Security Observability Engineer Job Overview We are seeking an experienced Security Observability ... The role emphasizes secure data delivery, advanced SIEM coverage, Splunk expertise, data reduction ...
Security Observability Engineer Job Overview We are seeking an experienced Security Observability ... The role emphasizes secure data delivery, advanced SIEM coverage, Splunk expertise, data reduction ...
Security Observability Engineer Job Overview We are seeking an experienced Security Observability ... The role emphasizes secure data delivery, advanced SIEM coverage, Splunk expertise, data reduction ...
Security Observability Engineer Job Overview We are seeking an experienced Security Observability ... The role emphasizes secure data delivery, advanced SIEM coverage, Splunk expertise, data reduction ...
SIEM/SOAR Engineer[Onsite]
Tampa, FL · On-site
SIEM/SOAR Security Engineer Visa: USC, GC, GC-EAD, H4-EAD Interview: Video Mode: Onsite Work ... Working knowledge in RegEx, Splunk search language, etc. is required. Knowledge and experience in ...
Quick apply
SIEM/SOAR Engineer[Onsite]
Tampa, FL · On-site
SIEM/SOAR Security Engineer Visa: USC, GC, GC-EAD, H4-EAD Interview: Video Mode: Onsite Work ... Working knowledge in RegEx, Splunk search language, etc. is required. Knowledge and experience in ...
Sr. Security Engineer (SIEM) - Vice President
Tampa, FL · Hybrid
$108K - $148K/yr
Maintain the current customer managed Splunk infrastructure * Support log onboarding and alert ... Subject matter expertise in administration of SIEM Splunk Cloud, Splunk Enterprise, Splunk Phantom ...
Sr. Security Engineer (SIEM) - Vice President
Tampa, FL · Hybrid
$108K - $148K/yr
Maintain the current customer managed Splunk infrastructure * Support log onboarding and alert ... Subject matter expertise in administration of SIEM Splunk Cloud, Splunk Enterprise, Splunk Phantom ...
The Lead Engineer is also part of the Raymond James Splunk administration team and is responsible for the operation and maintenance of the Raymond James Splunk Cloud environment, including search ...
The Lead Engineer is also part of the Raymond James Splunk administration team and is responsible for the operation and maintenance of the Raymond James Splunk Cloud environment, including search ...
The Lead Engineer is also part of the Raymond James Splunk administration team and is responsible for the operation and maintenance of the Raymond James Splunk Cloud environment, including search ...
The Lead Engineer is also part of the Raymond James Splunk administration team and is responsible for the operation and maintenance of the Raymond James Splunk Cloud environment, including search ...
Journeyman Cyber Security Engineer (Splunk/SIPR) - USSOCOM EDAT with Security Clearance
Tampa, FL · On-site
... SIEM), and Security Orchestration, Automation, and Response (SOAR) capabilities. The Journeyman Cyber Security Engineer will work as part of a multidisciplinary Zero Trust team supporting the ...
Journeyman Cyber Security Engineer (Splunk/SIPR) - USSOCOM EDAT with Security Clearance
Tampa, FL · On-site
... SIEM), and Security Orchestration, Automation, and Response (SOAR) capabilities. The Journeyman Cyber Security Engineer will work as part of a multidisciplinary Zero Trust team supporting the ...
Journeyman Cyber Security Engineer (Splunk/TS) - USSOCOM EDAT Ze with Security Clearance
Tampa, FL · On-site
The selected candidate will assist with SIEM, UEBA, and SOAR integrations while supporting security ... Experience with Splunk administration and engineering. * Experience with Splunk Enterprise Security ...
Journeyman Cyber Security Engineer (Splunk/TS) - USSOCOM EDAT Ze with Security Clearance
Tampa, FL · On-site
The selected candidate will assist with SIEM, UEBA, and SOAR integrations while supporting security ... Experience with Splunk administration and engineering. * Experience with Splunk Enterprise Security ...
... Engineer. The role focuses on leading the migration, optimization, and secure operation of log ... SIEM coverage, Splunk expertise, data reduction strategies, and robust load balancing and high ...
... Engineer. The role focuses on leading the migration, optimization, and secure operation of log ... SIEM coverage, Splunk expertise, data reduction strategies, and robust load balancing and high ...
Security Operations Center Cloud Engineer
Coral Gables, FL · On-site
$165/hr
Ensure AWS and Azure log sources are properly ingested into the SIEM (e.g., Splunk) and normalized ... Work with infrastructure and DevOps teams to improve visibility and security posture across AWS and ...
Security Operations Center Cloud Engineer
Coral Gables, FL · On-site
$165/hr
Ensure AWS and Azure log sources are properly ingested into the SIEM (e.g., Splunk) and normalized ... Work with infrastructure and DevOps teams to improve visibility and security posture across AWS and ...
Security Operations Center Cloud Engineer
Coral Gables, FL · On-site +1
$165/hr
The Senior Security Operations Center (SOC) Cloud Engineer is responsible for monitoring, detecting ... Experience using SIEM platforms (preferably Splunk) for log ingestion, correlation, and threat ...
Security Operations Center Cloud Engineer
Coral Gables, FL · On-site +1
$165/hr
The Senior Security Operations Center (SOC) Cloud Engineer is responsible for monitoring, detecting ... Experience using SIEM platforms (preferably Splunk) for log ingestion, correlation, and threat ...
Senior Detection Engineer
Tampa, FL · On-site +1
$108K - $148K/yr
As a Senior Detection Engineer, you will be responsible for technical execution and delivery of ... Experience with SIEM technologies such as Splunk (preferred), Microsoft Sentinel, Google Chronicle ...
Senior Detection Engineer
Tampa, FL · On-site +1
$108K - $148K/yr
As a Senior Detection Engineer, you will be responsible for technical execution and delivery of ... Experience with SIEM technologies such as Splunk (preferred), Microsoft Sentinel, Google Chronicle ...
Senior Detection Engineer
Tampa, FL · On-site +1
$108K - $148K/yr
As a Senior Detection Engineer, you will be responsible for technical execution and delivery of ... Experience with SIEM technologies such as Splunk (preferred), Microsoft Sentinel, Google Chronicle ...
Senior Detection Engineer
Tampa, FL · On-site +1
$108K - $148K/yr
As a Senior Detection Engineer, you will be responsible for technical execution and delivery of ... Experience with SIEM technologies such as Splunk (preferred), Microsoft Sentinel, Google Chronicle ...
Senior Detection Engineer
Tampa, FL · On-site +1
$108K - $148K/yr
As a Senior Detection Engineer, you will be responsible for technical execution and delivery of ... Experience with SIEM technologies such as Splunk (preferred), Microsoft Sentinel, Google Chronicle ...
Senior Detection Engineer
Tampa, FL · On-site +1
$108K - $148K/yr
As a Senior Detection Engineer, you will be responsible for technical execution and delivery of ... Experience with SIEM technologies such as Splunk (preferred), Microsoft Sentinel, Google Chronicle ...
Cybersecurity Engineer
Miami, FL · On-site
$100K - $150K/yr
Cybersecurity Engineer We work with companies protecting modern digital systems-and we're looking ... SIEM tools (Splunk, Sentinel) * Cloud security (AWS, Azure, GCP) * Identity & access management
Cybersecurity Engineer
Miami, FL · On-site
$100K - $150K/yr
Cybersecurity Engineer We work with companies protecting modern digital systems-and we're looking ... SIEM tools (Splunk, Sentinel) * Cloud security (AWS, Azure, GCP) * Identity & access management
Accenture Federal Services is seeking an experienced Cloud Information Systems Security Engineer ... Hands-on experience with ACAS/Nessus scanning and SIEM/Splunk dashboard creation for continuous ...
Accenture Federal Services is seeking an experienced Cloud Information Systems Security Engineer ... Hands-on experience with ACAS/Nessus scanning and SIEM/Splunk dashboard creation for continuous ...
Advanced Cyber Security Engineer Operational role on Splunk & XSOAR (our Soar platform). Should ... or any other SIEM tool) and perform periodic maintenance activities • Deploy and evaluate ...
Advanced Cyber Security Engineer Operational role on Splunk & XSOAR (our Soar platform). Should ... or any other SIEM tool) and perform periodic maintenance activities • Deploy and evaluate ...
The Senior IT Cyber Security Engineer is a technical, hands-on role spanning Security Operations ... native SIEM and SOAR platforms (e.g., Google SecOps / Chronicle, Splunk, Microsoft Sentinel, or ...
The Senior IT Cyber Security Engineer is a technical, hands-on role spanning Security Operations ... native SIEM and SOAR platforms (e.g., Google SecOps / Chronicle, Splunk, Microsoft Sentinel, or ...
The Senior IT Cyber Security Engineer is a technical, hands-on role spanning Security Operations ... native SIEM and SOAR platforms (e.g., Google SecOps / Chronicle, Splunk, Microsoft Sentinel, or ...
The Senior IT Cyber Security Engineer is a technical, hands-on role spanning Security Operations ... native SIEM and SOAR platforms (e.g., Google SecOps / Chronicle, Splunk, Microsoft Sentinel, or ...
Security Operations Engineer, Associate - Security Operations Engineering
Miami, FL · On-site
$106K - $170K/yr
The Associate Security Engineer is responsible for providing Security Information and Event ... Hands-on experience with SIEM (e.g. Splunk) for detection and security orchestration and automated ...
Security Operations Engineer, Associate - Security Operations Engineering
Miami, FL · On-site
$106K - $170K/yr
The Associate Security Engineer is responsible for providing Security Information and Event ... Hands-on experience with SIEM (e.g. Splunk) for detection and security orchestration and automated ...
Splunk Siem Engineer information
See Florida salary details
$43.4K - $52.6K
1% of jobs
$52.6K - $61.7K
2% of jobs
$61.7K - $70.9K
7% of jobs
$70.9K - $80.1K
11% of jobs
$82.9K is the 25th percentile. Wages below this are outliers.
$80.1K - $89.2K
13% of jobs
The median wage is $97.6K / yr.
$89.2K - $98.4K
18% of jobs
$98.4K - $107.5K
19% of jobs
$111.9K is the 75th percentile. Wages above this are outliers.
$107.5K - $116.7K
9% of jobs
$116.7K - $125.9K
7% of jobs
$125.9K - $135K
6% of jobs
$135K - $144.2K
6% of jobs
$43.4K
$100.4K
$144.2K
How much do splunk siem engineer jobs pay per year?
What are the key skills and qualifications needed to thrive as a Splunk SIEM Engineer, and why are they important?
What are some common challenges faced by Splunk SIEM Engineers when integrating new data sources?
What is the difference between Splunk Siem Engineer vs Security Analyst?
| Aspect | Splunk Siem Engineer | Security Analyst |
|---|---|---|
| Certifications | Splunk Certified Power User, Splunk Certified Admin | CompTIA Security+, GIAC Security Essentials |
| Work Environment | Focus on configuring, maintaining, and optimizing Splunk SIEM tools | Monitor security alerts, investigate incidents, and implement security measures |
| Industry Usage | Primarily in cybersecurity, IT operations, and compliance | Across cybersecurity teams, incident response, and risk management |
The Splunk Siem Engineer specializes in deploying and managing Splunk SIEM solutions, ensuring data ingestion and system performance. In contrast, the Security Analyst focuses on analyzing security data, investigating threats, and responding to incidents. While both roles require security knowledge and certifications, the engineer emphasizes system setup and maintenance, whereas the analyst emphasizes threat detection and response.
What does a Splunk SIEM Engineer do?

Full-time
Re-posted 20 days ago
Job description
Security Observability Engineer
Job Overview
We are seeking an experienced Security Observability Engineer to lead the migration, optimization, and secure operation of our log ingestion and observability pipelines. The role emphasizes secure data delivery, advanced SIEM coverage, Splunk expertise, data reduction strategies, and robust load balancing and high availability for log infrastructure.
Key Responsibilities
• End-to-End SIEM Pipeline Management & Optimization
• Lead the migration of log sources from Splunk ingestion to Cribl Stream/Edge
pipelines, ensuring load-balanced, fault-tolerant delivery and processing of security and IT logs.
• Architect and manage scalable, resilient pipelines-including design,
implementation, and operation of load balancing solutions (e.g., Cribl worker groups, external load balancers, or syslog load distribution) for high ingest volumes.
• Analyze, tune and securely onboard all log sources (firewalls, EDR, cloud,
authentication, proxies, etc.)-covering parsing, filtering, and data reduction techniques to minimize Splunk ingest/storage costs without sacrificing security coverage.
• Develop and maintain Cribl and Splunk configurations, including advanced
transformations, field normalization, masking, and enrichment for security analytics.
• Ensure optimal distribution of logging workload across Cribl worker nodes and
Splunk indexers to prevent bottlenecks, data loss, or single points of failure. • Security Event Visibility and SOC Enablement
• Collaborate with SOC, IR, and threat detection teams to ensure all security logs
reach the SIEM eRiciently and reliably, and logs are tuned for actionable detection. • Actively monitor, test, and remediate pipeline balancing and ingestion health to
maximize uptime and forensic visibility.
• Respond to and resolve SIEM and pipeline issues that impact security, detection, or
compliance visibility.
• Governance, Compliance & Documentation
• Apply and document security policies for log routing, load balancing, event
retention, and integrity-ensuring pipeline architecture meets audit, legal, and privacy requirements.
• Track and report ingest reduction, Splunk cost savings, pipeline health, and event
loss/drop rates across the load-balanced infrastructure.
• Maintain clear, up-to-date documentation of log flows, pipeline topology, load
balancing strategies, and operational procedures.
Required Skills & Qualifications
• Extensive hands-on experience with Splunk SIEM engineering (indexers, search
heads, clustering, forwarders, CIM, performance/load optimization).
• 2+ years with Cribl Stream/Edge, including deployment and tuning of distributed,
load-balanced pipelines.
• Deep understanding of machine data transport (syslog, HEC, TCP, UDP), log
balancing strategies (syslog balancers, DNS round-robin, Cribl worker groups, etc.), and high-availability logging environments.
• Proven expertise onboarding, parsing, and tuning security log sources (firewalls,
cloud, EDR/XDR, IAM, authentication, and networking) for best possible coverage and SOC/IR support.
• Advanced Splunk SPL, data model, event parsing, and alert tuning skills; practical
SIEM optimization experience.
• Scripting/automation ability (Python, shell/CLI, or similar) for pipeline management
and validation.
• Strong troubleshooting, monitoring, and operational dashboard skills for both
pipeline and SIEM health.
Preferred Qualifications
• Hands-on experience designing and operating clustered/HA Cribl and Splunk
deployments (worker groups, clustered indexers, resilient data forwarders, etc.). • Splunk ES or Cribl certifications.
Key Success Metrics
• No loss of security data or alert coverage during/after pipeline migration and
optimization.
• Documented, measurable reductions in Splunk ingest volume and
operational/storage cost.
• Consistently balanced log throughput and minimal risk of bottlenecks or
overloads-pipeline health and reliability metrics maintained above SLA. • Well-documented, adaptable pipeline and load balancing architecture.
The estimated salary range for this position is 90k-120k
Starr is an equal opportunity employer, which means we'll consider all suitably qualified applicants regardless of gender identity or expression, ethnic origin, nationality, religion or beliefs, age, sexual orientation, disability status or any other protected characteristic. We recruit and develop our people based on merit and we're committed to creating an inclusive environment for all employees. We offer first class training and development opportunities to all employees. Our aim is to grow our own talent and bring out the best in people.