1

Splunk Cybersecurity Defense Analyst Jobs in Wisconsin

WI · On-site

$99 - $206/hr

Our capabilities include cyber space operations, cyber defense and resiliency, vulnerability ... data analytics. Our engineers do more than just work with cutting-edge technology--they ensure ...

Customize cybersecurity solutions to address the unique needs of each organization. * Collaborate ... Analyze market trends, competitor activity and customer feedback to identify opportunities for ...

Certified Cloud Architect

Madison, WI · On-site

$65.50 - $83.50/hr

Google, Microsoft, AWS, Splunk Onsite or Remote: Candidate MUST be a WI resident or willing to ... Request for Services (RFS Cybersecurity AI Implementation for Accelerated Exposure Reduction Time ...

Physical Therapist

Harshaw, WI · On-site

$1.6K - $2.0K/wk

... Cybersecurity, Program/Financial Management, Logistics, and Data Analytics. At IND US, we believe ... of Defense, Air Force, or the Medical Group training, on-line Relias health training, Military ...

New

Investigating potential cybersecurity incidents. * Developing response processes and training ... Analyzing threats and vulnerabilities to determine their impact to the bank's operations

Investigating potential cybersecurity incidents. * Developing response processes and training ... Analyzing threats and vulnerabilities to determine their impact to the bank's operations

Investigating potential cybersecurity incidents. * Developing response processes and training ... Analyzing threats and vulnerabilities to determine their impact to the bank's operations

Showing results 21-40

Splunk Cybersecurity Defense Analyst information

How does a Splunk Cybersecurity Defense Analyst typically collaborate with other IT and security teams?

A Splunk Cybersecurity Defense Analyst frequently works alongside network administrators, incident response teams, and other security professionals to detect, investigate, and remediate threats. Collaboration often involves sharing threat intelligence, creating automated alerts, and developing dashboards to provide visibility into security events across the organization. Analysts also participate in regular meetings to coordinate response strategies, review incident post-mortems, and ensure that Splunk configurations align with evolving security requirements. This cross-functional teamwork is essential for maintaining an effective and proactive cybersecurity posture.

What is a Splunk Cybersecurity Defense Analyst?

Splunk Cybersecurity Defense Analysts are professionals who use the Splunk platform to monitor, analyze, and defend an organization’s digital infrastructure against cyber threats. They collect and interpret security data, investigate incidents, and create alerts and dashboards to detect suspicious activity in real-time. Their work helps organizations respond quickly to threats, ensuring the safety and integrity of sensitive information and systems. These analysts often collaborate with IT and security teams to develop best practices for threat detection and response.

What are the key skills and qualifications needed to thrive as a Splunk Cybersecurity Defense Analyst, and why are they important?

To thrive as a Splunk Cybersecurity Defense Analyst, you need a solid understanding of cybersecurity principles, threat analysis, and incident response, typically supported by a degree in information security or related certifications like CompTIA Security+ or GIAC. Proficiency with Splunk Enterprise Security, SIEM platforms, and scripting languages such as Python or PowerShell is essential. Strong analytical thinking, problem-solving abilities, and effective communication are important soft skills for collaborating with teams and responding to security incidents. These skills and qualities are critical for quickly identifying, investigating, and mitigating cyber threats to protect organizational assets.

What is the difference between Splunk Cybersecurity Defense Analyst vs Security Operations Center (SOC) Analyst?

AspectSplunk Cybersecurity Defense AnalystSecurity Operations Center (SOC) Analyst
CertificationsSplunk certifications, CompTIA Security+CompTIA Security+, GIAC certifications
Work EnvironmentPrimarily uses Splunk platform for data analysisMonitors security alerts across various tools in a SOC
Industry UsageFinancial, healthcare, tech sectors leveraging SplunkBroadly in all sectors with security teams
Job FocusAnalyzing security data with Splunk, threat detectionMonitoring, incident response, alert management

While both roles focus on cybersecurity, the Splunk Cybersecurity Defense Analyst specializes in using Splunk for data analysis and threat detection, whereas the SOC Analyst performs broader security monitoring and incident response across multiple tools. The roles often overlap but differ in platform focus and scope of responsibilities.

What are popular job titles related to Splunk Cybersecurity Defense Analyst jobs in Wisconsin? For Splunk Cybersecurity Defense Analyst jobs in Wisconsin, the most frequently searched job titles are:
What job categories do people searching Splunk Cybersecurity Defense Analyst jobs in Wisconsin look for? The top searched job categories for Splunk Cybersecurity Defense Analyst jobs in Wisconsin are:
What cities in Wisconsin are hiring for Splunk Cybersecurity Defense Analyst jobs? Cities in Wisconsin with the most Splunk Cybersecurity Defense Analyst job openings:

$112K - $154K/yr

Full-time

Posted 20 days ago


Northwestern Mutual rating

8.0

Company rating: 8.0 out of 10

Based on 73 frontline employees who took The Breakroom Quiz

163rd of 301 rated insurance


Job description

About the Job:

The Senior Threat Hunt Engineer is an advanced and highly trusted role supporting the enterprise cybersecurity program. As a member of Northwestern Mutual's Threat Hunting Program under theThreat Intelligenceumbrella, the Senior Threat Hunt Engineer is primarily responsible for developing andmaintainingthe operational and technical foundation of the program including automation, tooling integration, detection handoff pipelines, and AI-assisted hunt workflows. Grounded in threat intelligence and hunt experience, the Senior Threat Hunt Engineer also executes proactive and signal-driven hunts across endpoint, network, cloud, and identity telemetry, translating findings into durable detections and institutional knowledge.

This role works closely with internal technical teams - including Threat Intelligence, Detection & Response, Detection Engineering, Adversarial Simulation, Purple Team, Incident Command, and Governance, Risk & Compliance - and with peer organizations, industry-sharing groups, and law enforcement affiliations whereappropriate. The Senior Threat Hunt Engineer supports the hunt community across Cyber Defense, contributes engineering rigor to hunt artifacts, and ensures repeatable, version-controlled hunt processes as the program matures from manual to increasingly automated operations.

What You'll Do:

  • Maintain and mature the operational hunt frameworkused across Cyber Defense. Build, document, and refine the templates, integrations, andstandardshunters from multiple teams follow.
  • Design, build, andmaintainintegrations and automationacross the hunt lifecycle - spanning work-tracking, collaboration, ticketing, knowledge management, SIEM, EDR, threat intelligence platforms, and reporting.
  • Execute hunts and support the hunt community across teams. Perform proactive and signal-driven hunts, respond to hunt questions from hunters across Cyber Defense, and partner with Threat Intelligence to translate hunt-informed analysis into actionable intelligence. Synthesize hunt outcomes into cross-hunt correlations, control gap identification, and inputs to future hunts and detections.
  • Partner with detection engineering to translate hunt findingsinto production rules and analytics. Contributedetectioncandidates through the established handoff pipeline.
  • Consume and apply threat intelligence to hunt activity. Track adversary and threat cluster TTPs relevant to Northwestern Mutual, prioritize what matters, and translate intel into hunt hypotheses.
  • Mentor analysts and junior hunters. Pair on investigations, lead technical deep-dives, and grow the hunt capability across teams.
  • Report on program outcomes. Communicate findings to internal stakeholders - what was found, what wascontained, where detection coverage gaps exist, and what was changed as a result.
  • Evaluate, integrate, andmaintainsecurity toolingused by the Threat Hunting Program, including threat intelligence platforms, enrichment services, and hunt-supporting analytical tools.
  • Evaluate and integrate AIto accelerate hunt workflows, including hypothesis drafting, MITRE ATT&CK mapping suggestion, query generation, and summarization, withappropriate humanreview and tracking.
  • Researchcurrent and emerging cyber threatsfacing the business and industrysector.
  • Track threat actors, threat clusters, and associated malware families relevant to Northwestern Mutual and the financial services sector.
  • Document threats into contextual reportsoutlining severity, urgency, and impact, and ensure they can be understood by both leadership and technical teams.
  • Serve as a trusted advisortomaintaincredibility with business unit leadership and technical teams.
  • Actively inform andengage in security projectsacross the business to disrupt active or potential threats.
  • Participate incollaborative threat analysis discussionswith internal and external trusted entities.
  • Perform other dutiesas assigned.

What You'll Bring to the Role:

  • A minimum of 5-10 years in threat intelligence, threat hunting, incident response, or detection engineering, with meaningful experience across both threat intelligence and threat hunting disciplines.
  • Bachelor's degree in computer science, cybersecurity, engineering, ora relatedfield (or equivalent experience).
  • Relevant certifications such as GCTI, GCIH, GCFA, GCIA, GCDA, OSCP, CEH, or CISSP are a plus. Cloud-focused security certifications (e.g., AWS Security Specialty, GCP Professional Cloud Security Engineer) are also valued.
  • Deep hands-on experience running proactive and signal-driven hunts across SIEM, EDR, network, cloud, and identity telemetry in enterprise environments.
  • Strong scripting and automation skills; Pythonrequired, withadditionalexperience in PowerShell, Bash, or equivalenta plus.
  • Deep hands-on experience with enterprise SIEM search languages, including advanced query development, dashboard building, saved searches, alerting, and query optimization at enterprise scale.
  • Hands-on experience developing and consuming REST APIs across security tooling - including work-tracking, collaboration, ticketing, SIEM, EDR, and threat intelligence platforms.
  • Demonstrated experience building event-driven automation using webhooks or similar integration patterns.
  • Experience building, integrating, andmaintainingsecurity tooling and workflows at enterprise scale.
  • Working knowledge of version control workflows, branching strategies, and code review practices.
  • Ability to write clear technical documentation forautomationand integrations, including runbooks for maintenance and troubleshooting.
  • Ability to communicate complex findings clearly to both technical and leadership audiences.
  • Advanced analytical reasoning skills.
  • Applicable knowledge of adversary tactics, techniques, and procedures (TTPs), the MITRE ATT&CK framework, the unified kill chain, and open-source intelligence (OSINT).
  • Hands-on experience with SIEM, intrusion detection/prevention systems, threat intelligence platforms, and security orchestration and automation platforms.
  • Ability to analyze host, network, cloud, and identity telemetry; strong understanding of operating system internals; working knowledge of malware behavior, vulnerabilities, and exploitation techniques.
  • Experience with incident collaboration, adversary tooling, and threat-informed defensemethodology.
  • Capable of working with diverse teams across Cyber Defense; comfortable operating in a cross-team enablement role rather than a single-team hunt queue.
  • Demonstrated understanding of network, host, cloud, and identity cybersecurity solutions.
  • Ability tomaintaina high levelof integrity, trustworthiness, and confidence, with the highest level of professionalism.
  • Strong project management, multitasking, and organizational skills with minimum guidance.
  • Ability to preserve credibility with the team and external constituents through sustained industry knowledge.
  • Self-starter requiring minimal supervision.

Nice to Have Skills:

  • Experience with AI-assisted security workflows andappropriate operationalguardrails.
  • Familiarity with structured, version-controlled hunt methodologies.
  • Experience building andmaintainingCI/CD pipelines for security content.
  • Experience building or contributing to a new or evolving threathuntor detection engineering program, as opposed to onlyoperatingwithin an established one.
  • Experience with SOAR platforms and playbook development.
  • Experience with cloud-native security tooling and cloud API integration.
  • Experience in financial services or another regulated industry.
  • Contributions to open-source security tooling, published research, or public threat intelligence.

#LI-Remote

Compensation Range:

Pay Range - Start:

$118,960.00

Pay Range - End:

$178,440.00

Geographic Specific Pay Structure:

Structure 110:

Structure 115:

We believe in fairness and transparency. It's why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you're living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable, click here to learn more.

Job Posting End Date:


The timeline for this job posting may be shortened or extended based on organizational needs.


Grow your career with a best-in-class company that puts our clients' interests at the center of all we do. Get started now!


Northwestern Mutual is an equal opportunity employer that welcomes talented individuals of all backgrounds. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives.


What Northwestern Mutual employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Northwestern Mutual logo

About Northwestern Mutual

Sourced by ZipRecruiter

Northwestern Mutual has been helping families and businesses achieve financial security for over 160 years through a distinctive planning approach that integrates risk management with wealth accumulation, preservation, and distribution. With more than $290 billion in assets, $30 billion in revenues and more than $1.9 trillion worth of life insurance protection in force, Northwestern Mutual delivers financial security to more than 4.6 million clients. People are the power behind Northwestern Mutual, and diversity makes us better. We are committed to reflecting and serving the marketplace. We do so by attracting and improving the engagement of those who bring their outstanding perspectives, ideas, and beliefs.

Industry

Finance and insurance

Company size

5,001 - 10,000 Employees

Headquarters location

Milwaukee, WI, US