Prin Cybersecurity Anlyst (Splunk Knowledge Manager) - Remote

UnitedHealth GroupEden Prairie, MN
$112,700 - $193,200Remote

About The Position

The Enterprise Information Security (EIS) team is responsible for cybersecurity across our organization. We support our business and members by reducing risk, rapidly responding to threats, focusing on business resiliency and securing new acquisitions. UHG operates one of the largest and most complex Splunk environments in the world — supporting a massive user base, 10,000+ applications, and data ingestion volumes exceeding hundreds of TB/day across on-premises, cloud (AWS, Azure, GCP), and hybrid infrastructures. Our mission is to ensure this platform is not only operational and performant, but intelligently governed — delivering security intelligence that is trustworthy, searchable, and actionable at enterprise scale. The Splunk Knowledge Manager is a critical, specialized role responsible for the governance, lifecycle management, and strategic oversight of all Splunk knowledge objects across the enterprise SIEM. This individual serves as the authoritative custodian of how data is classified, normalized, searched, and consumed — bridging platform engineering, detection engineering, and SOC operations. In a deployment of this scale, ungoverned knowledge objects directly drive alert fatigue, missed detections, redundant content, and degraded platform performance; this role exists to prevent that entropy and ensure the SIEM delivers high-fidelity security outcomes. You’ll enjoy the flexibility to work remotely from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.

Requirements

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent professional experience
  • 5+ years of hands-on Splunk experience in enterprise environments, with 3+ years specifically in Splunk knowledge management, CIM normalization, or SIEM content engineering at large scale (100+ TB/day)
  • Deep expertise in Splunk Enterprise Security (ES) — correlation search authoring, ES data models, risk-based alerting, asset/identity frameworks
  • Advanced SPL proficiency (tstats, macros, sub-searches, eval functions, streaming/non-streaming commands) and full knowledge object lifecycle mastery
  • Hands-on experience with Splunk Enterprise (distributed, multi-site, clustered), Splunk Apps & Add-ons, ACS, configuration file management (btool, precedence), and Edge/Ingest Processor pipelines
  • Demonstrated experience enforcing enterprise naming conventions and taxonomy standards across multi-team, multi-app Splunk environments
  • Multi-cloud log source experience (AWS, Azure, GCP), Linux/Windows administration, scripting in Python and Bash, and version control via GitHub / GitHub Actions / CI-CD pipelines
  • Proven working knowledge of MITRE ATT&CK, NIST CSF / 800-53, CIS Benchmarks, and Agile/Scrum content delivery
  • Demonstrated background in detection engineering, threat hunting, or SOC operations, with proven ability to produce technical documentation (runbooks, standards guides, architecture artifacts)

Nice To Haves

  • Splunk Certifications: Splunk Core Certified Consultant, Splunk Enterprise Security Certified Admin (SPLK-3001), or Splunk Certified Architect
  • Security Certifications: GIAC (GCIA, GCIH, GCED) or equivalent
  • Splunk UBA behavioral analytics experience
  • Experience in highly regulated industries (Healthcare/HIPAA, Federal/NIST, NYDFS, PCI)
  • Infrastructure-as-code experience (Ansible, Terraform) for Splunk configuration management
  • Proficiency with LLM-powered tooling and AI-assisted automation for knowledge retrieval and content generation
  • Experience supporting Splunk deployments with 10,000+ users and multi-petabyte retention
  • Demonstrated familiarity with Kafka, streaming data pipelines, and real-time telemetry routing

Responsibilities

  • Knowledge Object Governance & Lifecycle Management — Provide centralized governance of all Splunk knowledge objects (saved/correlation searches, field extractions, tags, aliases, event types, lookups, macros, data models, workflow actions, KV store). Establish naming conventions, conduct audits to retire duplicate/orphaned content, maintain a registry/catalog, manage permissions, and lead CI/CD promotion pipelines (GitHub, GitHub Actions)
  • CIM Normalization & Data Model Management — Serve as the enterprise CIM authority; design and maintain CIM-compliant field mappings, data models, and acceleration strategies (TSIDX, tstats, summary indexing) across endpoint, network, identity, cloud, and application domains. Enforce sourcetype/index taxonomy standards and maintain CIM-to-MITRE ATT&CK coverage matrices
  • Knowledge Architecture & Standards Program — Own the enterprise Splunk knowledge architecture, publish and maintain the Knowledge Management Standards document, chair the Knowledge Governance Working Group, and define reusable content type templates for searches, dashboards, lookups, and macros
  • Custom Automation & Data Quality Monitoring — Build automations to track data ingest, flow consistency, and drift from normalization standards, surfacing issues before they degrade detection efficacy
  • Documentation, Training & Enablement — Maintain a comprehensive internal knowledge base (runbooks, SPL reference library, object catalogues), deliver training and office hours, mentor junior staff, partner with Splunk Professional Services, and produce executive reporting on knowledge base health
  • Cross-Team Collaboration & Strategic Alignment — Serve as primary SME and liaison across Detection Engineering, SOC Operations, Platform Engineering, Compliance, and application teams — driving content quality, version migration planning, regulatory alignment (NYDFS, PCI DSS, HIPAA, SOX, NIST CSF), and AI/LLM-ready knowledge object structuring

Benefits

  • comprehensive benefits package
  • incentive and recognition programs
  • equity stock purchase
  • 401k contribution
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service