As Security Engineer, you'll join the Cybersecurity Operations team, where you'll serve as the ... Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise ...
As Security Engineer, you'll join the Cybersecurity Operations team, where you'll serve as the ... Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise ...
As Security Engineer, you'll join the Cybersecurity Operations team, where you'll serve as the ... Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise ...
Quick apply
As Security Engineer, you'll join the Cybersecurity Operations team, where you'll serve as the ... Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise ...
Security Engineer - SIEM (Splunk) Platform & Operations
San Jose, CA · On-site
$125 - $175/hr
Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise ... Knowledge of detection engineering, correlation rule development, and incident response workflows.
Security Engineer - SIEM (Splunk) Platform & Operations
San Jose, CA · On-site
$125 - $175/hr
Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise ... Knowledge of detection engineering, correlation rule development, and incident response workflows.
As Security Engineer, you'll join the Cybersecurity Operations team, where you'll serve as the ... Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise ...
As Security Engineer, you'll join the Cybersecurity Operations team, where you'll serve as the ... Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise ...
Threat Detection & Response Analyst (CrowdStrike, Splunk, Darktrace, CASB - Must) _San Jose, CA (ons
San Jose, CA · On-site
$85/hr
Conduct proactive threat hunting using SIEM, EDR, CASB, and cloud telemetry to identify advanced or ... Knowledge of detection engineering, correlation logic, MITRE ATT&CK techniques, and SOC operational ...
Threat Detection & Response Analyst (CrowdStrike, Splunk, Darktrace, CASB - Must) _San Jose, CA (ons
San Jose, CA · On-site
$85/hr
Conduct proactive threat hunting using SIEM, EDR, CASB, and cloud telemetry to identify advanced or ... Knowledge of detection engineering, correlation logic, MITRE ATT&CK techniques, and SOC operational ...
Network Security Engineer
San Jose, CA · On-site
$122K - $167K/yr
Administer and fine-tune security technologies including SIEM (Splunk, QRadar), Firewall (Palo Alto ... Mentor and provide technical guidance to L1 and L2 engineers, supporting skill development and ...
Quick apply
Network Security Engineer
San Jose, CA · On-site
$122K - $167K/yr
Administer and fine-tune security technologies including SIEM (Splunk, QRadar), Firewall (Palo Alto ... Mentor and provide technical guidance to L1 and L2 engineers, supporting skill development and ...
Staff Software Engineer - AI/Security Platform
San Francisco, CA · On-site
$170 - $260/hr
Develop an AI DevOps pipeline for rapid experimentation with knowledge bases, models, and context ... SIEM architectures, correlation searches, and threat-hunting support systems * Preferred: Splunk ...
New
Staff Software Engineer - AI/Security Platform
San Francisco, CA · On-site
$170 - $260/hr
Develop an AI DevOps pipeline for rapid experimentation with knowledge bases, models, and context ... SIEM architectures, correlation searches, and threat-hunting support systems * Preferred: Splunk ...
New
Network Security Engineer
San Francisco, CA · Hybrid
$123K - $168K/yr
What We're Looking For We're looking for a Network Security Engineer to design, implement, and ... Experience with SIEM (e.g., Splunk, QRadar), vulnerability scanners (e.g., Nessus, Qualys), and ...
Network Security Engineer
San Francisco, CA · Hybrid
$123K - $168K/yr
What We're Looking For We're looking for a Network Security Engineer to design, implement, and ... Experience with SIEM (e.g., Splunk, QRadar), vulnerability scanners (e.g., Nessus, Qualys), and ...
Host Security Engineer
Pleasanton, CA · On-site
Company Description About the Host Security Engineer Opportunity Talent Connection is partnering ... SIEM & Security Monitoring (Splunk, Microsoft Sentinel, QRadar) * Vulnerability Management (Tenable ...
Host Security Engineer
Pleasanton, CA · On-site
Company Description About the Host Security Engineer Opportunity Talent Connection is partnering ... SIEM & Security Monitoring (Splunk, Microsoft Sentinel, QRadar) * Vulnerability Management (Tenable ...
Host Security Engineer
Pleasanton, CA · On-site
Company Description About the Host Security Engineer Opportunity Talent Connection is partnering ... SIEM & Security Monitoring (Splunk, Microsoft Sentinel, QRadar) * Vulnerability Management (Tenable ...
Host Security Engineer
Pleasanton, CA · On-site
Company Description About the Host Security Engineer Opportunity Talent Connection is partnering ... SIEM & Security Monitoring (Splunk, Microsoft Sentinel, QRadar) * Vulnerability Management (Tenable ...
Host Security Engineer
Pleasanton, CA · On-site
Company Description About the Host Security Engineer Opportunity Talent Connection is partnering ... SIEM & Security Monitoring (Splunk, Microsoft Sentinel, QRadar) * Vulnerability Management (Tenable ...
Quick apply
Host Security Engineer
Pleasanton, CA · On-site
Company Description About the Host Security Engineer Opportunity Talent Connection is partnering ... SIEM & Security Monitoring (Splunk, Microsoft Sentinel, QRadar) * Vulnerability Management (Tenable ...
Senior Security Engineer
San Jose, CA · On-site
$184K - $208K/yr
Experience with SIEM platforms (Splunk, Sentinel, Elastic, or similar) for log analysis and detection engineering * Solid networking knowledge - firewalls, proxies, DNS security, network segmentation ...
Senior Security Engineer
San Jose, CA · On-site
$184K - $208K/yr
Experience with SIEM platforms (Splunk, Sentinel, Elastic, or similar) for log analysis and detection engineering * Solid networking knowledge - firewalls, proxies, DNS security, network segmentation ...
Cyber Security Engineer
Fremont, CA · On-site
... SIEM, vulnerability management, incident response, PKI, user behavior analytics, SSO, IAM ... Splunk, Snowflake, Crowdstrike, Umbrella, Rapid 7 and Cisco Attack Surface Management. Company
Cyber Security Engineer
Fremont, CA · On-site
... SIEM, vulnerability management, incident response, PKI, user behavior analytics, SSO, IAM ... Splunk, Snowflake, Crowdstrike, Umbrella, Rapid 7 and Cisco Attack Surface Management. Company
Security Operations Lead
Foster City, CA · On-site
$140 - $210/hr
This role leads the global SOC function--monitoring, SIEM ownership, detection engineering, alert ... Strong experience with SIEM platforms (Chronicle, Splunk, Elastic, Sentinel, Panther, etc.). * Deep ...
Security Operations Lead
Foster City, CA · On-site
$140 - $210/hr
This role leads the global SOC function--monitoring, SIEM ownership, detection engineering, alert ... Strong experience with SIEM platforms (Chronicle, Splunk, Elastic, Sentinel, Panther, etc.). * Deep ...
Senior Information Security Engineer (Detection, Automation & AI) Software
Foster City, CA · On-site
$190 - $228/hr
Detection Engineering & SIEM Operations * Design, build, test, and maintain high-fidelity detection ... Deep, hands‑on experience with either Splunk (SPL, Enterprise Security) or ElasticSIEM (ES|QL ...
Senior Information Security Engineer (Detection, Automation & AI) Software
Foster City, CA · On-site
$190 - $228/hr
Detection Engineering & SIEM Operations * Design, build, test, and maintain high-fidelity detection ... Deep, hands‑on experience with either Splunk (SPL, Enterprise Security) or ElasticSIEM (ES|QL ...
Senior Staff Software Engineer - AI/Security Platform
San Francisco, CA · Remote
$134K - $185K/yr
Enterprise-grade Security Product Experience - Familiarity with TDIR/SIEM architectures ... Bonus ifyou'veworked with Splunk's APIs, internals, or have experience developing on the Splunk ...
Senior Staff Software Engineer - AI/Security Platform
San Francisco, CA · Remote
$134K - $185K/yr
Enterprise-grade Security Product Experience - Familiarity with TDIR/SIEM architectures ... Bonus ifyou'veworked with Splunk's APIs, internals, or have experience developing on the Splunk ...
Senior Staff Software Engineer - AI/Security Platform
San Jose, CA · Remote
$134K - $184K/yr
Enterprise-grade Security Product Experience - Familiarity with TDIR/SIEM architectures ... Bonus ifyou'veworked with Splunk's APIs, internals, or have experience developing on the Splunk ...
Senior Staff Software Engineer - AI/Security Platform
San Jose, CA · Remote
$134K - $184K/yr
Enterprise-grade Security Product Experience - Familiarity with TDIR/SIEM architectures ... Bonus ifyou'veworked with Splunk's APIs, internals, or have experience developing on the Splunk ...
... Splunk User Behavior Analytics (UBA) or similar behavioral detection platforms * Knowledge of SIEM architecture, data onboarding, and optimization techniques Threat Hunting and Detection Engineering
Quick apply
... Splunk User Behavior Analytics (UBA) or similar behavioral detection platforms * Knowledge of SIEM architecture, data onboarding, and optimization techniques Threat Hunting and Detection Engineering
Enterprise-grade Security Product Experience - Familiarity with TDIR/SIEM architectures ... Bonus if you've worked with Splunk's APIs, internals, or have experience developing on the Splunk ...
Enterprise-grade Security Product Experience - Familiarity with TDIR/SIEM architectures ... Bonus if you've worked with Splunk's APIs, internals, or have experience developing on the Splunk ...
Enterprise-grade Security Product Experience - Familiarity with TDIR/SIEM architectures ... Bonus if you've worked with Splunk's APIs, internals, or have experience developing on the Splunk ...
Enterprise-grade Security Product Experience - Familiarity with TDIR/SIEM architectures ... Bonus if you've worked with Splunk's APIs, internals, or have experience developing on the Splunk ...
Splunk Siem Engineer information
What does a Splunk SIEM Engineer do?
What are the key skills and qualifications needed to thrive as a Splunk SIEM Engineer?
What are some common challenges faced by Splunk SIEM Engineers when integrating new data sources?
What is the difference between Splunk Siem Engineer vs Security Analyst?
| Aspect | Splunk Siem Engineer | Security Analyst |
|---|---|---|
| Certifications | Splunk Certified Power User, Splunk Certified Admin | CompTIA Security+, GIAC Security Essentials |
| Work Environment | Focus on configuring, maintaining, and optimizing Splunk SIEM tools | Monitor security alerts, investigate incidents, and implement security measures |
| Industry Usage | Primarily in cybersecurity, IT operations, and compliance | Across cybersecurity teams, incident response, and risk management |
The Splunk Siem Engineer specializes in deploying and managing Splunk SIEM solutions, ensuring data ingestion and system performance. In contrast, the Security Analyst focuses on analyzing security data, investigating threats, and responding to incidents. While both roles require security knowledge and certifications, the engineer emphasizes system setup and maintenance, whereas the analyst emphasizes threat detection and response.
What job categories do people searching Splunk Siem Engineer jobs in San Ramon, CA look for?
The top searched job categories for Splunk Siem Engineer jobs in San Ramon, CA are:
What cities near San Ramon, CA are hiring for Splunk Siem Engineer jobs?
Cities near San Ramon, CA with the most Splunk Siem Engineer job openings:

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 26 days ago
Samsung SDS America rating
7.1
Based on 16 frontline employees who took The Breakroom Quiz
150th of 226 rated it services
Job description
Position Summary:
As Security Engineer, you'll join the Cybersecurity Operations team, where you'll serve as the frontline detective monitoring and correlating real-time threat data from firewalls, cloud assets, EDR, and AI-driven platforms like Darktrace. You'll design, tune, and optimize Splunk Enterprise Security dashboards, detection rules, and correlation searches to cut false positives while delivering rapid, high-fidelity alerts. Leveraging your experience SOC environments, you'll lead deep incident investigations, spearhead proactive threat-hunting missions, and drive remediation priorities based on risk and business impact. Collaboration is key: you'll partner with global engineers, cloud specialists, and incident-response teams to continuously improve our security posture and document best-practice playbooks.
This is a Full Time Onsite position located in San Jose, CA.
Responsibilities:
- Monitor and analyze security event logs from multiple sources, including firewalls, intrusion detection/prevention systems, endpoint protection platforms, servers, cloud environments, and tools like Darktrace, to identify potential threats.
- Monitor, triage, and investigate alerts and logs within the Splunk SIEM and Splunk Enterprise Security (ES) platform.
- Assist in improving SIEM processes, detection coverage, alert fidelity, and operational workflows including creating dashboards
- Support the onboarding and integration of logs from enterprise systems into the Splunk environment.
- Validate log source completeness, data normalization, rule logic, and alert relevance across critical systems and infrastructure
- Perform initial analysis of security events, escalate incidents when appropriate, and assist with root cause identification.
- Conduct in-depth investigations of security incidents and recommend remediation and containment actions.
- Conduct proactive threat hunting using SIEM, EDR, CASB, and network detection tools, such as Darktrace, to identify suspicious activity that may have bypassed traditional controls.
- Tune and optimize correlation searches, detection rules, dashboards, and use cases to improve operational efficiency and reduce false positives.
- Prioritize remediation efforts based on risk, severity, and business impact.
- Participate in incident response activities and support threat hunting initiatives as needed.
- Collaborate with cross-functional teams to respond effectively to cybersecurity incidents and strengthen overall security posture.
- Create and maintain documentation for log flows, detection use cases, triage procedures, playbooks, cybersecurity processes, and operational standards.
Requirements
- Bachelor's degree in Computer Science, Information Security, Information Assurance, or a related field; Master's degree preferred.
- 3+ years of experience in a cybersecurity operations or related security role.
- 2+ years of hands-on experience administering Splunk Enterprise Security (ES).
- Strong hands-on experience with Splunk log ingestion, data normalization, search heads, indexers, SPL query development, and dashboard optimization.
- Knowledge of detection engineering, correlation rule development, and incident response workflows.
- Proven experience in threat analysis & incident response.
- Strong understanding of security log sources, including Windows and Linux servers, firewalls, endpoint tools, cloud infrastructure, and network detection platforms, such as Darktrace.
- Experience triaging and analyzing security alerts in complex, multi-platform enterprise environments.
- Familiarity with cloud platforms such as AWS, Azure, or similar environments.
- Strong analytical, communication, and collaboration skills, with the ability to clearly present findings and recommendations.
- Ability to work effectively across diverse global teams and adapt to evolving business and technical environments.
- Curious, resilient, and data-driven, with a proactive approach to solving security challenges.
Preferred Qualifications:
- Relevant certifications such as Splunk Enterprise Security Certified Admin.
- Experience with supporting tools such as Darktrace, Crowdstrike, or Netskope are highly preferred
- Active knowledge & experience with rule creation & executing correlation searches in Splunk.
Benefits
Samsung SDSA offers a comprehensive suite of programs to support our employees:
- Top-notch medical, dental, vision and prescription coverage
- Wellness program
- Parental leave
- 401K match and savings plan
- Flexible spending accounts
- Life insurance
- Paid Holidays
- Paid Time off
- Additional benefits
Samsung SDS America, Inc. is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability, status as a protected veteran, marital status, genetic information, medical condition, or any other characteristic protected by law.
We are committed to providing reasonable accommodations to participate in the job application or interview process for candidates with disabilities. Please let your recruiter know if you need an accommodation at any point during the interview process.
The base pay range for this role depends on appropriate skills, experience, and technical level. Career Level 2 base salary is USD $125,000-175,000.
Individual base pay depends on various factors, in addition to primary work location, such as complexity and responsibility of role, job duties/requirements, and relevant experience and skills.
Certain roles are eligible for additional rewards, including annual bonus. U.S.-based employees have access to medical, dental, and vision insurance, a 401(k) plan and company match, short-term and long-term disability coverage, basic life insurance, and wellbeing benefits, among others. U.S.-based employees also receive, per calendar year, up to 10 scheduled paid holidays, and Paid Time Off.
What Samsung SDS America employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Samsung SDSA
Sourced by ZipRecruiter
Industry
It services
Company size
10,000+ Employees
Headquarters location
Ridgefield Park, NJ, US
Year founded
1985