Splunk and Splunk SOAR Security Engineer

TekWissenTaylor, TX
Hybrid

About The Position

Client's Security team is seeking a contract security engineer to take on day-to-day administration, engineering, and operational support for our Splunk Enterprise and Splunk SOAR environments.

Requirements

  • 3+ years hands-on experience administering Splunk Enterprise (indexers, search heads, forwarders, data onboarding)
  • Direct experience building and maintaining Splunk SOAR playbooks
  • Direct experience integrating Splunk/SOAR with endpoint, vulnerability, or other security tool
  • Experience with REST API-based integrations
  • Experience troubleshooting issues related to API, network, authentication and other integrations
  • Strong SPL skills, including correlation searches, dashboard/report development, and system health monitoring

Nice To Haves

  • Splunk certifications (Core Certified Power User, Certified Admin, or SOAR-specific certs)
  • Scripting experience (Python, PowerShell) to support custom SOAR app development or automation
  • Familiarity with security operations workflows: infrastructure build pipelines, alert triage, incident response, threat detection engineering

Responsibilities

  • Manage and maintain the Splunk Enterprise environment, including data onboarding, index and source type management, search head and indexer health, and performance tuning.
  • Build and maintain playbooks, manage app/connector integrations, and support automation of playbooks across the broader security stack.
  • Troubleshoot data ingestion issues.
  • Support upgrades and patching.
  • Work with the broader security engineering team to align Splunk/SOAR use cases with Client's detection and response priorities, and service delivery workflows.
  • Document architecture, playbooks, and standard operating procedures to support knowledge transfer.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service