Senior Splunk Engineer
# Senior Splunk Engineer **EnSolutions Inc** · Suitland, MD 20746 · `On-site` 🕒 **Статус:** *Опубликовано: 2 дня назад* · *Источник: Indeed* --- ### About the Role Splunk Engineer (UEBA/UBA Focus)Position Summary We are seeking a highly skilled Splunk Engineer with hands-on experience designing, implementing, and optimizing Splunk Enterprise Security (ES) and User and Entity Behavior Analytics (UEBA/UBA) solutions. This role will be responsible for building scalable security monitoring capabilities, developing advanced detection content, integrating diverse data sources, and enhancing threat detection through behavioral analytics. The ideal candidate will have deep expertise in Splunk architecture, security operations, threat detection engineering, and behavioral analytics methodologies to support enterprise cybersecurity initiatives. Key Responsibilities: Splunk Platform Engineering Design, deploy, configure, and maintain Splunk Enterprise and Splunk Enterprise Security environments. Manage distributed Splunk architectures including indexers, search heads, heavy forwarders, deployment servers, and cluster configurations. Develop and maintain Splunk data onboarding pipelines for security, infrastructure, cloud, and application logs. Optimize Splunk performance, data retention strategies, indexing, and search efficiency. Create dashboards, reports, visualizations, and executive-level security metrics. UEBA / UBA Administration Implement, configure, and maintain Splunk UEBA (or legacy UBA) environments. Develop behavioral models and anomaly detection use cases for insider threat, account compromise, privilege misuse, and lateral movement detection. Tune anomaly scoring models to reduce false positives and improve detection fidelity. Integrate identity, authentication, endpoint, cloud, and network telemetry into UEBA models. Collaborate with SOC analysts and threat hunters to validate and enhance behavioral detections. Detection Engineering Develop and maintain correlation searches, risk-based alerting (RBA) content, and custom detections in Splunk Enterprise Security. Create and optimize Security Content Framework use cases aligned with MITRE ATT&CK. Develop custom SPL queries, macros, lookups, data models, and accelerated searches. Implement risk-based monitoring and improve detection coverage across enterprise environments. Support threat hunting and incident response investigations. Pay: From $150,000.00 per year License/Certification: DoD 8570 (Preferred) Security clearance: Top Secret (Required) Work Location: Hybrid remote in Suitland, MD 20746
Наблюдалась 2026-09-21, впервые 2026-09-18, источник — Indeed.