Splunk SOAR Engineer
Tampa, FL · On-site
The Splunk SOAR Engineer will lead the full lifecycle of platform architecture, integration ... phishing, malware, unauthorized access). * Translate manual security procedures into robust ...
Quick apply
Tampa, FL · On-site
The Splunk SOAR Engineer will lead the full lifecycle of platform architecture, integration ... phishing, malware, unauthorized access). * Translate manual security procedures into robust ...
Quick apply
Tampa, FL · On-site
The Splunk SOAR Engineer will lead the full lifecycle of platform architecture, integration ... phishing, malware, unauthorized access). * Translate manual security procedures into robust ...
The Splunk SOAR Engineer will lead the full lifecycle of platform architecture, integration ... phishing, malware, unauthorized access). * Translate manual security procedures into robust ...
The Splunk SOAR Engineer will lead the full lifecycle of platform architecture, integration ... phishing, malware, unauthorized access). * Translate manual security procedures into robust ...
Atlanta, GA · On-site
Information Security Analyst [ CrowdStrike (EDR), Splunk (SIEM), and Tenable (Vulnerability ... Develop and deliver security awareness programs, emphasizing CUI handling, phishing defense, and ...
Atlanta, GA · On-site
Information Security Analyst [ CrowdStrike (EDR), Splunk (SIEM), and Tenable (Vulnerability ... Develop and deliver security awareness programs, emphasizing CUI handling, phishing defense, and ...
Reston, VA · On-site
$40K - $50K/yr
Knowledge of phishing techniques, email security, and social engineering tactics. * Knowledge of Splunk and SEIM preferred. Compensation and Benefits * Starting compensation range: $40,000 - $50,000 ...
Reston, VA · On-site
$40K - $50K/yr
Knowledge of phishing techniques, email security, and social engineering tactics. * Knowledge of Splunk and SEIM preferred. Compensation and Benefits * Starting compensation range: $40,000 - $50,000 ...
Jacksonville, FL · On-site
$25/hr
Handle Tier 1 level alerts in ArcSight/Splunk via the standard work processes and escalate to Tier ... Triage phishing emails and escalate potential real phishing email to Tier2 team. Triage of SIRT and ...
Jacksonville, FL · On-site
$25/hr
Handle Tier 1 level alerts in ArcSight/Splunk via the standard work processes and escalate to Tier ... Triage phishing emails and escalate potential real phishing email to Tier2 team. Triage of SIRT and ...
Overland Park, KS · On-site
$113K - $155K/yr
... phishing/BEC attack techniques. • Strong understanding of DLP and information protection. • Experience with SIEM tools (e.g., Sentinel, Splunk) and alert tuning. • Ability to analyze and ...
New
Overland Park, KS · On-site
$113K - $155K/yr
... phishing/BEC attack techniques. • Strong understanding of DLP and information protection. • Experience with SIEM tools (e.g., Sentinel, Splunk) and alert tuning. • Ability to analyze and ...
New
$93K - $124K/yr
The organization also utilizes Splunk and related analytics platforms for advanced log analysis and ... Phishing and spear phishing o Malicious attachments and payload delivery o URL-based attacks and ...
$93K - $124K/yr
The organization also utilizes Splunk and related analytics platforms for advanced log analysis and ... Phishing and spear phishing o Malicious attachments and payload delivery o URL-based attacks and ...
Conduct continuous monitoring of enterprise systems using CrowdStrike (EDR), Splunk (SIEM), and ... Develop and deliver security awareness programs, emphasizing CUI handling, phishing defense, and ...
Conduct continuous monitoring of enterprise systems using CrowdStrike (EDR), Splunk (SIEM), and ... Develop and deliver security awareness programs, emphasizing CUI handling, phishing defense, and ...
Anchorage, AK · On-site
... Splunk. * Cyber Security Training - Provide training on various Cyber Security topics, developing cultural awareness campaigns with topics such as phishing, social engineering, and access control.
Quick apply
Anchorage, AK · On-site
... Splunk. * Cyber Security Training - Provide training on various Cyber Security topics, developing cultural awareness campaigns with topics such as phishing, social engineering, and access control.
Anchorage, AK · On-site
... Splunk. * Cyber Security Training - Provide training on various Cyber Security topics, developing cultural awareness campaigns with topics such as phishing, social engineering, and access control.
Quick apply
Anchorage, AK · On-site
... Splunk. * Cyber Security Training - Provide training on various Cyber Security topics, developing cultural awareness campaigns with topics such as phishing, social engineering, and access control.
San Jose, CA · Hybrid
Investigate phishing, malware, and suspicious activities * Support incident response and ... Splunk * QRadar * Sentinel * CrowdStrike * Defender * Understanding of: * SIEM * SOC operations
San Jose, CA · Hybrid
Investigate phishing, malware, and suspicious activities * Support incident response and ... Splunk * QRadar * Sentinel * CrowdStrike * Defender * Understanding of: * SIEM * SOC operations
New York, NY · Hybrid
$125K - $171K/yr
... malware, phishing, viruses, denial-of-service attacks, information warfare and hacking. The ... Practical expertise using Splunk SPL to extract actionable insights from security analytics ...
Quick apply
New York, NY · Hybrid
$125K - $171K/yr
... malware, phishing, viruses, denial-of-service attacks, information warfare and hacking. The ... Practical expertise using Splunk SPL to extract actionable insights from security analytics ...
Houston, TX · On-site
... phishing, malware, lateral movement, identity compromise • Participate in client-facing meetings ... Splunk, CrowdStrike, Sumo Logic, QRadar, Elastic, or similar) • Industry certification: CompTIA ...
Houston, TX · On-site
... phishing, malware, lateral movement, identity compromise • Participate in client-facing meetings ... Splunk, CrowdStrike, Sumo Logic, QRadar, Elastic, or similar) • Industry certification: CompTIA ...
Washington, DC · On-site
Conduct advanced analysis of cyber threat actors, campaigns, malware, phishing activity, suspicious ... Perform intelligence analysis utilizing Splunk Enterprise Security, Microsoft Sentinel, Splunk SOAR ...
Quick apply
Washington, DC · On-site
Conduct advanced analysis of cyber threat actors, campaigns, malware, phishing activity, suspicious ... Perform intelligence analysis utilizing Splunk Enterprise Security, Microsoft Sentinel, Splunk SOAR ...
$131K - $180K/yr
Oversee the ingestion of Azure and M365 logs into Splunk for centralized monitoring, creating ... Harden email security through anti-phishing, anti-impersonation, and safe links/attachments ...
$131K - $180K/yr
Oversee the ingestion of Azure and M365 logs into Splunk for centralized monitoring, creating ... Harden email security through anti-phishing, anti-impersonation, and safe links/attachments ...
Washington, DC · On-site
Conduct advanced analysis of cyber threat actors, campaigns, malware, phishing activity, suspicious ... Perform intelligence analysis utilizing Splunk Enterprise Security, Microsoft Sentinel, Splunk SOAR ...
Washington, DC · On-site
Conduct advanced analysis of cyber threat actors, campaigns, malware, phishing activity, suspicious ... Perform intelligence analysis utilizing Splunk Enterprise Security, Microsoft Sentinel, Splunk SOAR ...
A strong working knowledge of Splunk is required - including the ability to build, interpret, and ... Detect the full spectrum of known cyberattacks (DDoS, malware, phishing, ransomware, and others ...
A strong working knowledge of Splunk is required - including the ability to build, interpret, and ... Detect the full spectrum of known cyberattacks (DDoS, malware, phishing, ransomware, and others ...
The Tier III analyst brings deep hands-on experience working in Splunk at an advanced level and ... Detect the full spectrum of known cyberattacks (DDoS, malware, phishing, ransomware, and others ...
The Tier III analyst brings deep hands-on experience working in Splunk at an advanced level and ... Detect the full spectrum of known cyberattacks (DDoS, malware, phishing, ransomware, and others ...
Monitor SIEM alerts (Splunk) and triage security events; escalate and coordinate incident response ... Support security awareness training and phishing simulation programs for end users * Maintain ...
Monitor SIEM alerts (Splunk) and triage security events; escalate and coordinate incident response ... Support security awareness training and phishing simulation programs for end users * Maintain ...
Monitor SIEM alerts (Splunk) and triage security events; escalate and coordinate incident response ... Support security awareness training and phishing simulation programs for end users * Maintain ...
Monitor SIEM alerts (Splunk) and triage security events; escalate and coordinate incident response ... Support security awareness training and phishing simulation programs for end users * Maintain ...
$29K - $40.8K
2% of jobs
$40.8K - $52.5K
7% of jobs
$52.5K - $64.3K
1% of jobs
$64.3K - $76.1K
4% of jobs
$76.1K - $87.9K
5% of jobs
$99.6K is the 25th percentile. Wages below this are outliers.
$87.9K - $99.6K
5% of jobs
$99.6K - $111.4K
16% of jobs
The median wage is $121K / yr.
$111.4K - $123.2K
11% of jobs
$132.8K is the 75th percentile. Wages above this are outliers.
$123.2K - $135K
28% of jobs
$135K - $146.7K
17% of jobs
$146.7K - $158.5K
3% of jobs
$29K
$117K
$158.5K
| Aspect | Phishing Splunk | Security Analyst |
|---|---|---|
| Certifications | Splunk certifications, cybersecurity basics | CompTIA Security+, CISSP, CEH |
| Work Environment | Security operations centers, incident response teams | IT departments, security teams across industries |
| Industry Usage | Data analysis, threat detection, log management | Threat assessment, incident response, policy enforcement |
Phishing Splunk specialists focus on using Splunk tools to detect and analyze phishing attacks, often within security operations centers. Security Analysts have a broader role in monitoring, analyzing, and responding to various security threats, including phishing, using multiple tools and techniques. While both roles require cybersecurity knowledge and certifications, Phishing Splunk roles are more specialized in data analysis with Splunk, whereas Security Analysts have a wider scope in security management.

Full-time
Medical, Dental, Vision, Retirement, PTO
Posted 5 days ago
About Us
Venatore is a woman-owned small business headquartered in Tampa, Florida, providing mission-driven technology and professional services to federal defense and civilian agencies. We deliver expertise in information technology, engineering, logistics, and program support to help our clients achieve operational excellence and mission success.
About the Job
Venatore is seeking a Splunk SOAR Engineer to support U.S. Central Command (USCENTCOM) operations by designing, implementing, and optimizing enterprise-level Security Orchestration, Automation, and Response (SOAR) capabilities. This role is responsible for transforming manual incident response processes into scalable, automated workflows that accelerate threat detection, containment, and remediation. The Splunk SOAR Engineer will lead the full lifecycle of platform architecture, integration, content development, and performance optimization while collaborating closely with SOC analysts, threat hunters, and incident response teams. An active TS/SCI clearance is required.
Responsibilities
Platform Architecture & Engineering
Design, deploy, document, and maintain distributed Splunk SOAR (Phantom) platform architecture to ensure high availability, scalability, and performance.
Support system upgrades, patching, and performance tuning across the SOAR infrastructure.
Provide advanced troubleshooting and resolution of platform issues and playbook execution errors.
Adhere to security best practices and compliance requirements within the operational environment.
Playbook Development & Automation
Develop, customize, and maintain complex SOAR playbooks using Python and the Phantom Playbook Editor for automated enrichment, triage, containment, and remediation of security incidents (e.g., phishing, malware, unauthorized access).
Translate manual security procedures into robust, automated workflows aligned with SecOps best practices.
Establish and track automation metrics, including utilization rates, automation coverage, and Mean Time to Respond (MTTR) improvements.
Integration & Interoperability
Integrate Splunk SOAR with Splunk Enterprise Security (ES) and other core security technologies, including EDR/XDR platforms, firewalls, vulnerability scanners, threat intelligence platforms, and ticketing systems.
Develop custom apps and integrations to connect proprietary or unsupported security tools using RESTful APIs and custom connectors.
Manage and optimize data flow between Splunk ES and Splunk SOAR to ensure effective event-triggered automation actions.
Collaboration & Documentation
Partner with SOC analysts, threat hunters, and incident response teams to gather requirements and document workflows.
Develop and maintain detailed technical documentation for platform configurations, integrations, and automation content.
Provide training and mentorship to SOC staff on SOAR usage, content development, and automation best practices.
Evaluate and integrate emerging security technologies and threat intelligence feeds into the automation ecosystem.
Required Qualifications
Active TS/SCI security clearance.
U.S. citizenship.
Applicable DoD 8140 or DoD 8570 certification.
8+ years of related experience in security engineering or security operations.
Hands-on expertise with Splunk SOAR (Phantom) administration, configuration, and maintenance in a distributed enterprise environment.
Advanced proficiency in Python scripting for playbook development, custom apps, and integrations.
Proven experience integrating SOAR platforms with Splunk Enterprise Security (ES), SIEMs, EDR/XDR tools, and other security technologies.
Strong understanding of security operations principles, incident response lifecycles, and threat detection methodologies.
Experience working with RESTful APIs and developing tool connectors.
Proficiency in data manipulation, log parsing, and understanding of the Common Information Model (CIM) in a security context.
Strong verbal and written communication skills with the ability to convey complex automation concepts to technical and non-technical audiences.
Preferred Qualifications
Familiarity with cloud security logging, containerization (Docker/Kubernetes), and CI/CD pipelines for playbook deployment.
Knowledge of the MITRE ATT&CK framework and its application in automated detection and response use cases.
Experience using Git or other version control systems for SOAR content management.
Familiarity with network protocols, Windows and Linux operating systems, and enterprise security architecture components.
Splunk Enterprise Security Certified Admin or Architect certification.
Splunk SOAR (Phantom) Certified Content Developer or Administrator certification.
Experience with other SOAR platforms (e.g., Palo Alto Cortex XSOAR, IBM Resilient).
Experience supporting USCENTCOM or multi-domain defense security operations environments.
ITIL 4 Foundation certification.
Benefits
Venatore offers a competitive benefits package designed to support the well-being of our employees, including:
Paid Time Off (PTO)
10 Federal Holidays
401(k) with company matching
Medical, dental, and vision insurance
Paid parental leave
Paid military leave
Venatore is an equal opportunity employer and considers qualified applicants without regard to disability or protected veteran status.
Sourced by ZipRecruiter
It services
11 - 50 Employees
Tampa, FL, US
2007