1

Splunk Siem Engineer Jobs in Tennessee (NOW HIRING)

DLP Engineer

Memphis, TN · On-site

$90 - $120/hr

This role combines security operations with platform engineering: the analyst will investigate and ... Use Microsoft Purview, Microsoft Defender, SentinelOne EDR, Splunk SIEM, audit, identity, and ...

New

Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process ... Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent ...

Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process ... Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent ...

next page

Showing results 1-20

Splunk Siem Engineer information

See Tennessee salary details

$55K

$127.2K

$182.7K

How much do splunk siem engineer jobs pay per year?

As of Sep 2, 2026, the average yearly pay for splunk siem engineer in Tennessee is $127,213.00, according to ZipRecruiter salary data. Most workers in this role earn between $105,477.00 and $146,860.00 per year, depending on experience, location, and employer.

What does a Splunk SIEM Engineer do?

A Splunk SIEM Engineer is responsible for designing, implementing, and managing Splunk Security Information and Event Management (SIEM) solutions within an organization. They monitor security events, create dashboards, and develop alerts to detect and respond to potential threats. Their work involves integrating various data sources into Splunk, maintaining system performance, and ensuring compliance with security policies. Splunk SIEM Engineers also play a key role in incident response and help organizations improve their overall security posture.

What are the key skills and qualifications needed to thrive as a Splunk SIEM Engineer?

To thrive as a Splunk SIEM Engineer, you need strong expertise in security information and event management (SIEM), log analysis, scripting, and a background in cybersecurity, often supported by a computer science degree or related certifications. Familiarity with Splunk Enterprise Security, Splunk Query Language (SPL), and certifications like Splunk Certified Power User or Splunk Certified Admin are commonly required. Analytical thinking, problem-solving skills, and effective communication help engineers interpret security data and collaborate with IT teams. These skills are crucial for proactively detecting threats, optimizing security operations, and ensuring the resilience of organizational IT environments.

What are some common challenges faced by Splunk SIEM Engineers when integrating new data sources?

Splunk SIEM Engineers often encounter challenges such as inconsistent log formats, lack of documentation from data source owners, and ensuring data normalization for effective correlation and analysis. Additionally, dealing with high data volume while maintaining system performance and security compliance can be demanding. Close collaboration with IT, security teams, and application owners is critical to troubleshoot issues and fine-tune data onboarding processes.

What is the difference between Splunk Siem Engineer vs Security Analyst?

AspectSplunk Siem EngineerSecurity Analyst
CertificationsSplunk Certified Power User, Splunk Certified AdminCompTIA Security+, GIAC Security Essentials
Work EnvironmentFocus on configuring, maintaining, and optimizing Splunk SIEM toolsMonitor security alerts, investigate incidents, and implement security measures
Industry UsagePrimarily in cybersecurity, IT operations, and complianceAcross cybersecurity teams, incident response, and risk management

The Splunk Siem Engineer specializes in deploying and managing Splunk SIEM solutions, ensuring data ingestion and system performance. In contrast, the Security Analyst focuses on analyzing security data, investigating threats, and responding to incidents. While both roles require security knowledge and certifications, the engineer emphasizes system setup and maintenance, whereas the analyst emphasizes threat detection and response.

What job categories do people searching Splunk Siem Engineer jobs in Tennessee look for?

The top searched job categories for Splunk Siem Engineer jobs in Tennessee are:

What cities in Tennessee are hiring for Splunk Siem Engineer jobs?

Cities in Tennessee with the most Splunk Siem Engineer job openings:

Infographic showing various Splunk Siem Engineer job openings in Tennessee as of August 2026, with employment types broken down into 90% Full Time, 4% Part Time, and 6% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $127,213 per year, or $61.2 per hour.

$90 - $120/hr

Other

Posted yesterday

New


Job description

Data Security & Insider Risk Analyst

Suggested alternate title: Data Security Analyst – DLP & Insider Risk

Position Summary

We are seeking a hands‑on Data Security & Insider Risk Analyst to protect sensitive information across Microsoft 365, endpoints, and other enterprise platforms. This role combines security operations with platform engineering: the analyst will investigate and respond to data loss prevention (DLP), insider risk, and endpoint security events while continuously tuning Microsoft Purview policies, detections, and workflows to improve accuracy and reduce risk. The ideal candidate is analytical, curious, and comfortable translating security data into clear findings and practical control improvements.

Key Responsibilities
  • Monitor, triage, investigate, and respond to DLP, insider risk, and endpoint security alerts and incidents.
  • Determine incident scope, business context, data sensitivity, user activity, and potential impact; document findings and coordinate appropriate containment, escalation, and remediation.
  • Administer and tune Microsoft Purview DLP policies, rules, sensitive information types, classifiers, alert thresholds, exceptions, and user notifications.
  • Support DLP controls across Exchange, SharePoint, OneDrive, Teams, endpoints, browsers, removable media, printing, clipboard activity, and cloud applications, as applicable.
  • Review false positives, false negatives, user overrides, and recurring alert patterns; recommend and implement policy improvements.
  • Support Microsoft Purview Insider Risk Management use cases, indicators, policies, alerts, cases, and privacy‑aware investigation workflows.
  • Partner with identity, corporate security, human resources, incident response teams, and line‑of‑business teams during investigations, containment, remediation, and control changes.
  • Use Microsoft Purview, Microsoft Defender, SentinelOne EDR, Splunk SIEM, audit, identity, and endpoint telemetry to build investigation timelines, correlate activity, and validate findings.
  • Create dashboards, metrics, and trend analyses that communicate incident volume, policy effectiveness, data movement, root causes, and control gaps.
  • Develop and maintain procedures, investigation playbooks, tuning standards, exception records, and knowledge articles.
  • Participate in testing, change management, and phased deployment of new or updated data protection controls.
  • Identify opportunities for automation, enrichment, and workflow integration that improve response speed and consistency.
Required Qualifications
  • Experience in information security, data protection, security operations, incident response, threat analysis, compliance operations, criminology, law enforcement, corporate security, fraud investigation, or a related discipline. Candidates with transferable investigative experience are encouraged to apply.
  • Working knowledge of DLP concepts, data classification, sensitive data handling, insider risk, and common data exfiltration paths.
  • Ability to investigate alerts using evidence from users, devices, applications, email, collaboration platforms, and audit logs.
  • Experience configuring or tuning security policies, detections, rules, or alerting logic in an enterprise environment.
  • Strong analytical and problem‑solving skills, including the ability to distinguish legitimate business activity from potential misuse.
  • Clear written and verbal communication skills, with the judgment to handle sensitive investigations professionally and confidentially.
  • Ability to manage multiple investigations and tuning efforts while maintaining accurate case documentation.
Preferred Qualifications
  • Hands‑on experience with Microsoft Purview Data Loss Prevention, Endpoint DLP, Insider Risk Management, Information Protection, Data Explorer, Activity Explorer, or related capabilities.
  • Hands‑on experience with Zscaler Data Loss Prevention (DLP), including policy configuration, content inspection, alert investigation, false‑positive tuning, or data exfiltration controls across web, cloud applications and email.
  • Experience investigating Microsoft Purview alerts and incidents through Microsoft Defender or an integrated SIEM/SOAR workflow.
  • Experience using any endpoint detection and response (EDR) platform to investigate endpoint activity, correlate alerts, or support containment and remediation. Experience with comparable EDR tools is readily transferable to SentinelOne, which is used in this role.
  • Data analytics or reporting experience using Power BI, Tableau, SQL, Kusto Query Language (KQL), Excel, or similar tools.
  • Experience using any security information and event management (SIEM) platform for searching, correlation, dashboards, reporting, or investigation support. Experience with comparable SIEM tools is readily transferable to Splunk, which is used in this role.
  • Understanding of Microsoft 365 services, Microsoft Entra ID, endpoint management, audit logging, and cloud security concepts.
  • Experience in a regulated industry or with privacy, records management, legal, HR, or compliance stakeholders.
  • Relevant certifications, such as Microsoft Information Protection and Compliance Administrator (SC‑400), Microsoft Security Operations Analyst (SC‑200), Security+, or equivalent practical experience.
  • Professional experience in criminology, law enforcement, corporate security, fraud, investigations, or a similar field that demonstrates sound investigative judgment, evidence handling, interviewing, case management, or pattern analysis.
What Success Looks Like
  • DLP and insider risk alerts are investigated promptly, consistently, and with clear supporting evidence.
  • Policies become more effective over time, with fewer unnecessary alerts and better coverage of meaningful risk.
  • Incident trends and control gaps are translated into measurable recommendations for security and business partners.
  • Investigation procedures, tuning decisions, and exceptions are documented and repeatable.
  • Data security, endpoint security, and business stakeholders collaborate effectively on remediation and risk reduction.
Ideal Candidate Profile

You enjoy both sides of data security operations: working an alert through investigation and resolution, then using what you learned to improve the control that generated it. You can analyze technical evidence, understand business context, communicate findings without unnecessary jargon, and make thoughtful tuning decisions that balance protection with user productivity.

#J-18808-Ljbffr