cary, Wake County, North Carolina, 27518, USA
Listing for: CYNET SYSTEMS
Full Time position
Listed on 2026-09-12
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 47 - 52 USD Hourly USD 47.00 52.00 HOUR
Job Description & How to Apply Below
Job Overview:
Pay Range: $47.00hr - $52.00hr Requirement/Must Have: 8+ years of hands-on Splunk experience in enterprise environments. 3+ years of direct experience with Splunk knowledge management, CIM normalization, or SIEM content engineering in a large-scale deployment (20+ TB/day). Deep expertise in Splunk Enterprise Security, including correlation search authoring, ES data models, and risk-based alerting. Demonstrated experience managing knowledge object governance at scale across multi-team, multi-app Splunk environments.

Strong proficiency in SPL including complex statistical pipelines, accelerated searches, and macro development. Experience developing and enforcing enterprise naming conventions and taxonomy standards for Splunk deployments. Proven ability to create and maintain technical documentation such as runbooks, standards guides, and architecture documentation. Background in detection engineering, threat hunting, or SOC operations with an understanding of how knowledge objects serve analysts in practice.

Deep administrative and engineering proficiency with Splunk Enterprise (distributed, multi-site, clustered). Advanced normalization across all major data model domains using Splunk Common Information Model (CIM). Full lifecycle mastery of Knowledge Objects including field extractions, lookups (CSV, KV Store), macros, tags, aliases, event types, workflow actions, and saved searches.

Experience with Splunk Apps & Add-ons, including TA development/review, app packaging, and deployment via Deployment Server and Deployer. Proficiency with Splunk Admin Config Service (ACS) and configuration file management (conf files, btool, precedence rules). Awareness of Splunk Edge Processor / Ingest Processor for pipeline-level routing and data transformation.

Experience with multi-cloud environments including AWS, Azure, and GCP for log source integration and cloud-native telemetry normalization. Linux and Windows system administration skills. Python and Bash/Shell scripting skills for automation of knowledge object management and API-driven content deployment.

Experience with Git Hub, Git Hub Actions, and CI-CD pipelines for knowledge object version control and promotion workflows. Knowledge of MITRE ATT&CK for technique mapping for detection content governance. Knowledge of NIST CSF / 800-53 and CIS Benchmarks for compliance-driven requirements.

Experience with Agile / Scrum methodology for iterative content development. Responsibilities:
Provide centralized oversight and authoritative governance of all Splunk knowledge objects across the enterprise SIEM environment. Establish, publish, and enforce enterprise-wide naming conventions for all knowledge object types to ensure consistency across teams and deployments. Conduct regular audits of knowledge object libraries to identify and retire duplicate, orphaned, deprecated, or conflicting objects. Create custom automations to track data ingest, consistent flow, and drift from normalization standards.

Define and maintain a knowledge object registry/catalog documenting ownership, scope, purpose, permissions, and lifecycle stages. Collaborate with platform teams on permission structures and sharing models to ensure secure access across environments. Lead the promotion pipeline for knowledge objects from development through production using CI/CD and Git Ops practices. Serve as the CIM authority for the enterprise, defining and maintaining compliant field mappings across all ingested data sources.

Design, build, and maintain Splunk data models for Pivot users, ES correlation searches, and accelerated reporting. Manage data model acceleration strategies across all production data models, monitoring for search load and coverage gaps. Define and enforce source-type and index taxonomy standards to optimize search performance and multi-team usability. Ensure entity zone enrichment is properly incorporated into data models and asset/identity lookups.

Maintain CIM coverage matrices across all logging domains, mapping fields to MITRE ATT&CK techniques and compliance controls. Design and own the enterprise Splunk knowledge architecture, defining taxonomy hierarchies and classification frameworks. Develop and maintain a Knowledge Management Standards document covering naming conventions and change control procedures. Establish and chair a Knowledge Governance Working Group to review standards and prioritize improvements.

Define content type templates for correlation searches,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary