1

Splunk Security Engineer Jobs (NOW HIRING)

The Splunk SOAR Engineer will lead the full lifecycle of platform architecture, integration ... Adhere to security best practices and compliance requirements within the operational environment.

Showing results 21-40

Splunk Security Engineer information

See salary details

$61.5K

$152.8K

$205.5K

How much do splunk security engineer jobs pay per year?

As of Aug 13, 2026, the average yearly pay for splunk security engineer in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Splunk Security Engineer?

To thrive as a Splunk Security Engineer, you need strong expertise in cybersecurity principles, log analysis, and experience with Splunk Enterprise or Splunk Cloud platforms, often supported by a related degree or certifications like Splunk Certified Power User or Architect. Familiarity with SIEM tools, scripting languages (e.g., Python), and integration of security data sources is essential. Strong problem-solving, attention to detail, and excellent communication skills help you collaborate effectively with IT and security teams. These skills are crucial for proactively detecting threats, improving system security, and ensuring an organization's digital safety.

What does a Splunk Security Engineer do?

A typical day for a Splunk Security Engineer involves monitoring security alerts and dashboards, investigating and responding to potential threats, and fine-tuning Splunk queries or correlation searches. You may work closely with SOC analysts, network engineers, and system administrators to interpret security logs, uncover patterns, and implement new detection rules or data integrations. Additionally, you might help with onboarding new data sources into Splunk and contribute to incident response activities or post-incident reviews. The role is highly collaborative and often fast-paced, requiring a blend of analytical and technical skills to keep organizational data secure.

What is a Splunk Security Engineer?

A Splunk Security Engineer is responsible for implementing, managing, and optimizing Splunk for security operations. They design and maintain Splunk infrastructure, create alerts and dashboards, and analyze security logs to detect threats. Their role involves integrating Splunk with various security tools and developing custom use cases for threat detection and response. Additionally, they collaborate with security teams to enhance monitoring capabilities and ensure compliance with organizational security policies.

More about Splunk Security Engineer jobs
What cities are hiring for Splunk Security Engineer jobs? Cities with the most Splunk Security Engineer job openings:
What are the most commonly searched types of Splunk Security Engineer jobs? The most popular types of Splunk Security Engineer jobs are:
What states have the most Splunk Security Engineer jobs? States with the most job openings for Splunk Security Engineer jobs include:
What job categories do people searching Splunk Security Engineer jobs look for? The top searched job categories for Splunk Security Engineer jobs are:
Infographic showing various Splunk Security Engineer job openings in the United States as of August 2026, with employment types broken down into 85% Full Time, 12% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $152,773 per year, or $73.4 per hour.

$95K - $112K/yr

Full-time

Medical, Retirement, PTO

Re-posted 14 days ago


Job description

Position Overview
Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.
We are seeking a skilled Splunk SIEM Engineer to lead the evolution of our Splunk environment into a fully operational, enterprise-grade Security Information and Event Management (SIEM) platform. This role will be responsible for both the build-out and ongoing operations of the platform, ensuring it delivers reliable, actionable security insights and supports evolving cybersecurity initiatives. This is a hybrid position that requires regular onsite presence in Crane, Indiana.
Key Responsibilities
  • Lead the transformation of the Splunk environment into a fully functional SIEM platform
  • Manage and optimize the data ingestion pipeline:
    • Audit existing data sources for relevance and efficiency
    • Eliminate unnecessary data ingestion to control licensing costs
    • Onboard and integrate new data sources
  • Parse, normalize, and map ingested data to the Splunk Common Information Model (CIM)
  • Configure, maintain, and optimize Splunk Enterprise Security (ES)
  • Configure, maintain, and optimize Splunk security orchestration, automation, and response platform (SOAR)
  • Develop and maintain correlation searches, detections, and use cases
  • Create and tune alerts to improve fidelity and reduce false positives
  • Build dashboards and visualizations for operational awareness and trend analysis
  • Monitor overall platform health and performance
  • Perform system upgrades, patching, and capacity planning
  • Manage intra Splunk certificates
  • Manage the lifecycle of security content:
    • Continuously refine detections and correlation rules
    • Enhance visibility and detection coverage based on emerging threats
  • Ensure consistent SIEM operations regardless of hosting environment or infrastructure ownership
  • Support ongoing security operations and future cybersecurity initiatives

Requirements
Required Qualifications
  • A SecurityX, CASP, or equivalent DoD 8140 IAT-3 certification is required.
  • Security Clearance: An interim DoD Secret security clearance or higher is required to start. Applicant selected may be subject to a security investigation and must meet eligibility requirements for access to classified information.
  • Hands-on experience with Splunk Enterprise and Splunk Enterprise Security (ES)
  • Strong understanding of SIEM architecture, design, and operations
  • Experience with log ingestion, parsing, normalization, and CIM mapping
  • Proficiency in developing correlation searches, alerts, and dashboards
  • Experience tuning SIEM content to reduce false positives and improve detection accuracy
  • Familiarity with data onboarding strategies and license optimization
  • Knowledge of cybersecurity principles, threat detection, and incident response
  • Experience with system administration tasks including patching, upgrades, and performance monitoring

Preferred Qualifications
  • Experience operating Splunk in distributed or multi-tenant environments
  • Knowledge of data pipelines and log forwarding technologies (e.g., syslog, APIs, forwarders)
  • Familiarity with frameworks such as MITRE ATT&CK
  • Experience supporting Zero Trust or advanced security architectures
  • Preferred certifications (e.g., Splunk Certified Admin, Splunk ES Certified, Security+)

Benefits
At RMC, we're committed to your career growth! RMC differentiates itself from other firms through its investment in our employees. We invest our resources to train, certify, educate, and build our employees. RMC can offer you a great place to work with a small company feel and give you the experience, tuition assistance, and certifications that will take your career to the next level. This includes a competitive paid vacation package with 11 paid federal holidays. We also offer high-quality, low-deductible healthcare plans, pet insurance, and a competitive 401K package.
Salary at RMC is determined by various factors, including but not limited to location, a candidate's specific combination of education, knowledge, skills, competencies, and experience, as well as contract-specific requirements. The current salary range for this position will be $95,000 to $112,000 (annually).
#LI-MB1 #IND123