1

Splunk Siem Engineer Jobs in Puerto Rico (NOW HIRING)

Splunk Siem Engineer information

What are the key skills and qualifications needed to thrive as a Splunk SIEM Engineer, and why are they important?

To thrive as a Splunk SIEM Engineer, you need strong expertise in security information and event management (SIEM), log analysis, scripting, and a background in cybersecurity, often supported by a computer science degree or related certifications. Familiarity with Splunk Enterprise Security, Splunk Query Language (SPL), and certifications like Splunk Certified Power User or Splunk Certified Admin are commonly required. Analytical thinking, problem-solving skills, and effective communication help engineers interpret security data and collaborate with IT teams. These skills are crucial for proactively detecting threats, optimizing security operations, and ensuring the resilience of organizational IT environments.

What are some common challenges faced by Splunk SIEM Engineers when integrating new data sources?

Splunk SIEM Engineers often encounter challenges such as inconsistent log formats, lack of documentation from data source owners, and ensuring data normalization for effective correlation and analysis. Additionally, dealing with high data volume while maintaining system performance and security compliance can be demanding. Close collaboration with IT, security teams, and application owners is critical to troubleshoot issues and fine-tune data onboarding processes.

What is the difference between Splunk Siem Engineer vs Security Analyst?

AspectSplunk Siem EngineerSecurity Analyst
CertificationsSplunk Certified Power User, Splunk Certified AdminCompTIA Security+, GIAC Security Essentials
Work EnvironmentFocus on configuring, maintaining, and optimizing Splunk SIEM toolsMonitor security alerts, investigate incidents, and implement security measures
Industry UsagePrimarily in cybersecurity, IT operations, and complianceAcross cybersecurity teams, incident response, and risk management

The Splunk Siem Engineer specializes in deploying and managing Splunk SIEM solutions, ensuring data ingestion and system performance. In contrast, the Security Analyst focuses on analyzing security data, investigating threats, and responding to incidents. While both roles require security knowledge and certifications, the engineer emphasizes system setup and maintenance, whereas the analyst emphasizes threat detection and response.

What does a Splunk SIEM Engineer do?

A Splunk SIEM Engineer is responsible for designing, implementing, and managing Splunk Security Information and Event Management (SIEM) solutions within an organization. They monitor security events, create dashboards, and develop alerts to detect and respond to potential threats. Their work involves integrating various data sources into Splunk, maintaining system performance, and ensuring compliance with security policies. Splunk SIEM Engineers also play a key role in incident response and help organizations improve their overall security posture.
What are popular job titles related to Splunk Siem Engineer jobs in Puerto Rico? For Splunk Siem Engineer jobs in Puerto Rico, the most frequently searched job titles are:
Infographic showing various Splunk Siem Engineer job openings in Puerto Rico as of July 2026, with employment types broken down into 93% Full Time, 4% Part Time, and 3% Contract. Highlights an 88% Physical, 5% Hybrid, and 7% Remote job distribution.
AI Cyber Defense Engineer - Emerging Risks

AI Cyber Defense Engineer - Emerging Risks

Popular

San Juan, PR • On-site

Full-time

Posted 2 days ago


Job description

Job Summary:
Popular is Puerto Rico’s leading financial institution, and they are seeking an AI Cyber Defense Engineer – Emerging Risks. This role is responsible for designing, building, and improving AI-driven cyber defense capabilities with a focus on threat detection, prevention, response, and remediation.
Responsibilities:
• Support the design, testing, and implementation of AI-enabled cyber defense capabilities across prevention, detection, protection, response, and remediation.
• Evaluate emerging AI, machine learning, automation, and analytics tools for practical cybersecurity use cases.
• Assess how threat actors may use AI to accelerate reconnaissance, social engineering, vulnerability discovery, exploitation, malware generation, credential attacks, and evasion techniques.
• Develop defensive AI use cases that improve threat detection, anomaly analysis, attack path mapping, control validation, incident triage, and remediation decisioning.
• Contribute to the organization’s broader strategy for emerging cyber risks, including AI-enabled threats, autonomous agents, quantum-related risks, supply chain compromise, and advanced offensive cyber techniques.
• Analyze security telemetry, threat intelligence, endpoint data, network activity, cloud signals, identify data, and application indicators to identify opportunities to strengthen cyber defenses.
• Develop or enhance detection logic, monitoring approaches, alerting rules, threat hunting queries, response playbooks, and protective controls
• Use AI, automation, and data analysis to identify, prioritize, and support remediation of high-risk exposures, misconfigurations, vulnerabilities, and control gaps.
• Correlate security findings with asset criticality, business impact, exploitability, threat intelligence, exposure, compensating controls, and regulatory relevance.
• Analyze data from scanners, SIEM, EDR, cloud platforms, CMDBs, APIs, ticketing systems, threat intelligence sources, and raw data files to support risk-based decision-making.
• Recommend appropriate remediation, mitigation, monitoring, isolation, or risk treatment options based on technical feasibility and business context.
• Build scripts, integrations, dashboards, automation workflows, and analytical models that improve cyber defense operations, reduce manual effort, and improve risk-based decision making.
• Evaluate and tune security tools to improve effectiveness, reduce noise, and generate actionable outputs for technical teams.
• Partner with cross-functional stakeholders (Enterprise Architecture, Cloud Platform, DevSecOps, and business/operational teams) to scale cyber defense capabilities without creating unnecessary operational burden.
Qualifications:
Required:
• 5+ years of experience in cybersecurity, security engineering, application security, infrastructure security, or related fields.
• 1+ years of hands-on experience with enterprise AI platforms or frameworks such as AWS Bedrock, OpenAI APIs or similar.
• Strong knowledge with cloud environments (AWS, Azure)
• Strong understanding of vulnerability management, exploitability analysis, threat intelligence, attack paths, security controls, and risk-based remediation
• Hands-on experience with endpoint security, SIEM tools, SOAR, EDR, cloud/application/infrastructure security tools
• Working knowledge of AI, machine learning, LLMs, agentic AI concepts, or AI-assisted security tools, with the ability to evaluate their practical use in cyber defense.
• Experience using scripting, automation, and data analysis to solve security problems
Preferred:
• Experience in financial services, banking, or another regulated industry
• Experience with security tools such as Tenable, Microsoft Defender, Splunk, Sentinel, Zscaler, ServiceNow, Veracode or similar
• Knowledge of how AI frontier models work for cyber security defense
• Experience with cloud platforms, container environments, CI/CD pipelines, identity platforms, network segmentation, zero trust, endpoint hardening, or cryptography
Company:
Popular is a banking firm that provides banking and financial services. Founded in 1893, the company is headquartered in San Juan, PRI, with a team of 5001-10000 employees. The company is currently Late Stage.