We are seeking a highly skilled Splunk Enterprise Security Expert to provide centralized oversight and authoritative governance of all Splunk knowledge objects across the enterprise SIEM environment. This role is crucial for ensuring consistency, scalability, and effective utilization of Splunk knowledge objects, including saved searches, correlation searches, field extractions, tags, aliases, event types, lookups, macros, data models, workflow actions, and KV store collections. The ideal candidate will have a deep understanding of Splunk Enterprise Security, CIM normalization, and SIEM content engineering, with a proven ability to manage knowledge object governance at scale. You will collaborate with various teams to establish standards, lead promotion pipelines, and serve as the authority for CIM compliance and data model management. This position requires strong technical skills in SPL, Splunk administration, scripting, and CI/CD practices, as well as a background in detection engineering or SOC operations.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior