Retour à la recherche
J
JobgetherSource d’offres vérifiée

Splunk Enterprise Security Expert

Offre en anglais

Establish and enforce enterprise-wide Splunk governance, naming conventions, and lifecycle management for security content. Design and maintain CIM normalization, data models, and automation pipelines to improve detection quality and search performance.

  • Télétravail
  • Canada
  • Publié 26 août 2026
  • 1 poste

D’autres postes auxquels postuler directement

Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.

Résumé du poste

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Splunk Enterprise Security Expert based in Canada. This role offers the opportunity to shape enterprise-wide Splunk governance and security content architecture at significant scale. You’ll serve as a technical authority across Splunk Enterprise, Enterprise Security, CIM normalization, data models, and knowledge object lifecycle management. Your work will help security teams improve detection quality, search performance, governance, and operational consistency across complex environments. You’ll establish standards, automate processes, and ensure security content moves reliably from development through testing and production. The role combines hands-on engineering with architecture, documentation, cross-functional collaboration, and governance leadership. You’ll work across cloud, infrastructure, security operations, compliance, and detection engineering teams to create scalable and maintainable solutions. This is an ideal opportunity for a seasoned Splunk professional who enjoys solving complex platform challenges and establishing enterprise-level technical standards. Accountabilities Provide centralized governance and lifecycle management for Splunk knowledge objects, including saved searches, correlation searches, field extractions, tags, aliases, event types, lookups, macros, data models, workflow actions, and KV Store collections. Establish and enforce enterprise-wide naming conventions, taxonomy standards, ownership models, permissions, and lifecycle processes for Splunk content. Audit knowledge object libraries to identify duplicate, orphaned, deprecated, or conflicting content and drive consolidation or retirement where appropriate. Develop automation to monitor data ingestion, data flow consistency, normalization drift, and other critical aspects of the Splunk environment. Maintain an enterprise knowledge object registry documenting ownership, scope, purpose, permissions, and lifecycle stage. Collaborate with platform teams to define appropriate permission structures and sharing models across applications, environments, and user groups. Lead the promotion of knowledge objects through development, testing, staging, and production using change control, CI/CD, and GitOps practices. Serve as the enterprise authority for Splunk Common Information Model (CIM) normalization and maintain compliant field mappings across endpoint, network, identity, cloud, and application data sources. Design, build, and maintain Splunk data models supporting Pivot users, Enterprise Security correlation searches, reporting, and risk-based analytics. Manage data model acceleration strategies, including TSIDX, tstats, and summary indexing, while monitoring search load, acceleration performance, and coverage. Define and enforce source-type and index taxonomy standards to improve search performance, configuration consistency, and usability across teams. Ensure asset zones, network zones, identity tiers, and other entity enrichment are incorporated into data models and Enterprise Security frameworks. Maintain CIM coverage matrices connecting data model fields with MITRE ATT&CK techniques, detection use cases, and compliance controls. Own the enterprise Splunk knowledge architecture, including taxonomy hierarchies, content standards, metadata schemas, and classification frameworks. Develop and maintain knowledge management standards covering naming conventions, lifecycle stages, ownership, permissions, CIM mappings, and change control procedures. Lead a cross-functional knowledge governance working group involving detection engineering, SOC operations, platform engineering, compliance, and application teams. Create reusable templates for correlation searches, dashboards, reports, lookups, and macros to accelerate development while maintaining governance standards. Design and implement automation using Python, Bash, GitHub Actions, and related tooling to improve knowledge object management and deployment. Maintain clear technical documentation, including architecture documentation, standards guides, runbooks, and operational procedures. Support detection engineering, threat hunting, and SOC teams by ensuring Splunk content is reliable, discoverable, performant, and aligned with operational needs. Requirements Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience. 8+ years of hands-on Splunk experience in enterprise environments. At least 3 years of direct experience in Splunk knowledge management, CIM normalization, SIEM content engineering, or comparable large-scale Splunk environments. Experience working with large-scale Splunk deployments, ideally handling 20+ TB of data per day. Deep expertise in Splunk Enterprise Security, including correlation searches, notable events, risk-based alerting, ES data models, threat intelligence, and asset and identity frameworks. Advanced proficiency in SPL, including complex statistical pipelines, tstats, macros, sub-searches, evaluation functions, and streaming and non-streaming commands. Strong understanding of Splunk data models, acceleration strategies, Pivot functionality, and Enterprise Security dependencies. Comprehensive knowledge of Splunk knowledge objects and their full lifecycle, including field extractions, lookups, KV Store collections, macros, tags, aliases, event types, workflow actions, saved searches, and correlation searches. Deep administrative and engineering experience with distributed, multi-site, and clustered Splunk Enterprise environments. Experience developing or reviewing Splunk Technology Add-ons and applications, including packaging and deployment through Deployment Server and Deployer. Strong understanding of Splunk configuration management, including configuration files, btool, precedence rules, and the Splunk Admin Config Service. Experience with Splunk Edge Processor or Ingest Processor and awareness of pipeline-level routing and data transformation. Practical experience integrating telemetry from AWS, Azure, and GCP environments and normalizing cloud-native data sources. Strong Linux and Windows administration knowledge. Experience using Python and Bash/Shell scripting to automate Splunk administration, knowledge object management, and API-driven deployments. Experience with GitHub, GitHub Actions, CI/CD pipelines, and version-controlled content promotion workflows. Familiarity with MITRE ATT&CK, NIST CSF, NIST 800-53, CIS Benchmarks, and security or compliance-driven detection requirements. Background in detection engineering, threat hunting, SOC operations, or another security discipline that provides an understanding of how Splunk content supports analysts. Demonstrated ability to create and maintain technical documentation, standards, architecture guides, and operational runbooks. Strong analytical, problem-solving, communication, and collaboration skills, with the ability to work across multiple technical and security teams. Splunk certifications such as Splunk Core Certified Consultant, Splunk Enterprise Security Certified Admin, or Splunk Certified Architect are strongly preferred. Security certifications such as GIAC credentials are a plus. Experience with Splunk SOAR, Splunk UBA, infrastructure-as-code tools such as Ansible or Terraform, and AI-assisted automation is desirable. Familiarity with Kafka, streaming data pipelines, real-time telemetry routing, and very large-scale Splunk environments is advantageous. Benefits Competitive contract compensation of approximately $60 per hour, with the final rate depending on qualifications, experience, and location. Contract opportunity with an expected duration of 6+ months. Remote work arrangement. Competitive compensation package for eligible W2 employees. Healthcare options, including medical, dental, and vision coverage. Paid sick leave in accordance with applicable state requirements. Major paid holidays. Opportunity to work on complex enterprise cybersecurity and SIEM environments. Exposure to large-scale Splunk Enterprise Security, cloud telemetry, automation, and security operations technologies. Opportunity to contribute to enterprise-wide architecture, governance, and security engineering initiatives. How Jobgether Works We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Ce que vous ferez

Establish and enforce enterprise-wide Splunk governance, naming conventions, and lifecycle management for security content. Design and maintain CIM normalization, data models, and automation pipelines to improve detection quality and search performance.

Exigences

Requires a Bachelor's degree and over 8 years of Splunk experience, with at least 3 years focused on knowledge management and SIEM content engineering. Deep expertise in Splunk Enterprise Security, SPL, and automation tools like Python and GitHub Actions is essential.

Avantages

• Healthcare Options • Medical Coverage • Dental Coverage • Vision Coverage • Paid Sick Leave • Major Paid Holidays • Remote Work Arrangement

Compétences indiquées

  • CI/CDSouhaitée
  • PythonSouhaitée

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Splunk Enterprise Security
  • CIM Normalization
  • SPL
  • Knowledge Object Management
  • Data Models
  • Python
  • Bash
  • GitHub Actions
  • CI/CD
  • GitOps
  • Linux Administration
  • Windows Administration
  • MITRE ATT&CK
  • SIEM Content Engineering
  • Cloud Telemetry
  • Splunk Architecture

Domaines d’emploi

  • Security & Safety
  • Technology
  • Data & Analytics
  • Software
  • Engineering

Renseignements supplémentaires

Formation minimale
Diplôme professionnel
Expérience minimale
10+ ans
Langue de l’offre
anglais
Heures de travail
40 heures par semaine
Niveau d’expérience
Mid-Senior level
Mode de candidature
La candidature directe est offerte