1

Splunk Cybersecurity Defense Analyst Jobs in Georgia

... defensive posture. The ideal candidate will have a strong cybersecurity and security operations ... Practical experience with Splunk, Gravwell, or other Security Information and Event Management ...

Cybersecurity Architect

Augusta, GA · On-site

$112K - $257K/yr

Cybersecurity Architect The Opportunity: Everyone knows security needs to be "baked in" to system ... defense, zero trust, A&O, AI, analytics, secure DevOps, identity and access management, or network ...

The Cyber Security Engineer II with strong Akamai experience serves as the first line of defense ... Design, build, manage, and safeguard enterprise web apps, analyze traffic logs, tune security rules ...

The Cyber Security Engineer II with strong Akamai experience serves as the first line of defense ... Design, build, manage, and safeguard enterprise web apps, analyze traffic logs, tune security rules ...

... cybersecurity and applied defense grade secure cross-domain solutions for the U.S. government ... Position SummaryCyber Analysts support a 24/7 operation and are responsible for designing ...

... defensive posture. The ideal candidate will have a strong cybersecurity and security operations ... Practical experience with Splunk, Gravwell, or other Security Information and Event Management ...

... defensive posture. The ideal candidate will have a strong cybersecurity and security operations ... Practical experience with Splunk, Gravwell, or other Security Information and Event Management ...

Showing results 41-60

Splunk Cybersecurity Defense Analyst information

How does a Splunk Cybersecurity Defense Analyst typically collaborate with other IT and security teams?

A Splunk Cybersecurity Defense Analyst frequently works alongside network administrators, incident response teams, and other security professionals to detect, investigate, and remediate threats. Collaboration often involves sharing threat intelligence, creating automated alerts, and developing dashboards to provide visibility into security events across the organization. Analysts also participate in regular meetings to coordinate response strategies, review incident post-mortems, and ensure that Splunk configurations align with evolving security requirements. This cross-functional teamwork is essential for maintaining an effective and proactive cybersecurity posture.

What is a Splunk Cybersecurity Defense Analyst?

Splunk Cybersecurity Defense Analysts are professionals who use the Splunk platform to monitor, analyze, and defend an organization’s digital infrastructure against cyber threats. They collect and interpret security data, investigate incidents, and create alerts and dashboards to detect suspicious activity in real-time. Their work helps organizations respond quickly to threats, ensuring the safety and integrity of sensitive information and systems. These analysts often collaborate with IT and security teams to develop best practices for threat detection and response.

What are the key skills and qualifications needed to thrive as a Splunk Cybersecurity Defense Analyst, and why are they important?

To thrive as a Splunk Cybersecurity Defense Analyst, you need a solid understanding of cybersecurity principles, threat analysis, and incident response, typically supported by a degree in information security or related certifications like CompTIA Security+ or GIAC. Proficiency with Splunk Enterprise Security, SIEM platforms, and scripting languages such as Python or PowerShell is essential. Strong analytical thinking, problem-solving abilities, and effective communication are important soft skills for collaborating with teams and responding to security incidents. These skills and qualities are critical for quickly identifying, investigating, and mitigating cyber threats to protect organizational assets.

What is the difference between Splunk Cybersecurity Defense Analyst vs Security Operations Center (SOC) Analyst?

AspectSplunk Cybersecurity Defense AnalystSecurity Operations Center (SOC) Analyst
CertificationsSplunk certifications, CompTIA Security+CompTIA Security+, GIAC certifications
Work EnvironmentPrimarily uses Splunk platform for data analysisMonitors security alerts across various tools in a SOC
Industry UsageFinancial, healthcare, tech sectors leveraging SplunkBroadly in all sectors with security teams
Job FocusAnalyzing security data with Splunk, threat detectionMonitoring, incident response, alert management

While both roles focus on cybersecurity, the Splunk Cybersecurity Defense Analyst specializes in using Splunk for data analysis and threat detection, whereas the SOC Analyst performs broader security monitoring and incident response across multiple tools. The roles often overlap but differ in platform focus and scope of responsibilities.

What are popular job titles related to Splunk Cybersecurity Defense Analyst jobs in Georgia?

For Splunk Cybersecurity Defense Analyst jobs in Georgia, the most frequently searched job titles are:

What job categories do people searching Splunk Cybersecurity Defense Analyst jobs in Georgia look for?

The top searched job categories for Splunk Cybersecurity Defense Analyst jobs in Georgia are:

What cities in Georgia are hiring for Splunk Cybersecurity Defense Analyst jobs?

Cities in Georgia with the most Splunk Cybersecurity Defense Analyst job openings:

Infographic showing various Splunk Cybersecurity Defense Analyst job openings in Georgia as of August 2026, with employment types broken down into 50% Full Time, and 50% Contract. Highlights an 100% In-person job distribution.

Adversary Threat Hunter

Southern Company

Atlanta, GA • On-site

Full-time

Medical, Retirement

Posted 8 days ago


Southern Company rating

8.4

Company rating: 8.4 out of 10

Based on 23 frontline employees who took The Breakroom Quiz


Job description


Adversary Threat Hunter
Job Description
At Southern Company, our core objective is to provide a safe, reliable computing environment for the consumers of our services, both internally and externally. Our complex environment requires continual innovation and effective use of evolving technologies. Protecting the network helps ensure our users remain connected to critical applications, products, and services.
Position Overview:
Southern Company is seeking a knowledgeable, hands-on Adversary Threat Hunter to join our Cyber Security team. This role leads proactive threat hunting engagements to identify suspicious behavior, adversary activity, and unauthorized access across Southern Company networks and systems. The position also supports incident response, detection engineering, investigative processes, and recommendations for security technologies and controls that improve the company's defensive posture.
The ideal candidate will have a strong cybersecurity and security operations background, with forensic, investigative, analytical, threat intelligence, and technical skills.
Qualifications:
  • Bachelor's degree or equivalent experience
  • 7 or more years of information technology security experience
  • Broad knowledge of information security principles, including access control, least privilege, data integrity, and core security capabilities
  • Strong understanding of network design principles, including topology, protocols, network components, and virtualized infrastructure
  • Practical experience with Splunk, Gravwell, or other Security Information and Event Management (SIEM) platforms
  • Demonstrated experience in security operations, including security monitoring, incident response, host or network forensics, penetration testing, cyber threat intelligence, malware analysis, or security consulting
  • Experience performing forensic analysis on Windows and Linux/Unix systems
  • Experience using Endpoint Detection and Response (EDR), Network Detection and Response (NDR), Security Orchestration, Automation, and Response (SOAR), and related cybersecurity tools to support threat hunting, investigation, and response
  • Experience with memory analysis, disk artifact collection, endpoint telemetry, and forensic acquisition methods used to identify malicious or evasive activity
  • Ability to develop threat hunting hypotheses from cyber threat intelligence, incident response findings, adversary tradecraft, vulnerability information, and business risk priorities
  • Ability to evaluate available data sources, identify visibility gaps, and determine whether logs, telemetry, or security tooling are sufficient to validate a hunt hypothesis
  • Basic understanding of YARA, Snort, Sigma, or similar detection logic
  • Experience using data analysis methods such as searching, filtering, grouping, stacking, baselining, anomaly detection, visualization, and trend analysis to identify suspicious behavior
  • Experience mapping adversary behaviors to MITRE ATT&CK, MITRE ATT&CK for ICS, Cyber Kill Chain, Diamond Model, or similar analytical frameworks to prioritize hunt activity and detection improvements
  • Familiarity with the threat intelligence lifecycle and adversary tactics, techniques, and procedures, including cybercrime, malware, botnets, hacktivism, social engineering, advanced persistent threats, and insider threats
  • Familiarity with Operational Technology (OT) networks and processes
  • Understanding of how threat hunting differs between Information Technology (IT) and Operational Technology (OT) environments, including safety considerations, specialized protocols, logging limitations, and coordination with operational teams
  • Experience drafting security operations processes and procedures
  • Ability to organize tasks, manage multiple priorities, meet schedules, and deliver on commitments
  • Ability to document hunt plans, analytical methods, evidence, findings, limitations, recommendations, and lessons learned in a repeatable format
  • Strong written and verbal communication skills

Responsibilities
Job Responsibilities:
  • Plan and conduct structured, hypothesis-driven threat hunting engagements
  • Collect and analyze data from multiple sources and tools to identify anomalies, suspicious activity, and potential adversary behavior
  • Maintain awareness of the current threat landscape through intelligence reports, internet research, and sector-specific sources
  • Partner with the Cyber Threat Intelligence team to understand threat actor behavior, tactics, techniques, procedures, and emerging threats
  • Support detection engineering and security monitoring by recommending improved SIEM detections, alert logic, and related capabilities
  • Recommend and support implementation of security controls and solutions based on lessons learned from hunting engagements
  • Partner with Threat Analysis and Incident Response teams to evaluate adversary techniques and improve defensive capabilities
  • Support incident response, remediation, recovery, threat scenario development, and response playbooks

Qualifications
Job Requirements:
  • Must pass NERC CIP and Insider Threat Protection background checks
  • Ability to work independently and as part of a team
  • Ability to understand business requirements, communicate technical findings, and recommend appropriate solutions
  • Strong critical thinking, independent judgment, and creative problem-solving skills
  • Occasional travel to local and regional locations in support of job duties and requirements

Desired certifications (one or more of the following):
  • Offensive Security Certified Professional (OSCP)
  • GIAC Security Essentials (GSEC)
  • GIAC Certified Forensic Examiner (GCFE)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)

About Us
About Southern Company
Southern Company (NYSE: SO) is a leading energy provider serving 9 million customers across the Southeast and beyond through its family of companies. Providing clean, safe, reliable and affordable energy with excellent service is our mission. The company has electric operating companies in three states, natural gas distribution companies in four states, a competitive generation company, a leading distributed energy solutions provider with national capabilities, a fiber optics network and telecommunications services. Through an industry-leading commitment to innovation, resilience and sustainability, we are taking action to meet customers' and communities' needs while advancing our goal of net-zero greenhouse gas emissions by 2050. Our uncompromising values ensure we put the needs of those we serve at the center of everything we do and are the key to our sustained success. We are transforming energy into economic, environmental and social progress for tomorrow. Our corporate culture has been recognized by a variety of organizations, earning the company awards and recognitions that reflect Our Values and dedication to service. To learn more, visit www.southerncompany.com.
Southern Company invests in the well-being of its employees and their families through a comprehensive total rewards strategy that includes competitive base salary, annual incentive awards for eligible employees and health, welfare and retirement benefits designed to support physical, financial, and emotional/social well-being. This position may also be eligible for additional compensation, such as an incentive program, with the amount of any bonus/awards subject to the terms and conditions of the applicable incentive plan(s). A summary of the benefits offered for this position can be found here https://seo.nlx.org/southernco/pdf/SOCO-Benefits.pdf. Additional and specific details about total compensation and benefits will also be provided during the hiring process.
Southern Company is an equal opportunity employer where an applicant's qualifications are considered without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, sexual orientation, gender identity or expression, or any other basis prohibited by law.
About the Team
Southern Company Services

What Southern Company employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom