Splunk Onboarding Content Engineer
Listed on 2026-08-30
-
IT/Tech
Cybersecurity
Splunk Onboarding and Content Engineer
Business Area: Information Security — Security Operations
Work Arrangement: On-site (Memphis area preferred, other metro areas where First Horizon has office space may be considered)
SummaryWe are seeking a Splunk Onboarding and Content Engineer to help application teams turn their security, audit, operational, and business logs into useful, reliable Splunk capabilities. This role will coordinate onboarding from initial discovery through production validation, then partner with application owners to develop dashboards, alerts, reports, and other content that improves visibility, investigation, compliance, and operational decision-making.
The ideal candidate combines strong stakeholder coordination with hands‑on Splunk development. You can translate business and technical questions into data requirements, guide teams through onboarding dependencies, validate that logs are usable and appropriately protected, and create practical content that application owners will adopt.
Key Responsibilities- Serve as the primary coordinator for application log onboarding into Splunk, managing intake, discovery, requirements, dependencies, testing, production readiness, and handoff.
- Partner with application owners, developers, infrastructure teams, security teams, risk partners, and vendors to identify available log sources, transport methods, environments, owners, retention needs, and priority use cases.
- Assess proposed log sources for security, audit, compliance, fraud, troubleshooting, and operational value; help teams distinguish required telemetry from low‑value or duplicative data.
- Gather and document host names, file paths, APIs, database connections, cloud services, event streams, authentication requirements, network dependencies, service accounts, and sample events needed for onboarding.
- Coordinate onboarding across common collection methods, including universal forwarders, syslog, APIs, database connectors, cloud integrations, event hubs, and supported Splunk add‑ons.
- Validate data flow, timestamp accuracy, source and source type assignment, field extraction, event breaking, permissions, completeness, and search performance.
- Normalize and enrich data using the Splunk Common Information Model, field aliases, calculated fields, tags, event types, lookups, and supporting reference data.
- Develop and maintain dashboards, alerts, correlation searches, reports, scheduled searches, drill downs, and reusable search content aligned with application‑owner needs.
- Facilitate use‑case workshops that translate questions such as who accessed an application, what administrative changes occurred, whether privileged access was elevated, and which high‑risk events require notification into Splunk content.
- Test alerts and dashboards with stakeholders, tune thresholds and logic, reduce false positives, and document expected behavior, ownership, response procedures, and escalation paths.
- Identify sensitive information in logs and coordinate with data owners and security partners to address masking, minimization, access, and retention requirements before production use.
- Troubleshoot onboarding issues involving connectivity, stale or missing data, log permissions, malformed events, unsupported platforms, add‑on compatibility, and application‑side configuration.
- Maintain onboarding status, risks, decisions, blockers, metrics, and technical documentation in the organization’s ticketing and knowledge‑management systems.
- Create runbooks, data dictionaries, dashboard guides, alert specifications, validation evidence, and support documentation that enable sustainable ownership.
- Provide demonstrations, knowledge transfer, and practical Splunk guidance to application teams so they can effectively use the content delivered for them.
- Support continuous improvement of onboarding standards, intake forms, reusable templates, quality gates, and automation.
- Experience using Splunk Enterprise or Splunk Cloud to search, analyze, visualize, and alert on machine data.
- Hands‑on proficiency with Search Processing Language, including filtering, aggregation, field extraction, lookups, time‑based analysis,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).