×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Senior SIEM Engineer - Splunk

Job in Washington, District of Columbia, 20022, USA
Listing for: Quantum Sky
Full Time position
Listed on 2026-09-19
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 145000 - 155000 USD Yearly USD 145000.00 155000.00 YEAR
Job Description & How to Apply Below

Description

Quantum Sky is searching for a Senior SIEM Engineer to own the architecture, strategy, and long-term health of the organization's Splunk deployment, setting standards for detection engineering, data onboarding, and platform scalability. This role operates with autonomy, mentors mid-level engineers, and partners directly with security leadership to align Splunk's capability with the broader detection and response strategy.

Theseniorengineeristhe escalation point for complex platform issues, distributed environment troubleshooting, and high-priority incidents.

Responsibilities

  • Design and own the overall Splunk architecture, including indexer clustering, search head clustering, forwarder tiering, and storage/retention (includingSmartStorewhere applicable) strategy
  • Lead detection engineering strategy within Splunk ES: prioritize correlation search development based on threat intelligence, risk assessments, and gaps in coverage
  • Establish and enforce standards for data onboarding, CIM normalization, field extraction quality, and correlation search performance
  • Drive Splunk platform upgrades, app/add-on management, and integrations with other security tools (SOAR platforms, threat intel feeds, EDR, ticketing systems)
  • Optimize search performance and indexing strategy to manage license usage and infrastructure cost at scale
  • Mentor andprovidetechnical guidance to mid-level SIEM engineers and SOC analysts on SPL, use case design, and Splunk best practices
  • Serve as the technical escalation point for complex investigations and major incidents requiring deep Splunkexpertise
  • Evaluate and recommend new Splunk apps, premium solutions,or architectural changes
  • Own Splunk-related metrics and reporting for leadership (detection coverage, mean time to detect, platform performance, license/cost efficiency)
  • Lead threat hunting initiatives using advanced SPL, data models, and Splunk's pivot/statistical functions
  • Ensure Splunk configuration and processes support audit and compliance requirements (e.g., PCI-DSS, HIPAA, SOC 2, NIST)
  • Represent the SIEM/detection function in cross-functional security architecture and incident response planning
Qualifications

Required:

  • Bachelor's Degree required(experience and education equivalents are considered and can be substituted for aBachelor's Degree.
  • 8 years of general work experience with 6 years relevant “functional” experience in security operations or detection engineering, with substantial hands-on Splunk ownership, including at least some experience in distributed/clustered environments
  • Advancedproficiencyin SPL, including complex correlation searches, data models, and search optimization for large-scale environments
  • Deep working knowledge of Splunk architecture (indexer/search head clustering, forwarder management, index design) and Splunk Enterprise Security if deployed
  • Strong understanding of the MITRE ATT&CK framework, cyber kill chain, and threat modeling
  • Demonstrated experience designing detection strategies within Splunk, not just implementing individual searches
  • Strong scripting/automation skills (Python, Power Shell) and familiarity with SOAR platform integration (e.g., Splunk SOAR, if in use)
  • Experience with cloud security monitoring (AWS, Azure, or GCP log sources) and Splunk's cloud-specific add-ons
  • Track recordof leading or significantly contributing to incident response investigations
  • Familiarity with compliance frameworks relevant to the organization's industry
  • Relevant certifications preferred:
    Splunk Core Certified Advanced Power User, Splunk Certified Architect, Splunk Enterprise Security Certified Admin, GCIA, GCIH, GCFA, or CISSP

Desired:

  • Experience with Splunk in aVMwareESXi, vCenter virtual infrastructure
  • Experience or working knowledge with similar SIEM tools

Cleara…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary