Splunk SME

Purple Drive

Not Interested
Bookmark
Report This Job

profile Job Location:

Baltimore, MD - USA

profile Monthly Salary: Not Disclosed
Posted on: 8 hours ago
Vacancies: 1 Vacancy

Job Summary

Role: Splunk SOAR & Splunk Engineer/ SME

Location:Baltimore MD

Key Responsibilities

  • Design develop and maintain automated playbooks usingSplunk SOAR (Phantom)to streamline SOC workflows.
  • Integrate SOAR with security tools IT systems ticketing platforms and threat intelligence feeds.
  • Administer and optimizeSplunk Enterprisein distributed high-ingest environments.
  • Implement Splunk best practices for indexing data models SPL optimization and knowledge objects.
  • Manage data ingestion and routing usingCribl and leverageRedisfor caching and enrichment.
  • Develop SQL-based integrations for data correlation enrichment and reporting.
  • Collaborate with SOC and IT teams to align automation with detection and response strategies.
  • Monitor Splunk platform health scalability and redundancy.

Essential Skills

  • 5 yearsof hands-on experience withSplunk Enterprise including multi-TB daily ingest environments.
  • 2 yearsof SplunkSOAR (Phantom)playbook design and development experience.
  • Advanced SPL knowledge search optimization and object management.
  • Strong experience withCribl Redis and SQLfor data ingestion enrichment and correlation.
  • Proficiency inPython(JSON/XML parsing API integrations regex); familiarity withPowerShell and Bash.
  • Experience integrating REST APIs with OAuth and key-based authentication.
  • Solid understanding ofSOC operations cybersecurity fundamentals andMITRE ATT&CKframework.
  • Strong knowledge ofLinux/Unix administration networking concepts and authentication systems.
  • Experience withGit/version control systems.
  • Splunk Certified AdminandSplunk SOAR Developercertifications.

Nice-to-Have Skills

  • Threat intelligence integrations (TAXII MISP Recorded Future).
  • Experience with Splunk upgrades and platform migrations.
  • Knowledge of SplunkMLTK UBA ITSI.
  • Understanding of data lifecycle management (compliance retention normalization).
  • Familiarity withDocker Kubernetes and DevOps practices.
  • Knowledge ofZero Trustsecurity architecture.

Experience Required

  • 10 yearsoverall IT/Security experience.
Role: Splunk SOAR & Splunk Engineer/ SME Location:Baltimore MD Key Responsibilities Design develop and maintain automated playbooks usingSplunk SOAR (Phantom)to streamline SOC workflows. Integrate SOAR with security tools IT systems ticketing platforms and threat intelligence feeds. Administer and ...
View more view more