1

Splunk Security Engineer Jobs (NOW HIRING)

Senior Splunk Engineer

Portland, OR · On-site +1

$121K - $166K/yr

The Senior Splunk Engineer designs, implements, maintains, and optimizes Splunk capabilities that ... Security Analytics & Detection Support * Develop, maintain, and tune SPL searches, correlation ...

Splunk Content Developer

Ashburn, VA · On-site

$131K - $237K/yr

The engineer will create scalable, resilient, and automated security solutions that improve threat ... Splunk * Axonius * Cribl * Corelight * Forescount * Wraithwatch * Cyrtica Cyber Operations ...

SPLUNK ENGINEER MILITARY FRIENDLY & PREFERRED - HOH SPONSOR Zermount is seeking an experienced Splunk Engineer to support our client's enterprise security, operations, and monitoring environment.

SPLUNK ENGINEER MILITARY FRIENDLY & PREFERRED - HOH SPONSOR Zermount is seeking an experienced Splunk Engineer to support our client's enterprise security, operations, and monitoring environment.

SPLUNK ENGINEER MILITARY FRIENDLY & PREFERRED - HOH SPONSOR Zermount is seeking an experienced Splunk Engineer to support our client's enterprise security, operations, and monitoring environment.

The Splunk SOAR Engineer will lead the full lifecycle of platform architecture, integration ... Adhere to security best practices and compliance requirements within the operational environment.

next page

Showing results 1-20

Splunk Security Engineer information

See salary details

$61.5K

$152.8K

$205.5K

How much do splunk security engineer jobs pay per year?

As of Jun 12, 2026, the average yearly pay for splunk security engineer in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Splunk Security Engineer position, and why are they important?

To thrive as a Splunk Security Engineer, you need strong expertise in cybersecurity principles, log analysis, and experience with Splunk Enterprise or Splunk Cloud platforms, often supported by a related degree or certifications like Splunk Certified Power User or Architect. Familiarity with SIEM tools, scripting languages (e.g., Python), and integration of security data sources is essential. Strong problem-solving, attention to detail, and excellent communication skills help you collaborate effectively with IT and security teams. These skills are crucial for proactively detecting threats, improving system security, and ensuring an organization's digital safety.

What does a typical day look like for a Splunk Security Engineer?

A typical day for a Splunk Security Engineer involves monitoring security alerts and dashboards, investigating and responding to potential threats, and fine-tuning Splunk queries or correlation searches. You may work closely with SOC analysts, network engineers, and system administrators to interpret security logs, uncover patterns, and implement new detection rules or data integrations. Additionally, you might help with onboarding new data sources into Splunk and contribute to incident response activities or post-incident reviews. The role is highly collaborative and often fast-paced, requiring a blend of analytical and technical skills to keep organizational data secure.

What is a Splunk Security Engineer job?

A Splunk Security Engineer is responsible for implementing, managing, and optimizing Splunk for security operations. They design and maintain Splunk infrastructure, create alerts and dashboards, and analyze security logs to detect threats. Their role involves integrating Splunk with various security tools and developing custom use cases for threat detection and response. Additionally, they collaborate with security teams to enhance monitoring capabilities and ensure compliance with organizational security policies.

More about Splunk Security Engineer jobs
What cities are hiring for Splunk Security Engineer jobs? Cities with the most Splunk Security Engineer job openings:
What are the most commonly searched types of Splunk Security Engineer jobs? The most popular types of Splunk Security Engineer jobs are:
What states have the most Splunk Security Engineer jobs? States with the most job openings for Splunk Security Engineer jobs include:
What job categories do people searching Splunk Security Engineer jobs look for? The top searched job categories for Splunk Security Engineer jobs are:
Infographic showing various Splunk Security Engineer job openings in the United States as of June 2026, with employment types broken down into 75% Full Time, and 25% Contract. Highlights an 87% In-person, and 13% Remote job distribution, with an average salary of $152,773 per year, or $73.4 per hour.

Splunk Content Developer

Kinzo Staffing

Owings Mills, MD

Full-time

Posted 15 days ago


Job description

Kinzo Staffing is seeking a Splunk Enterprise Security Engineer who can develop custom detection content (correlation rules) identify threat activity. This includes developing notable events, visualizations, forms, reports, alerts, as well as Splunk Apps, Technology Add-ons, and normalize data sources to the Common Information Model. The candidate will provide optimization of data flow using aggregation, filters, etc. The Splunk Engineer will provide overall engineering, and administration in supporting a very large distributed clustered Splunk environment consisting of search heads, indexers, deployers, deployment servers, heavy/universal forwarders and Splunk Enterprise Security app, spanning security, performance, and operational roles. The Engineer should be proficient with recognizing and onboarding new data sources into Splunk, analyzing the data for anomalies and trends, and building dashboards highlighting the key trends of the data. The Splunk engineer should be proficient within a Linux environment, editing and maintaining Splunk configuration files and apps.

What you will do:

  • Alert use case development
  • Upgrade Splunk apps required by Splunk ES upgrades.
  • Splunk Enterprise Security administration and management.
  • Configure notable event actions, action menus and Adaptive Responses.
  • Data onboarding and data ingestion normalization recommendations.
  • Strong knowledge of security risk procedures, security patterns, authentication technologies and security attack pathologies.
  • Develop, evaluate, and document, specific metrics for management purpose.
  • Write complex code to install and manage the Splunk enterprise development.
  • Performing maintenance and optimization of existing clustered Splunk deployments.
  • Create Dashboards to monitor the traffic volumes, response times, errors, and warnings across various data centers.
  • Monitor the web portals, log files and databases.
  • Provide debugging and monitoring capabilities.
  • Design and Develop Splunk for routine use.
  • Solve complex Integration challenges and debug complex configuration issues.
  • Consult with stakeholders to establish, maintain and refresh their strategic direction in cloud adoption.
  • Become knowledgeable on the CDM technical requirements for the federal government’s CDM program. Understand your role in CDM activities.
  • Involved in a wide range of security issues including architectures, firewalls, electronic data traffic, and network access.
  • Design, manage, and maintain enterprise SIEM infrastructure to improve data ingestion processes, including architectural work on data pipelines to ensure optimal flow of data.
  • Maintenance, configuration and implementing products, appliances and devices on the enterprise network.

Qualifications:Required Qualifications:

  • Bachelor’s degree and 8 years of experience, Master's degree and 6 years of experience. Additional years of relevant experience may be accepted in lieu of the degree.
  • At least 4 years’ experience using customer-focused Splunk Enterprise Security SIEM engineering background - SME knowledge of ES v4.7
  • At least 4 years’ experience in a senior Splunk role working in a Splunk clustered environment supporting SOC or NOC environments
  • At least 4 years of experience with:
    • In-depth knowledge of designing, upgrading, maintaining and implementing network devices on a large-scale enterprise
    • Direct experience with Splunk Engineering and data integration
    • Prior SIEM data modelling experience on similar platform at scale (>50 servers)
    • Scripting and development skills in Python/Perl with deep comprehension of regular expressions
    • Coordination and communication with other remotely deployed team members
    • Developing documentation with processes and procedures
    • Proposing, implementing automation features in a large enterprise environment
  • At least 3 years of experience with Linux and SQL/ODBC interfaces
  • At least 2 years of experience in app interface development, using REST API’s
  • Hold active Splunk Core Certifications of at least Splunk Architect
  • Minimum of 3 year of experience in developing and tailoring reporting from network security tools.
  • Must be able to obtain and maintain a US Public Trust clearance.

Preferred Qualifications:

  • Experience with Splunk Common Information Model (CIM) and Enterprise Analytic
  • Strong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.
  • Self-starter with the ability to independently prioritize and complete multiple tasks with little to no supervision
  • Knowledge of Cloud Services such as AWS, Azure, Office365
  • Ability to script in one more of the following computer languages Python, Bash, Visual Basic or Powershell
  • Experience in automating Splunk Deployments and orchestration with in a Cloud environment